Our Expert in India
No results available
Who this guide is for: in‑house counsel, private equity sponsors, corporate M&A teams and deal counsel advising on inbound or outbound transactions involving India. What you will get: a step‑by‑step HowTo, a Step / Who / Duration timeline table, a comprehensive documents checklist, realistic 2026 timelines, indicative costs, mitigation options and an extended FAQ.
National security screening india has become one of the most consequential regulatory checkpoints in cross‑border M&A, and in 2026 it functions as a live deal consideration rather than a mere procedural formality. Deal teams planning transactions in sensitive sectors must now build review time, disclosure obligations and mitigation options directly into their share purchase agreement (SPA) and financing timetables. This guide sets out, in the register of a practical playbook, what tends to trigger a review, who is involved, how long it can take, what documents you typically file and how to allocate risk in your transaction documents.
Timelines are realistic estimates for 2026: government‑route approvals under India’s FDI framework commonly take several weeks to a few months, and considerably longer where genuine national security concerns arise. Timelines are indicative only, as the government‑route process is discretionary and case‑specific.
National security screening india refers, in practice, to the government scrutiny of certain foreign investment and change‑of‑control transactions to assess whether they raise concerns relating to sovereignty, defence, critical infrastructure or strategic technology. Unlike ordinary merger control, this scrutiny is discretionary, policy‑driven and coordinated across multiple agencies. India does not currently operate a single, standalone “national security” statute of the type seen in some other jurisdictions; instead, security considerations are addressed within the FDI approval and exchange‑control framework. The following subsections explain the scope, rationale and legal basis.
The policy rationale is straightforward: investment that transfers control of sensitive assets, defence manufacturing, telecommunications networks, dual‑use technology, ports, power grids or data infrastructure, can create strategic vulnerabilities. India’s foreign direct investment (FDI) regime therefore layers security‑sensitive review over the standard approval architecture, principally through the government (approval) route. The review can apply to both direct acquisitions and indirect or offshore structures that ultimately change control of an Indian entity operating in a sensitive field. Scope is deliberately broad, and the government retains discretion in how it examines transactions requiring approval.
The framework for FDI screening rests on several instruments working together. The Department for Promotion of Industry and Internal Trade (DPIIT), within the Ministry of Commerce & Industry, issues the Consolidated FDI Policy and, with the concerned administrative ministries, administers the government approval route for FDI. Foreign investment formalities, reporting and the exchange‑control dimension are governed by the Foreign Exchange Management Act, 1999 (FEMA) and the rules and regulations made under it, principally the Foreign Exchange Management (Non‑debt Instruments) Rules, 2019 (administered by the Ministry of Finance) and RBI’s reporting regulations, with the Reserve Bank of India (RBI) as the exchange‑control authority.
Corporate change‑of‑control mechanics, board and shareholder resolutions, filings on acquisitions and significant beneficial ownership under the Companies Act, 2013, sit with the Ministry of Corporate Affairs (MCA). Security considerations are brought into the process through the Ministry of Home Affairs (MHA) and relevant security agencies. Where the transaction meets the notification thresholds under the Competition Act, 2002, the Competition Commission of India (CCI) runs a parallel merger‑control process. Deal teams should treat national security screening india as one strand within this multi‑authority matrix rather than a standalone filing.
Not every transaction attracts security‑focused scrutiny. The analysis turns on the form of the deal, the sector involved and the level and source of foreign ownership acquired. The subsections below break down the trigger analysis you should run at deal origination.
Heightened review is most likely where a transaction results in a change of control or the acquisition of a meaningful interest in an Indian target in a sensitive field, or where the government route is otherwise engaged. Trigger events include:
The key analytical test is control and beneficial ownership, together with the source of the investment and the sector, rather than merely the legal form of the instrument used.
Sector is one of the most important factors. Heightened scrutiny or government‑route approval commonly attaches to areas such as:
Investment from certain jurisdictions, in particular an entity of a country that shares a land border with India, or where the beneficial owner is situated in or is a citizen of such a country, requires government‑route approval irrespective of sector or size under the FDI rules, and such cases receive close scrutiny.
Sectoral caps and routes vary under the Consolidated FDI Policy and the Non‑debt Instruments Rules: some sectors are open under the automatic route up to defined percentages, while sensitive sectors require prior government approval from a specified threshold. The land‑border rule applies regardless of the ordinary sectoral caps. Treat percentage thresholds as necessary but not sufficient, a stake in a highly sensitive target, or investment from a restricted source, can still require government approval and close scrutiny. Confirm the current sectoral position against the DPIIT policy in force at the time of the transaction.
