The Cyber Security Authority (CSA) has sanctioned the Office of the Registrar of Companies (ORC) and Purpleline Solutions Limited Company for breaches of Ghana’s cybersecurity licensing and compliance requirements.
The ORC was sanctioned for engaging a cybersecurity service provider that was not licensed by the CSA, while Purpleline Solutions Limited Company was penalised for providing regulated cybersecurity services without first obtaining the requisite licence from the Authority.
The enforcement action forms part of the CSA’s efforts to ensure compliance with the Cybersecurity Act, 2020 (Act 1038) and strengthen the protection of Ghana’s Critical Information Infrastructure (CII).
ORC fined GH¢240,000
According to the CSA, the sanction against the ORC followed the Authority’s determination that the institution failed to comply with directives requiring designated CII institutions to engage appropriately licensed Cybersecurity Service Providers (CSPs).
On June 15, 2026, the CSA directed the ORC to engage Tier 1 licensed CSPs to strengthen the security and resilience of its Critical Information Infrastructure.
The ORC was also required to provide information on its cybersecurity service providers, the Terms of Reference for its proposed Security Operations Centre (SOC), and relevant approvals from the Public Procurement Authority (PPA).
However, the CSA said the ORC subsequently engaged Purpleline Solutions Limited Company, which was not licensed by the Authority to provide cybersecurity services. The CSA determined that the ORC had failed to comply with two separate directives.
Consequently, under Section 92(2) of the Cybersecurity Act, 2020, the Authority imposed a fine of 10,000 penalty units for each instance of non-compliance, resulting in a total penalty of GH¢240,000.
The ORC has also been directed to comply with the outstanding directives within one month of receiving the CSA’s sanction letter.
Purpleline Solutions fined GH¢120,000
The CSA also sanctioned Purpleline Solutions Limited Company for providing cybersecurity services without the required licence.
The Authority noted that Purpleline Solutions applied for a cybersecurity service provider licence on July 15, 2026, after it had already been engaged by the ORC to provide cybersecurity services.
The CSA stressed that submitting an application for a licence does not amount to obtaining a licence and does not authorise an organisation to begin providing regulated cybersecurity services.
Service providers are required to obtain the appropriate licence from the CSA before commencing regulated cybersecurity operations.
As a result, Purpleline Solutions Limited Company was fined 10,000 penalty units, equivalent to GH¢120,000, for providing cybersecurity services without the requisite licence.
CSA warns institutions and cybersecurity firms
The CSA has issued a strong warning to institutions and cybersecurity service providers, stating that the engagement or provision of regulated cybersecurity services without the appropriate licence will not be tolerated.
The Authority said institutions must verify the licensing status and appropriate licence tier of cybersecurity service providers before awarding contracts or allowing them to commence operations.
It further warned organisations against attempting to circumvent the licensing regime by engaging an unlicensed provider and expecting the provider to regularise its status afterwards.
Similarly, companies that have applied for a cybersecurity licence must not assume that their application authorises them to operate. According to the CSA, an application is not the same as a licence.
CII institutions urged to comply
The CSA has particularly urged designated Critical Information Infrastructure institutions, public-sector organisations and other entities subject to the Cybersecurity Act to strictly comply with the licensing requirements.
The Authority said it would continue monitoring compliance and take enforcement action against both institutions that engage unlicensed cybersecurity providers and companies that provide regulated cybersecurity services without the required licence.
The CSA reiterated that cybersecurity licensing is a legal requirement and not merely an administrative formality.
It said the enforcement action demonstrates its commitment to protecting Ghana’s digital ecosystem and ensuring that organisations entrusted with critical systems and sensitive information meet their cybersecurity obligations.
The sanctions against the ORC and Purpleline Solutions bring renewed attention to the importance of regulatory compliance within Ghana’s rapidly evolving cybersecurity sector and underscore the need for institutions to verify that cybersecurity providers are properly licensed before engaging their services.
Source: Sintim Media