CSA fines ORC GH¢240,000 over cybersecurity non-compliance

Accra, Aug. 13, GNA – The Cyber Security Authority (CSA) has fined the Office of the Registrar of Companies (ORC) GH¢240,000 for engaging an unlicensed cybersecurity service provider.    

Purpleline Solutions Limited Company, which provided the services, was also fined GH¢120,000 for operating without the requisite licence.   

The CSA, in a statement copied to the Ghana News Agency, said the sanctions followed its determination that the ORC, a designated Critical Information Infrastructure (CII) institution, had failed to comply with directives requiring it to engage only licensed Cybersecurity Service Providers (CSPs).   

The Authority said it directed the ORC on June 15, 2026, to engage Tier 1 licensed CSPs to strengthen the security and resilience of its critical information infrastructure.   

The ORC was also required to provide information on its cybersecurity service providers, the Terms of Reference for its proposed Security Operations Centre (SOC), and relevant Public Procurement Authority (PPA) approvals.   

The CSA said despite the directives, the ORC engaged Purpleline Solutions Limited Company, which was not licensed to provide cybersecurity services.   

It said the ORC had consequently failed to comply with two separate directives, constituting a violation of Section 92 of the Cybersecurity Act, 2020 (Act 1038).   

Under Section 92(2) of the Act, the ORC was fined 10,000 penalty units for each instance of non-compliance, totalling GH¢240,000.   

The CSA has directed the ORC to comply with the outstanding directives within one month of receiving its sanction letter.   

The Authority said Purpleline was sanctioned after it determined that the company had provided cybersecurity services without first obtaining the requisite licence.   

It said Purpleline applied for a cybersecurity service provider licence on July 15, 2026, after the CSA had determined that it had already been engaged by the ORC to provide cybersecurity services.   

The CSA stressed that submitting a licence application did not confer a licence to operate as a Cybersecurity Service Provider.   

Purpleline was therefore fined 10,000 penalty units, equivalent to GH¢120,000, for operating without the required licence.   

The CSA warned designated CII institutions, public-sector organisations and other entities subject to the Cybersecurity Act against engaging unlicensed cybersecurity service providers.   

It also warned companies against providing regulated cybersecurity services before obtaining the appropriate licence from the Authority.   

The Authority said organisations could not circumvent the licensing requirement by engaging an unlicensed provider and subsequently expecting the provider to regularise its status.   

It also clarified that submitting a licence application did not authorise a company to begin providing regulated cybersecurity services.   

The CSA urged institutions to verify both the licensing status and appropriate licence tier of cybersecurity service providers before awarding contracts or allowing them to commence work.   

“Cybersecurity licensing is a legal requirement, not an administrative formality,” it said.   

The CSA said it would continue to monitor compliance and take enforcement action against institutions that engaged unlicensed providers and companies that provided cybersecurity services without the requisite licence.   

It said the enforcement action formed part of its efforts to protect Ghana’s digital ecosystem and ensure that organisations entrusted with critical systems and sensitive information met their cybersecurity obligations.   

GNA   

Edited by Kenneth Sackey  

13 August 2026   

Reporter: Eric Appah Marfo   

[email protected]   

escortwex.com https://milliol.com HD sex HD порно xxx video birkerhane.com batumifox.org escortfox.mobi Dubai Escorts nusaybin.mobi Mardin Escort nusaybin.mobi