Understanding the institutional map is essential to sequencing your filings correctly and identifying who bears the notification burden.
DPIIT, within the Ministry of Commerce & Industry, facilitates the government approval route and routes applications to the concerned administrative ministry/department, which is the competent authority for the sector in question. For transactions raising security questions, the process draws in the Ministry of Home Affairs and, as required, other security agencies and sector ministries (for example, the Ministry of Defence, the Department of Telecommunications or the Ministry of Power). Where a proposal exceeds specified financial limits or is otherwise significant, approval may be escalated, including to the Cabinet Committee on Economic Affairs. The CCI operates in parallel on the competition assessment where thresholds are met.
As a practical matter, the applicant, typically the Indian investee company or the investor’s authorised Indian representative, depending on the application, makes the government‑route application through the prescribed portal and provides the supporting information. The target’s cooperation is essential because much of the required data (corporate records, licences, resolutions, key‑personnel details) sits with the target. Sponsors and fund investors should confirm at term‑sheet stage which entity will act as applicant, since the ultimate beneficial owner’s nationality and the funding chain drive the assessment.
Security‑focused review does not run in isolation. Expect, as applicable: CCI merger‑control notification where thresholds are met, FEMA reporting to the RBI on the foreign investment, MCA corporate filings on the change of control, and sector‑regulator approvals (for example, in telecom or defence). Sequencing these is a core planning task.
Decisional flow: trigger identified → applicant files government‑route application via the Foreign Investment Facilitation Portal → DPIIT routes to the competent ministry and consults MHA / security agencies / sector ministries → decision (approval, conditional approval or rejection) → closing and post‑closing compliance.
The following is a recommended procedural sequence, mapped to the timeline table below, for approaching government‑route clearance where security considerations may arise in a cross‑border M&A in India. Each step lists what to prepare and where to insert legal strategy.
Before signing, run a structured self‑assessment at deal origination. Map the target’s sector classification, the applicable FDI route and cap, the ultimate beneficial ownership chain, the nationality of funders and any land‑border nexus, and the presence of sensitive licences, data holdings or critical‑infrastructure contracts. This internal step typically takes a few days and determines whether the government route and security‑focused review are engaged. Produce a preliminary regulatory‑risk memo that feeds directly into deal structuring and the SPA conditionality architecture. (Practical guidance, confirm with counsel.)
Where the risk assessment flags a genuine review, informal engagement with DPIIT or the relevant ministry can help clarify scope, expected information requirements and likely conditions before filing. This is a legal‑strategy step: voluntary, candid disclosure of ownership and funding builds credibility and can help streamline the substantive phase. Keep a contemporaneous record of engagements and align the disclosure narrative with the documents you will later file.
File the government‑route application through the Foreign Investment Facilitation Portal, enclosing the full document index (see Section 5). Treat the filing date as Day 0 for timeline purposes. Ensure the cover letter summarises the transaction, identifies the applicant and authorised signatory, and cross‑references each annexure. Incomplete filings are a common cause of delay, so complete the checklist before submitting rather than filing merely to “start the clock”.
DPIIT routes the application to the competent ministry, which consults other stakeholders, the MHA, security agencies and sector ministries, as required. Expect completeness checks and clarification requests, followed by substantive assessment. In sensitive cases the authorities may seek additional funding evidence, clarifications on management, or further information to assess infrastructure and personnel. Respond promptly and completely; each round of clarification can extend the timetable. This is the phase most likely to overrun.
The competent authority may issue one of three broad outcomes: unconditional approval, approval with conditions, or rejection. Conditional approvals can arise in sensitive sectors and may require governance undertakings, board arrangements, data‑related commitments, ring‑fencing of sensitive operations or, in some cases, divestment of specific assets. Build a decision buffer into your timetable, and preserve the ability to renegotiate the SPA if conditions materially alter deal economics.
