Ensuring Robust Consideration of Evolving National Security Risks by the Committee on Foreign Investment in the United States
The order directs the Committee on Foreign Investment in the United States (CFIUS) to apply a broader, more detailed set of national security factors when reviewing foreign investments in U.S. businesses, explicitly adding supply chain resilience, cybersecurity vulnerabilities, sensitive personal data access, and cumulative investment patterns to its analytical framework.
It matters because foreign investors in sectors like microelectronics, artificial intelligence, biotechnology, quantum computing, and critical minerals will face heightened scrutiny under a more comprehensive review standard, and individual transactions will now be evaluated against broader industry-wide investment trends.
What this order does
What it orders
The order directs CFIUS to elaborate and expand the national security factors it must weigh when reviewing foreign investment transactions. On supply chains, it directs the Committee to assess whether a transaction could undermine U.S. resilience in manufacturing, critical minerals, or technologies such as microelectronics, AI, biotechnology, quantum computing, advanced clean energy, and food security. On technological leadership, it directs the Committee to assess whether a transaction could erode U.S. advantages in key technology sectors, and directs the Office of Science and Technology Policy (OSTP) to periodically publish a list of technology sectors fundamental to national security. It also adds three entirely new categories of factors: cumulative or aggregate investment patterns by foreign persons in a sector over time, cybersecurity risks — including threats to elections, critical infrastructure, and energy grids — and access to sensitive U.S. persons' data, including health, biological, and de-anonymizable data.
The order does not change the statutory scope of CFIUS jurisdiction or create new rights enforceable against the U.S. government. It requires the Committee to regularly review its own processes and periodically report findings and policy recommendations to the Assistant to the President for National Security Affairs. Implementation depends on the Committee applying these factors through its existing review machinery.
Who it affects
Foreign investors and companies seeking to acquire or invest in U.S. businesses, particularly in technology, critical infrastructure, data-rich, and critical-minerals sectors. U.S. businesses that are targets of such investments. CFIUS member agencies and OSTP, which must publish a technology sector list.
Why it matters
Foreign acquirers of U.S. companies in sensitive sectors now face scrutiny against a wider set of national security criteria, increasing the likelihood that deals involving data access, supply chain concentration, cybersecurity exposure, or cumulative sector ownership are flagged, conditioned, or blocked.
What must happen and when
How the order is supposed to work
CFIUS applies the new and elaborated factors within its existing transaction-by-transaction review process — no new jurisdictional threshold is set. The Department of Commerce's International Trade Administration can be asked to supply sector-level analysis when aggregate investment patterns are at issue. OSTP must publish a technology-sector list that the Committee consults, drawing on other government efforts. The Committee must periodically self-review and report policy recommendations to the National Security Advisor, creating an internal accountability loop but no external enforcement mechanism.
Actions and deadlines
- Periodically publish a list of technology sectors fundamental to U.S. technological leadership and national security
- Regularly review Committee processes, practices, and regulations and periodically report findings and policy recommendations to the Assistant to the President for National Security Affairs