The Cyber Security Authority (CSA) and Ernst & Young Ghana (EY Ghana) have successfully resolved regulatory matters relating to cybersecurity service licensing following constructive engagements.
Both parties remain committed to supporting and strengthening Ghana’s cybersecurity regulatory framework.
In a joint statement issued on August 18, 2026, the CSA and EY Ghana said they had held constructive engagements concerning the licensing requirements for the provision of cybersecurity services in the country. According to the statement, the two parties undertook discussions and took steps to clarify and address matters relating to licence fees and associated administrative requirements, resulting in the satisfactory resolution of the regulatory issues between them.
“The CSA and EY Ghana value the constructive and collaborative approach that has resulted in the resolution of these regulatory issues, and both parties remain committed to supporting Ghana’s cybersecurity regulatory framework,” the statement read.
Background to the Dispute
The joint statement follows an enforcement action the CSA had taken against EY Ghana just days earlier. On August 18, 2026, the Authority announced it had imposed a GH¢360,000 administrative penalty on EY Ghana for providing regulated cybersecurity services, including services to owners of Critical Information Infrastructure (CII), without a valid Cybersecurity Service Provider (CSP) licence.
The CSA said it had directed EY Ghana in a letter dated March 20, 2026, to apply for a CSP licence within 15 days, but the firm subsequently failed to comply with three separate regulatory directives issued by the Authority.
The CSA maintained that this conduct breached Sections 49 and 92 of the Cybersecurity Act, 2020 (Act 1038), which govern the licensing of cybersecurity service providers and prescribe sanctions for non-compliance with directives issued by the Authority.
At the time, the CSA stressed that the reputation, expertise, or clientele of a service provider does not exempt it from Ghana’s cybersecurity laws, and it urged organisations, particularly owners of Critical Information Infrastructure, to source cybersecurity services only from appropriately licensed providers.
A Collaborative Resolution
The latest joint statement signals that the dispute over licence fees and administrative requirements has now been settled between the two parties. Rather than continuing as an adversarial enforcement matter, the CSA and EY Ghana have opted to publicly frame the outcome as the product of dialogue and cooperation.
The statement reiterated that the CSA’s objective is not only to enforce compliance but also to support organisations in understanding and meeting their regulatory obligations. The Authority said it remains committed to building a secure, resilient, and trusted digital ecosystem through effective regulation, responsible industry participation, and strong enforcement of Ghana’s cybersecurity laws.
The statement was issued jointly by the Cyber Security Authority and Ernst & Young Ghana on August 18, 2026, at 20:30 hrs GMT, in Accra.
Source: Sintim Media