CFIUS 2025: What Turkish Acquirers Need to Know
The Committee on Foreign Investment in the United States (CFIUS) reviews foreign acquisitions of U.S. businesses for national security risks. For Turkish companies pursuing U.S. acquisitions, CFIUS is a critical — and often underestimated — regulatory hurdle. This guide explains how CFIUS works in 2025, which transactions trigger review, and how Turkish acquirers can navigate the process effectively.
CFIUS 2025: What Turkish Acquirers Need to Know
Introduction
The Committee on Foreign Investment in the United States (CFIUS) is an interagency committee chaired by the U.S. Treasury Secretary that reviews foreign acquisitions of U.S. businesses for national security implications. Since the enactment of the Foreign Investment Risk Review Modernization Act (FIRRMA) in 2018, CFIUS's jurisdiction has expanded significantly — covering not just controlling acquisitions but also certain non-controlling investments in sensitive U.S. businesses.
For Turkish companies pursuing U.S. acquisitions or investments, CFIUS is a regulatory reality that must be planned for from the earliest stages of deal structuring. Failing to account for CFIUS risk can result in deal delays, mandatory mitigation measures, or — in rare but high-profile cases — forced divestiture.
How CFIUS Works
Jurisdiction
CFIUS has jurisdiction over covered transactions, which include:
- Covered control transactions: Any transaction by which a foreign person could acquire control of a U.S. business
- Covered investments: Non-controlling investments by foreign persons in TID U.S. businesses (businesses involved in critical technology, critical infrastructure, or sensitive personal data)
- Covered real estate transactions: Purchases or leases of real estate near U.S. military installations or other sensitive government facilities
The Review Process
Voluntary filing: Most CFIUS filings are voluntary. Parties to a covered transaction may file a voluntary notice with CFIUS to obtain clearance before closing.
Mandatory filing: FIRRMA created mandatory filing requirements for certain transactions:
- Foreign government-controlled investors acquiring any interest in a TID U.S. business
- Foreign investors acquiring a substantial interest in a TID U.S. business involved in critical technology
Short-form declaration: A streamlined 30-day review process. CFIUS may clear the transaction, request a full notice, or take no action.
Full notice: A more comprehensive filing triggering a 30-day initial review, extendable to 45 days for an investigation phase. In complex cases, CFIUS may extend further.
Unilateral review: CFIUS can initiate review of any covered transaction on its own, even without a filing — including after closing. This "evergreen" jurisdiction means parties cannot simply avoid CFIUS by not filing.
Possible Outcomes
- Clearance: CFIUS approves the transaction without conditions
- Mitigation agreement: CFIUS approves subject to a National Security Agreement (NSA) or other mitigation measures (e.g., limiting foreign acquirer's access to sensitive data, requiring a security officer, establishing a firewall between the U.S. business and foreign parent)
- Presidential prohibition: In rare cases, the President can prohibit or unwind a transaction on national security grounds
- Withdrawal and refile: Parties may withdraw and refile to reset the review clock
What Makes a Transaction High-Risk for CFIUS?
Sensitive Sectors
CFIUS scrutiny is highest for transactions involving:
Critical technology:
- Items controlled under the Export Administration Regulations (EAR) or ITAR
- Emerging and foundational technologies (AI, quantum computing, advanced semiconductors, biotechnology, hypersonics)
- Items subject to export license requirements for certain countries
Critical infrastructure:
- Energy (power generation, transmission, distribution)
- Water systems
- Telecommunications
- Transportation (ports, airports, rail)
- Financial infrastructure
Sensitive personal data:
- U.S. businesses that collect, maintain, or use sensitive personal data of U.S. persons (health data, financial data, geolocation data, biometric data, government ID data)
- Businesses with access to data on U.S. government personnel
Proximity to military installations:
- Real estate transactions near military bases, training ranges, or sensitive government facilities
Foreign Government Nexus
CFIUS pays particular attention to foreign investors with ties to foreign governments. Turkish companies with:
- Significant Turkish government ownership or investment
- Contracts with the Turkish government or military
- Board members or executives with government affiliations
...should expect heightened scrutiny and should be prepared to address these connections in a CFIUS filing.
