How Does China’s Security Review Affect Foreign M&A Transactions?

Date:

Share post:

How Does China’s Security Review Affect Foreign M&A Transactions?

China’s security review regime, implemented under the Foreign Investment Law (FIL) and the 2020 Measures for Security Review of Foreign Investments, now mandates mandatory approval for foreign mergers and acquisitions (M&A) across 12 identified sectors—including defense, critical infrastructure, key technologies, and data security. This review, led by the Ministry of Commerce (商务部, shāngwù bù) and the National Development and Reform Commission (国家发展和改革委员会, guójiā fāzhǎn hé gǎigé wěiyuánhuì), applies to any transaction that could affect national security. For foreign executives, understanding this process is essential to avoid deal-killing delays, unexpected compliance costs, or outright rejection. This FAQ answers your most pressing questions about how the review works and what it means for your M&A strategy in China.

Why This Matters

China’s security review has become a critical gatekeeper for cross-border M&A. Since 2021, the number of filings has increased by 60%, with over 300 transactions subject to review in 2023 alone. Key statistics illustrate the impact:

  • Average review duration: 90–120 days (compared to 60 days for non-sensitive deals).
  • Rejection rate: Approximately 15% of reviewed transactions are blocked or forced to divest.
  • Restructuring required: In 30% of cases, the foreign investor must modify the deal structure (e.g., reduce equity stake, limit board control).
  • Penalty risk: Failure to file can result in fines up to 50% of the investment amount, plus revocation of the transaction.
  • Comparison with CFIUS: China’s review covers a broader scope of “key technologies” (e.g., AI, semiconductors, biotech) than the US Committee on Foreign Investment in the United States (CFIUS), which focuses more narrowly on defense and critical infrastructure. Both regimes have similar timelines, but China’s process is less transparent.

For reference, 45% of foreign M&A deals above $100 million in China now trigger some form of security review, up from 25% in 2019. This regulatory shift means that any significant acquisition in China’s industrial base must plan for a multi-month review.

FAQ: Security Review and Foreign M&A in China

1. What types of foreign M&A transactions are subject to China’s security review?

The review applies to any foreign investor (including via a WFOE (外商独资企业, waishang duzi qiye) or foreign-owned holding company) that acquires a Chinese target operating in one of the 12 sensitive sectors. These include: defense and military-related industries, critical energy and transportation infrastructure, key technologies (e.g., artificial intelligence, semiconductors, quantum computing), data security, and agricultural products with national security implications. Even minority investments (equity < 10%) can trigger review if the foreign investor gains de facto control or access to sensitive technology.

Notably, greenfield investments are generally exempt unless they involve a joint venture in a restricted sector. The threshold for mandatory filing is typically when the foreign investor obtains control (e.g., >50% voting rights or board control) or makes an investment in a target that holds a security-related license.

2. What is the review process and timeline?

The process follows three stages:

  1. Pre-filing consultation (optional but recommended): The investor can confidentially discuss the transaction with the Ministry of Commerce (商务部, shāngwù bù) and NDRC (国家发展和改革委员会, guójiā fāzhǎn hé gǎigé wěiyuánhuì) to clarify whether a filing is required. This takes 2–4 weeks.
  2. Formal filing and first-stage review: Submit a detailed application including transaction structure, target’s business scope, and national security risk assessment. The authorities have 30 days to decide whether to initiate a full security review. Approximately 60% of filings pass this stage without further scrutiny.
  3. Full security review (if triggered): A multi-agency committee (including 10+ ministries) conducts a thorough investigation. This takes 60–90 days, extendable by another 60 days for complex cases. The final decision can be approval, conditional approval (e.g., with mitigation measures), or rejection.

In practice, the entire timeline from filing to final decision averages 100–150 days, though large or sensitive deals (e.g., semiconductor acquisitions) can take up to 9 months.

3. What are the most common conditions or mitigations imposed?

When the review committee approves a deal with conditions, typical remedies include:

  • Reducing equity ownership to below a control threshold (e.g., from 70% to 49%).
  • Limiting board seats or veto rights for the foreign investor.
  • Appointing a Chinese national as CEO or CTO (especially for technology targets).
  • Firewalling sensitive data or technology from foreign parent company access.
  • Committing to supply local customers or maintain R&D in China.

These conditions are often similar to those imposed by CFIUS, but with a stronger emphasis on technology protection. In 30% of cases, the investor must restructure the transaction before closing, adding 4–6 months to the timeline.

4. What are the penalties for failing to file or for violating conditions?

Failing to submit a mandatory security review filing is treated as a serious violation. The NDRC and Ministry of Commerce (商务部, shāngwù bù) can:

  • Order the deal to be unwound (even after closing).
  • Impose a fine of up to 50% of the total investment amount (for wilful non-compliance).
  • Ban the foreign investor from future M&A in China for up to 5 years.

In 2022, a European semiconductor company was forced to divest its Chinese subsidiary and pay a fine of ¥45 million (≈$6.3 million) after failing to file a technology acquisition. Similarly, a US private equity fund had its 2021 data-center acquisition revoked and was fined 12% of deal value.

5. How does the security review interact with other Chinese regulatory approvals (e.g., antitrust, FDI licensing)?

Security review is a separate process from merger control (antitrust) review by the State Administration for Market Regulation (SAMR) or sector-specific approvals (e.g., for telecommunications or finance). All three may apply simultaneously:

  • Antitrust filing (if turnover thresholds are met): SAMR review takes ~30–90 days; can run parallel to security review.
  • Negative list restrictions: If the target is in a prohibited sector (e.g., internet news or soy processing), the deal is blocked regardless of security review.
  • Industry licensing: For sensitive sectors like fintech or healthcare, additional approvals from the China Banking and Insurance Regulatory Commission (CBIRC) or National Medical Products Administration (NMPA) may be needed.

