
The Cyber Security Authority and professional services firm Ernst & Young Ghana have announced the resolution of regulatory matters relating to cybersecurity licensing fees and associated administrative requirements.
The two institutions confirmed in a joint statement issued on Tuesday, August 18, 2026, that the matters had been “satisfactorily resolved” following engagement between them.
The announcement came hours after the CSA imposed a GH¢360,000 administrative penalty on EY Ghana for allegedly providing regulated cybersecurity services without the required Cybersecurity Service Provider license.
CSA Initially Orders Suspension of Services
In its initial enforcement directive, the Authority accused EY Ghana of providing cybersecurity services, including services to owners of Critical Information Infrastructure, without a valid license.
The CSA said it had directed the firm in correspondence dated March 20, 2026, to submit a licensing application within 15 days.
According to the regulator, EY Ghana failed to comply with three separate directives. The Authority consequently imposed a penalty of GH¢120,000 for each instance, bringing the total fine to GH¢360,000.
The enforcement action was based on Sections 49 and 92 of the Cybersecurity Act, 2020 (Act 1038), which govern the licensing of cybersecurity service providers and sanctions for failing to comply with regulatory directives.
EY Ghana was also ordered to stop providing regulated cybersecurity services without the required license and to complete the application process.
Regulatory Matters Satisfactorily Resolved
Following further discussions, the CSA and EY Ghana said they had taken steps to clarify and address issues concerning license fees and related administrative obligations.
“The regulatory issues between the CSA and EY Ghana have been satisfactorily resolved,” the institutions said in their joint statement.
They also welcomed the constructive and collaborative approach that led to the resolution and reaffirmed their commitment to supporting Ghana’s cybersecurity regulatory framework.
The statement did not publicly detail the specific terms of the resolution. It also did not clarify whether the original penalty was paid, revised or withdrawn.
Additionally, the announcement did not explicitly state whether a final license had been issued or provide details about the precise services EY Ghana was authorized to resume.
CSA Reaffirms Commitment to Enforcement
The Cyber Security Authority emphasized that its responsibility goes beyond penalizing organizations that fail to comply with the law.
It said the regulator also seeks to help businesses and professionals understand Ghana’s cybersecurity requirements and meet their obligations.
“The CSA remains committed to building a secure, resilient and trusted digital ecosystem through effective regulation, responsible industry participation and strong enforcement of Ghana’s cybersecurity laws,” the Authority stated.
The regulator has maintained that submitting an application does not automatically authorize an organization to provide regulated cybersecurity services. A service provider must receive the required license before commencing operations covered by the law.
Licensing Rules Apply to All Providers
The CSA’s enforcement action sends a warning to businesses and professionals operating within Ghana’s growing cybersecurity industry.
Under Act 1038, organizations offering regulated cybersecurity services must obtain the appropriate license, regardless of their size, reputation, expertise or clientele.
The Authority has indicated that compliance is especially important when services are provided to Critical Information Infrastructure owners because failures affecting such systems could threaten national security, economic activity and the delivery of essential public services.
Institutions procuring cybersecurity services are also expected to confirm that the firms or professionals they engage hold valid licenses.
The CSA has warned that it may take action against unlicensed providers and organizations that knowingly procure services from them.
Resolution Highlights Changing Regulatory Environment
The agreement between EY Ghana and the CSA demonstrates the increasing attention being paid to licensing and compliance within Ghana’s digital economy.
As businesses become more dependent on digital systems, regulators are intensifying efforts to ensure that cybersecurity providers meet professional and legal standards.
The resolution also illustrates the role of regulatory engagement in addressing compliance disputes while protecting the integrity of Ghana’s cybersecurity framework.
Source: Omanghana




