
The Cyber Security Authority has imposed combined penalties of GH¢360,000 on the Office of the Registrar of Companies and Purpleline Solutions Limited for violating Ghana’s cybersecurity licensing requirements.
The ORC was fined GH¢240,000 for engaging a cybersecurity company that did not hold the required license. Purpleline Solutions received a separate GH¢120,000 penalty for providing regulated cybersecurity services without prior authorization.
The sanctions relate to regulatory non-compliance rather than a reported cyberattack or data breach.
As an institution designated as Critical Information Infrastructure, the ORC is required to observe heightened security standards and work only with appropriately licensed Cybersecurity Service Providers.
According to the CSA, it directed the ORC on June 15, 2026, to engage a Tier 1 licensed provider to strengthen the security and resilience of its critical information systems.
The Authority also instructed the ORC to provide information about its cybersecurity service providers, the terms of reference for a proposed Security Operations Centre and the relevant approvals from the Public Procurement Authority.
Despite those instructions, the ORC proceeded to engage Purpleline Solutions, which was not licensed by the CSA to provide the regulated services.
The Authority determined that the ORC had failed to comply with two separate directives, constituting breaches under Section 92 of the Cybersecurity Act, 2020 (Act 1038).
Under Section 92(2) of the Act, the ORC was fined 10,000 penalty units for each instance of non-compliance. The two penalties amounted to GH¢240,000.
The institution has also been directed to fulfil the outstanding requirements within one month of receiving the sanction letter.
Purpleline Solutions was separately sanctioned after the CSA established that it had begun providing cybersecurity services without obtaining the required license.
The company submitted an application for a Cybersecurity Service Provider license on July 15, 2026. However, the regulator said that application was made after Purpleline had already been engaged by the ORC.
The CSA stressed that submitting an application does not confer licensed status or authorize a company to begin providing regulated services.
Purpleline was consequently fined 10,000 penalty units, equivalent to GH¢120,000.
The regulator used the case to warn public institutions, Critical Information Infrastructure operators and other organizations covered by the Cybersecurity Act to conduct proper checks before awarding cybersecurity contracts.
Institutions were urged to verify not only whether a prospective provider holds a valid license but also whether its licensing tier permits it to undertake the proposed work.
The CSA also cautioned cybersecurity companies against commencing operations while their applications remain under consideration.
“Cybersecurity licensing is a legal requirement, not an administrative formality,” the Authority said.
It warned that enforcement action would continue against institutions that hire unlicensed providers and companies that offer regulated cybersecurity services without the appropriate authorization.
Source: Omanghana



