The Cyber Security Authority (CSA) has sanctioned the Office of the Registrar of Companies (ORC) and Purpleline Solutions Limited Company over breaches of Ghana’s cybersecurity requirements.
In a statement dated Wednesday, August 12, the CSA said the ORC was sanctioned for engaging Purpleline Solutions Limited, an unlicensed cybersecurity service provider, despite being directed to work with a Tier 1 licensed Cybersecurity Service Provider (CSP).
The Authority said it directed the ORC on June 15, 2026, to engage Tier 1 licensed CSPs to strengthen the security and resilience of its Critical Information Infrastructure.
However, the ORC proceeded to engage Purpleline, which the CSA said had not obtained the required licence.
The Authority said the ORC’s actions amounted to non-compliance with two separate directives issued by the CSA. It subsequently imposed a fine of 10,000 penalty units for each violation, totalling GH¢240,000, and directed the ORC to comply with the outstanding directives within one month.
The CSA also sanctioned Purpleline Solutions Limited for providing cybersecurity services without the required licence.
The Authority said Purpleline applied for a cybersecurity service provider licence on July 15, 2026, after it had already been engaged by the ORC.
The CSA stressed that submitting a licence application does not authorise a company to begin providing regulated cybersecurity services.
It said, “An application for a license does not confer a license to operate as a Cybersecurity Service Provider. Entities are required to obtain the requisite license before commencing the provision of regulated cybersecurity services.”
Purpleline has consequently been fined 10,000 penalty units, equivalent to GH¢120,000, for operating without the required licence.
The CSA has warned public institutions and other organisations against engaging unlicensed cybersecurity providers.
The Authority stated, “The CSA wishes to make it unequivocally clear that the engagement or provision of cybersecurity services without the requisite license will not be tolerated.”
It further cautioned that institutions cannot engage a provider first and expect the company to regularise its licensing status afterwards.
“Similarly, an application for a license is not the same as holding a license and does not authorise an entity to commence regulated cybersecurity operations.”
The CSA has therefore urged designated Critical Information Infrastructure institutions, public-sector organisations and other entities covered by the Cybersecurity Act to verify the licensing status and appropriate licence tier of cybersecurity providers before awarding contracts.
The Authority said it will continue monitoring compliance and take enforcement action against institutions and service providers that breach the licensing requirements.
Source: Starrfm.com.gh

