The Cyber Security Authority (CSA) has fined the Office of the Registrar of Companies (ORC) GH¢240,000 for engaging a cybersecurity service provider that was not licensed by the Authority.
Purpleline Solutions Limited Company has also been fined GH¢120,000 for providing cybersecurity services without the requisite licence.
The sanctions followed the CSA’s determination that the ORC, a designated Critical Information Infrastructure (CII) institution, failed to comply with directives requiring it to engage only appropriately licensed Cybersecurity Service Providers (CSPs).
In a statement signed and issued by the CSA, the Authority said it directed the ORC on June 15, 2026, to engage Tier 1 licensed CSPs to strengthen the security and resilience of its critical information infrastructure.
The ORC is also required to provide information on its cybersecurity service providers, the Terms of Reference for its proposed Security Operations Centre (SOC), and relevant Public Procurement Authority (PPA) approvals.
The CSA said despite those directives, the ORC proceeded to engage Purpleline Solutions Limited Company, which was not licensed to provide cybersecurity services.
The Authority consequently determined that the ORC had failed to comply with two separate directives, constituting a violation of Section 92 of the Cybersecurity Act, 2020 (Act 1038).
Under Section 92(2) of the Act, the ORC was fined 10,000 penalty units for each instance of non-compliance, amounting to GH¢240,000.
The CSA has directed the ORC to comply with the outstanding directives within one month of receiving its sanction letter.
The CSA also sanctioned Purpleline Solutions Limited Company after determining that it had provided cybersecurity services without first obtaining the requisite licence.
According to the Authority, Purpleline applied for a Cybersecurity Service Provider licence on July 15, 2026, after the CSA had determined that it had already been engaged by the ORC to provide cybersecurity services.
The CSA stressed that submitting an application for a licence did not confer a licence to operate as a Cybersecurity Service Provider.
Purpleline was therefore fined 10,000 penalty units, equivalent to GH¢120,000, for providing regulated cybersecurity services without the required licence.
The CSA warned all designated CII institutions, public-sector organisations and other entities subject to the Cybersecurity Act against engaging unlicensed cybersecurity service providers.
It also cautioned companies against providing regulated cybersecurity services before obtaining the appropriate licence from the Authority.
The Authority said organisations could not circumvent the licensing requirement by engaging an unlicensed provider and subsequently expecting the provider to regularise its status.
It further clarified that submitting a licence application did not authorise a company to begin providing regulated cybersecurity services.
The CSA urged institutions to verify both the licensing status and appropriate licence tier of cybersecurity service providers before awarding contracts or allowing them to commence work.
“Cybersecurity licensing is a legal requirement, not an administrative formality,” the CSA said.
It said it would continue to monitor compliance and take enforcement action against institutions that engaged unlicensed providers and companies that provided cybersecurity services without the requisite licence.
The CSA said the enforcement action formed part of its efforts to protect Ghana’s digital ecosystem and ensure that organisations entrusted with critical systems and sensitive information complied with their cybersecurity obligations.