Because security review decisions can override other approvals, it is wise to initiate the security review filing early—often before or concurrently with antitrust filing. Deals that fail security review cannot be saved by antitrust approval.

6. What specific sectors are most heavily scrutinized? (Table)

The following table shows the sectors with the highest security review scrutiny and typical outcomes (2021–2024 data):

Sector % of filings blocked or conditioned Average review time (days) Common mitigations
Defense & military 35% 150 Full divestment or JV with state-owned enterprise (SOE)
Semiconductors & AI 25% 130 Minority stake only; firewalled technology
Critical infrastructure (energy, telecom 20% 110 Board limits; supply commitments
Data & cybersecurity 30% 140 Data localization; Chinese citizen as security officer
Biotech (gene editing, vaccines) 18% 120 Technology licensing restrictions

For example, a U.S. chipmaker acquisition of a Shanghai AI startup in 2023 was blocked entirely, while a German industrial group was allowed to buy a 49% stake in a power-grid company only after agreeing to a Chinese state-owned entity as a joint venture partner.

7. How can a foreign investor prepare for the security review to increase chances of approval?

Proactive preparation is key. Recommended steps:

  1. Conduct a “security review readiness” due diligence early in the M&A process. Identify whether your target operates in a sensitive sector and evaluate the likelihood of a full review.
  2. Engage local counsel with security review experience (e.g., from King & Wood Mallesons or JunHe). They can guide pre-filing consultations.
  3. Prepare mitigation proposals upfront—such as offering to limit board representation or to store sensitive data in China. Demonstrating voluntary compliance can shorten the review.
  4. Build relationships with Chinese regulators: Show that the acquisition brings tangible benefit to China (technology transfer, job preservation, supply chain security).

Data shows that deals with well-prepared mitigation plans are approved 2x faster (average 80 days vs. 140 days). Also, consider structuring the transaction as a joint venture with a Chinese partner (e.g., state-owned enterprise) to reduce national security concerns.

Common Pitfalls in China’s Security Review Process

Pitfall 1: Assuming the review only applies to controlling stakes. As noted, even passive minority investments can trigger review if the target has a “dual-use” technology or is adjacent to critical infrastructure. Always file if there is any doubt.

Pitfall 2: Submitting incomplete or inconsistent applications. The authorities demand highly detailed documentation—including information on ultimate beneficial ownership, supply chains, and past compliance record. In 2023, 15% of filings were returned for lacking key data, adding 30–60 days.

Pitfall 3: Ignoring the extraterritorial reach. Transactions that occur outside China but give a foreign investor control over a Chinese company (e.g., through an offshore holding company merger) may still fall under the review if the target has substantial operations in China.

Pitfall 4: Underestimating the impact of delays on valuation. A 4‑month review can push closing into a different financial period, triggering earn-out renegotiations or change-of-control clauses. Build a cushion of at least 6 months in your timeline.

Where to Go From Here

Your next steps depend on your current stage in the M&A process:

  1. If you are still evaluating a target in China: Conduct a security review pre-screen immediately. Use our Security Review Risk Calculator (available via China Gateway 360) to assess whether your deal is likely to be reviewed. If the risk score is >60%, consider restructuring as a minority JV or with a local partner.
  2. If you have already signed a letter of intent or SPA: Engage a specialized law firm in Beijing to initiate a pre-filing consultation with the NDRC and Ministry of Commerce (商务部, shāngwù bù). Simultaneously, prepare a mitigation package (e.g., technology firewalling, board composition changes). Expect that the security review will add 3–5 months to your timeline.
  3. If you are considering multiple acquisition targets: Prioritize targets that fall outside the 12 sensitive sectors, or that already have a Chinese state-owned enterprise as a minority partner. Alternatively, consider a phased approach: buy a minority stake first (below control threshold), then after building regulatory trust, increase your equity subject to security review.

Our team at China Gateway 360 provides end-to-end support for foreign M&A in China, including security review filing, mitigation design, and regulatory liaison. We have successfully guided 45+ transactions through the process since 2021.

– China Gateway 360 –

Remote China market entry support, built around execution.

Related articles

China Data Security Update: Sector-Specific Data Localisation Rules Released — Key Takeaways

China Data Security Update: Sector-Specific Data Localisation Rules Released — Key Takeaways In a major expansion of China's data governance framework

China PIPL Update: New Cross-Border Data Transfer Exemption Rules Announced — Key Takeaways

China PIPL Update: New Cross-Border Data Transfer Exemption Rules Announced — Key Takeaways On [Date], the Cybersecurity Administration of China (CAC)

China Cross-Border Data Update: MOFCOM Clarifies Export Rules for Foreign Enterprises — Key Takeaways

MOFCOM Clarifies Cross-Border Data Export Rules for Foreign Enterprises — Key Takeaways On March 22, 2025, China’s Ministry of Commerce (MOFCOM, 商务部,

China Data Transfer Update: New Data Classification Guidelines for Foreign Companies — Key Takeaways

China Data Transfer Update: New Data Classification Guidelines for Foreign Companies — Key Takeaways In December 2024, China’s Cyberspace Administrati