The Cyber Security Authority (CSA) has warned cybersecurity firms providing regulated services without a licence to immediately stop operating or face enforcement action, including possible administrative sanctions and court proceedings.
The Authority said the warning applies to all cybersecurity service providers operating in Ghana, regardless of their size, reputation, expertise or clientele, under the Cybersecurity Act, 2020 (Act 1038) and directives issued by the regulator.
The CSA said it considers compliance especially important where cybersecurity services are provided to owners of critical information infrastructure, whose systems are essential to Ghana’s national security, economy and delivery of critical services.
“Cybersecurity licensing is a legal requirement, not an administrative formality,” the authority said in a statement issued Aug. 18. The regulator directed organisations and professionals providing regulated cybersecurity services without the required licence to cease those services and regularise their operations immediately.
The CSA also warned organisations that engage unlicensed providers that they could face enforcement action. It said it will monitor compliance and take action against both service providers operating without licences and institutions that procure their services.
Possible measures include administrative sanctions, court proceedings and, where permitted by law, publication of the names of unlicensed service providers, according to the Authority.
The CSA urged organisations, particularly owners of critical information infrastructure, to ensure that cybersecurity services are procured only from appropriately licensed providers.
The Authority said it will use its regulatory powers to ensure organisations responsible for critical systems and sensitive information meet their cybersecurity obligations.
