What happened
The Capital Market, Insurance and Savings Authority, Israel's non-bank financial regulator, published a binding set of guidelines Wednesday covering how licensed virtual asset service providers must operate. Per CryptoBriefing, the rules give VASPs six months to align internal controls, meaning the compliance deadline lands in January 2027. The guidelines cover custody segregation, disclosure to retail clients, anti-money-laundering procedures, and conflict-of-interest handling for firms that both trade and custody assets.
CMISA, which supervises insurers, pension funds, and non-bank credit providers, took over crypto oversight through Israel's 2022 licensing regime. Wednesday's release converts what had been draft guidance and informal supervisory letters into enforceable rules. Separately, the Bank of Israel eased its stance on banks servicing crypto-related clients, a constraint that had pushed several Israeli operators to bank abroad.
Why it matters
Israel has been one of the more awkward jurisdictions for crypto firms. Licensing existed on paper but domestic banking access didn't, and that gap drove trading volume offshore. The combination of a binding CMISA rulebook and a softer Bank of Israel posture closes that gap.
It also brings Israel closer to the EU's MiCA framework, which entered full force in late 2024, and to the licensing regimes now live in the UAE and Singapore. For firms already licensed, the six-month clock is short. Custody segregation and client-money rules typically require operational changes that take longer than a quarter to implement cleanly.
Expect at least a handful of smaller VASPs to consolidate or exit rather than absorb the compliance cost.