Only close once the approval (and any conditions precedent) are satisfied and the parallel FEMA reporting and MCA filings are in order. Post‑closing, implement any undertakings, establish monitoring and reporting protocols, and diarise compliance obligations that may run for an extended period. Failure to honour conditions can put the approval at risk, so treat post‑closing compliance as an integral part of the transaction, not an afterthought.
| Step | Who / responsible | Typical duration (2026 estimate) |
|---|---|---|
| 1. Early screening & risk assessment | Buyer legal / FDI advisor + target management | A few days (internal) |
| 2. Pre‑notification engagement (if used) | Buyer counsel → DPIIT / relevant ministry (informal) | 1–3 weeks |
| 3. Formal notification / submission | Applicant via Foreign Investment Facilitation Portal | Filing date = Day 0 |
| 4. Completeness check & clarifications | DPIIT / competent ministry; consulted agencies (MHA / sector) | 1–4 weeks |
| 5. Inter‑agency substantive review | Competent ministry + MHA + security agencies + sector ministries | Several weeks to a few months (may extend) |
| 6. Decision (approval / conditional / rejection) | Competent authority (ministry / Cabinet Committee where applicable) | Weeks after substantive review |
| 7. Post‑decision compliance & monitoring | Buyer / target (undertakings, reporting) | Ongoing (as directed) |
Assembling a complete, well‑indexed submission is one of the most reliable ways to help streamline a review. This section sets out a standard documentary checklist, how to handle sensitive information and the templates you should prepare. The precise requirements are set by DPIIT and the competent ministry and should be confirmed against the current guidance.
The documents required vary by sector, but the core index below is a reliable starting point. Prepare certified copies, translations where required and a clear annexure numbering scheme that matches your cover letter.
| Document / information | Purpose / who needs it | Typical specifics |
|---|---|---|
| Cover letter / application (via portal) | Official filing record | Signed by authorised signatory; transaction summary |
| Transaction agreements (SPA, SSA, asset purchase) | Evidence of change in control | Signed agreements; redacted versions where confidentiality required |
| Corporate structure chart (pre & post) | Identify ultimate beneficial owners & indirect acquisition | Full ownership chain; percentage holdings |
| Beneficial owner KYC and identity documents | Nationality / ownership screening | Certified copies; IDs for ultimate owners and funders |
| Source of funds / funder agreements | Demonstrate funding chains | Bank statements, subscription agreements, lender letters |
| Transaction timeline & escrow arrangements | Assess control and post‑closing conditions | Proposed closing date; escrow terms |
| Sector‑specific licences & approvals | Show regulated activities & compliance | Telecom / defence licences, spectrum, import licences |
| Board & shareholder resolutions | Approvals authorising the transaction | Certified copies; meeting minutes |
| Business plan & sensitive tech disclosures | Risk assessment | Redacted IP details; technology descriptions; facility locations |
| Contracts with critical infrastructure providers | Identify sensitive links | Key supplier / customer contracts (if relevant) |
| Background information on key personnel | Identify governance risks | CVs, prior positions, clearances if any |
| Site & facility information | Infrastructure risk assessment | Site maps, capacity, personnel counts (as relevant) |
Cross‑border M&A India screening may require disclosure of commercially sensitive technology and pricing. Where full disclosure is unavoidable, provide a redacted summary in the main filing and offer to make sensitive detail available through a controlled submission where policy permits. Mark documents with confidentiality legends, maintain a clean audit trail of what was shared and with whom, and ensure your SPA confidentiality provisions expressly permit regulatory disclosure. Coordinate with the target so that its trade secrets are protected while still satisfying the authorities’ information needs.
Prepare standard templates ahead of filing: a layered ownership chart down to ultimate beneficial owners, a source‑of‑funds narrative supported by bank and lender evidence, and, where relevant, details of any clearances held by directors or key personnel. Notarisation and apostille may be required for foreign‑executed documents, and certified English translations should accompany any non‑English material.
Building the clearance timeline into your SPA is a discipline, not a guess. Because the government‑route review is discretionary, your timetable must accommodate a realistic band rather than a single fixed date. Use the following scenarios as planning anchors:
Translate these into drafting: set the long‑stop date generously (allow for the upper band plus a buffer), make regulatory approval a clear condition precedent, and draft material adverse effect carve‑outs so that a change flowing from the review process itself does not inadvertently give a party a walk‑away right. Provide for extension mechanisms if the authorities request further time, and align financing availability periods with the outer edge of the screening band so debt commitments do not lapse mid‑review.