Turkey-Specific Considerations
Turkey's Status
Turkey is a NATO ally and a U.S. partner, which generally reduces (but does not eliminate) CFIUS risk compared to investors from countries of concern (China, Russia, Iran, North Korea, Cuba, Venezuela). However:
- Turkey's purchase of the Russian S-400 missile defense system created friction in the U.S.-Turkey relationship and may increase CFIUS scrutiny of Turkish defense-adjacent transactions
- Turkish companies with significant business in countries of concern (Russia, Iran) may face additional questions about potential technology diversion
- Turkish state-owned enterprises or companies with significant government ownership face heightened scrutiny under FIRRMA
Practical Implications
Turkish acquirers should:
- Conduct a CFIUS risk assessment before signing a letter of intent or term sheet
- Include CFIUS-related representations and covenants in the acquisition agreement
- Build CFIUS review time into the deal timeline (add 3–6 months for complex transactions)
- Engage experienced CFIUS counsel early — ideally before approaching the target
Building a CFIUS Strategy
Pre-Deal Assessment
Before approaching a U.S. target, Turkish acquirers should assess:
- Does the target operate in a sensitive sector (critical technology, critical infrastructure, sensitive personal data)?
- Does the target have U.S. government contracts or security clearances?
- Is the target located near military installations?
- What is the acquirer's ownership structure — is there Turkish government involvement?
- Does the acquirer have business relationships with countries of concern?
Filing Decision
When to file voluntarily:
- The target operates in a sensitive sector
- The target has U.S. government contracts or classified programs
- The acquirer has government ties or operates in countries of concern
- The parties want deal certainty before closing
When mandatory filing applies:
- The acquirer is a foreign government-controlled entity acquiring any interest in a TID U.S. business
- The transaction involves a substantial interest in a critical technology company
Risk of not filing:
- CFIUS can review the transaction after closing
- Post-closing review can result in forced divestiture — a costly and disruptive outcome
- For transactions in sensitive sectors, voluntary filing is almost always advisable
Mitigation Measures
If CFIUS identifies national security concerns, it may require mitigation measures as a condition of approval. Common mitigation measures include:
- National Security Agreement (NSA): A binding agreement between the acquirer and the U.S. government specifying ongoing obligations (e.g., data security requirements, access restrictions, reporting obligations)
- Special security agreement: For targets with classified programs, requiring a security officer and limiting foreign access to classified information
- Firewall: Restricting the foreign acquirer's access to sensitive technology or data
- Divestiture of sensitive assets: Requiring the acquirer to divest specific business units or assets that raise national security concerns
Turkish acquirers should be prepared to negotiate mitigation measures and should understand that agreeing to reasonable mitigation is often preferable to deal failure.
CFIUS Timeline and Deal Planning
| Phase | Timeline |
|---|---|
| Pre-filing preparation | 4–8 weeks |
| Short-form declaration review | 30 days |
| Full notice initial review | 30 days |
| Investigation phase | 45 additional days |
| Presidential review (if referred) | 15 additional days |
| Total (worst case) | ~6 months |
For most transactions, the process is completed in 3–4 months. Turkish acquirers should build this timeline into their deal structure and financing commitments.
Conclusion
CFIUS is a significant but navigable regulatory hurdle for Turkish acquirers pursuing U.S. transactions. The key is early assessment, experienced counsel, and a proactive approach to the review process. Turkish companies that treat CFIUS as an afterthought risk deal delays, costly mitigation requirements, or — in extreme cases — forced divestiture.
ULF New York advises Turkish companies on CFIUS risk assessment, filing strategy, mitigation negotiation, and post-closing compliance. Contact us to assess your transaction's CFIUS exposure before signing.
This article is for informational purposes only and does not constitute legal advice. CFIUS regulations and enforcement priorities are subject to change; consult qualified CFIUS counsel for advice specific to your transaction.
Explore Topics
Written by
ULF New York Editorial Team
ULF New York legal team — New York-based attorneys advising Turkish companies and investors on U.S. market entry, corporate law, real estate, and international trade.