By Seli Baisie
The Cyber Security Authority (CSA) has fined the Office of the Registrar of Companies (ORC) and Purpleline Solutions Limited a combined GH¢360,000 for breaches of Ghana’s cybersecurity licensing requirements.
The CSA said the ORC was sanctioned for engaging Purpleline Solutions, an unlicensed Cybersecurity Service Provider (CSP), despite being directed to work with a Tier 1 licensed provider.
In a statement issued on Wednesday, August 12, 2026, the Authority said it had directed the ORC on June 15 to engage Tier 1 licensed CSPs to strengthen the security and resilience of its Critical Information Infrastructure (CII).
The ORC was also required to submit information on its cybersecurity service providers, the Terms of Reference for its proposed Security Operations Centre (SOC) and relevant Public Procurement Authority approvals.
However, according to the CSA, the ORC proceeded to engage Purpleline Solutions, which did not hold the required licence to provide cybersecurity services.
The Authority said the ORC had failed to comply with two separate directives and was therefore fined 10,000 penalty units for each breach under Section 92(2) of the Cybersecurity Act, 2020 (Act 1038).
Under Section 92(2) of the Act, the ORC has been fined 10,000 penalty units for each instance of non-compliance, amounting to GH¢240,000 in total.
The ORC has also been directed to comply with the outstanding directives within one month of receiving the sanction letter.
Purpleline fined GH¢120,000
The CSA also fined Purpleline Solutions Limited GH¢120,000 for providing cybersecurity services without the required licence.
The Authority said Purpleline applied for a cybersecurity service provider licence on July 15, 2026, after it had already been engaged by the ORC to provide cybersecurity services.
The CSA stressed that submitting an application does not amount to obtaining a licence and does not authorise a company to begin providing regulated cybersecurity services.
“An application for a license does not confer a license to operate as a Cybersecurity Service Provider,” the Authority said.
It added that entities “are required to obtain the requisite license before commencing the provision of regulated cybersecurity services.”
CSA warns institutions, service providers
The CSA has warned public institutions, designated Critical Information Infrastructure operators and other organisations subject to the Cybersecurity Act against engaging unlicensed cybersecurity service providers.
The Authority said companies providing regulated cybersecurity services must obtain the appropriate licence before beginning operations.
“Cybersecurity licensing is a legal requirement, not an administrative formality,” the CSA said.
It further warned organisations against engaging an unlicensed provider and expecting the company to regularise its status afterwards.
The Authority said it would continue monitoring compliance and take enforcement action against both institutions that engage unlicensed providers and companies that operate without the required licence.
“The CSA remains committed to protecting Ghana’s digital ecosystem and will use its regulatory powers to ensure that organisations entrusted with critical systems and sensitive information meet their cybersecurity obligations,” the statement said.
Below is the full statement;






































