Costs are dominated by professional fees rather than government charges. There is generally no separate government filing fee for the FDI government‑route application on the portal, but legal, technical and remedial costs can be material in sensitive matters. The table below sets out indicative planning estimates only, not quotations, and actual figures vary widely by transaction. Fees for parallel filings (for example CCI notification) are set by the relevant authority and are additional.
| Cost item | Who typically pays | Indicative note |
|---|---|---|
| Government FDI approval filing | Applicant | Generally no separate fee for the government‑route portal application |
| Legal advisor fees (India counsel) | Buyer / sponsor | Varies significantly with complexity; obtain a quote |
| Technical / security consultant | Buyer | Material in sensitive‑sector matters; scope‑dependent |
| Translation / notarisation / apostille | Buyer | Per‑document charges as applicable |
| Compliance monitoring & undertakings | Buyer | Ongoing, depending on conditions imposed |
| Structural remedies (escrow / trust) | Buyer / parties as agreed | Variable, can be material |
| Parallel filings (e.g. CCI notification) | Notifying party | Statutory fees as set by the relevant authority |
Allocate these costs expressly in the SPA. Address who bears advisor fees versus statutory fees, and negotiate indemnities and, where appropriate, a reverse break‑fee mechanism so that a rejection or an onerous condition does not leave the buyer exposed to sunk costs without recourse. Budget generously for the substantive‑review phase, where technical consultant time and repeated clarification responses drive the largest variances.
Recent years have seen deeper inter‑agency coordination and closer scrutiny of critical technology and supply‑chain links, and this has continued into 2026. The practical effect for sensitive‑sector deals tends to be longer substantive reviews, more frequent involvement of security agencies, and heightened focus on ultimate beneficial ownership and funding chains, particularly where offshore layers obscure control. There is increasing interest in data holdings, semiconductor and dual‑use exposure, and dependencies on foreign suppliers of critical inputs. Note also the evolving data‑protection framework under the Digital Personal Data Protection Act, 2023, which is relevant to targets holding significant personal data.
The likely practical consequence for deal teams is that early engagement moves from optional to advisable in any transaction touching a sensitive sector, and that timetables should assume the upper end of the review band. Official announcements on FDI policy are published through DPIIT and the Press Information Bureau, and counsel should confirm the current position against those primary sources before committing to a timetable. (Practical guidance, confirm with counsel.)
Structuring cannot lawfully be used to evade a required approval or a genuine security review, but it can allocate risk and preserve optionality. The following levers are standard in India inbound transactions.
Consider interim holding structures pending clearance, governance controls that limit foreign influence over sensitive functions until conditions are met, and pre‑closing mitigation such as ring‑fencing sensitive operations. These options manage regulatory risk in India M&A but must be presented transparently to the authorities, concealment undermines credibility and invites rejection, and any structure must comply with FEMA and the FDI rules.
Where conditions are anticipated, plan the remedies package in advance: monitoring arrangements, board arrangements, appropriately cleared management for sensitive roles, and divestment or trustee mechanisms for assets that cannot be held by a foreign controller. Pre‑agreeing the shape of these remedies internally can shorten the negotiation once conditions are proposed.
| Outcome | Typical remedies / conditions | Deal impact |
|---|---|---|
| Unconditional approval | Minimal or none | Smooth closing |
| Approval with conditions | Undertakings, governance controls, monitoring | Requires SPA tailoring; possible escrow |
| Rejection / not permitted | Restructuring, divestment or unwind may be required | Deal failure or renegotiation |
National security screening india is now a decisive factor in cross‑border M&A timetables, and the teams that succeed in 2026 are those that assess triggers at origination, engage early, file complete submissions and allocate risk explicitly in their transaction documents. Treat the review as one strand within the wider approval matrix, DPIIT and the competent ministry, MHA, CCI, RBI and MCA, and plan for the upper end of the timeline band. For a related deep‑dive, see our Cross‑border M&A due diligence (India) guide.
This article is for general guidance only and does not constitute legal advice. Regulatory positions change; readers should verify current requirements against primary sources and seek tailored advice on their specific transaction.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Shinoj Koshy at SK & Partners, a member of the Global Law Experts network.
posted 4 seconds ago
posted 17 minutes ago
posted 24 minutes ago
posted 31 minutes ago
posted 54 minutes ago
posted 2 hours ago
posted 2 hours ago
posted 3 hours ago
posted 3 hours ago
posted 3 hours ago
posted 4 hours ago
posted 4 hours ago
No results available
Find the right Legal Expert for your business
Send welcome message