CSA Fines ORC and Purpleline Over Cybersecurity Licensing Breaches

The Cyber Security Authority (CSA) has sanctioned the Office of the Registrar of Companies and Purpleline Solutions Limited for breaches of Ghana’s cybersecurity licensing laws, warning that engagement of unlicensed service providers will not be tolerated.
In a press release issued on August 12, 2026, the CSA said the ORC was fined GHC240,000 for engaging an unlicensed cybersecurity service provider, while Purpleline Solutions Limited was fined GHC120,000 for providing cybersecurity services without a license from the Authority.
According to the CSA, the sanction against the ORC follows its determination that the institution engaged Purpleline Solutions Limited Company despite it not being licensed by the CSA to provide cybersecurity services.
On June 15, 2026, the Authority formally directed the ORC, as a designated Critical Information Infrastructure institution, to engage a Tier 1 licensed Cybersecurity Service Provider and subsequently requested information on its cybersecurity providers and its proposed Security Operations Centre.
The CSA said the ORC proceeded to engage Purpleline despite these directives, which the Authority described as a violation of Section 92 of the Cybersecurity Act, 2020 (Act 1038).
Pursuant to Section 92(2) of the Act, the ORC has been fined 10,000 penalty units, amounting to GHC240,000, and has been directed to comply with the outstanding directives within one month of receiving the CSA’s sanction letter.
The Authority also found that Purpleline Solutions Limited provided cybersecurity services without holding a valid license.
The company applied for a cybersecurity service provider license on July 15, 2026, after it had already been engaged to provide such services.
The CSA stated that an application for a license does not confer the right to operate, and has accordingly sanctioned Purpleline with a fine of 10,000 penalty units, amounting to GHC120,000, for providing cybersecurity services without the required license.
The CSA used the sanctions to issue a strong warning to all institutions and service providers.
It said institutions must not engage unlicensed cybersecurity service providers, and companies must not provide regulated cybersecurity services unless they have first obtained the appropriate license.
The Authority stressed that an application for a license is not the same as holding a license and does not authorise an entity to commence regulated cybersecurity operations.
The CSA further urged all designated CII institutions, public-sector organisations and other entities subject to the Cybersecurity Act to verify the licensing status and appropriate license tier of any cybersecurity service provider before awarding a contract.
It added that it will continue to monitor compliance and take enforcement action against both institutions that engage unlicensed providers and entities that provide cybersecurity services without the requisite license.
Click to read more: https://opemsuo.com/author/hajara-fuseini/






