CFIUS Risk Matrix Flags Eight High-Risk Transaction Profiles, Sample Mitigation Terms
Cross-border M&A and investment teams must reassess deal risk: Treasury's new CFIUS matrix signals heightened scrutiny—and likely non-notified enforcement—against foreign acquirers in critical infrastructure, data, and sensitive-tech sectors.
On July 29, 2026, Treasury, as CFIUS chair, released a Risk Matrix cataloguing eight transaction profiles that pose elevated national security risk: critical infrastructure, cybersecurity, information security, personal data, product integrity, proximity to sensitive government sites, supply assurance, and technology transfer. For each profile, the matrix sets out the threat-vulnerability-consequence calculus under 31 C.F.R. § 800.102 and lists illustrative mitigation measures—governance restrictions, source-code reviews, third-party monitorships, segregation of protected technology, supply-continuation commitments, and CFIUS access and audit rights. The release aligns with the America First Investment Policy and a stated push to 'demystify' the process, but it also signals broader enforcement reach, including non-notified outreach. Counsel advising foreign investors, sponsors, and U.S. targets should map deal profiles against the matrix, weigh voluntary filings where risk indicators are present, and prepare for more standardized mitigation expectations rather than bespoke negotiations.