The directive required the ORC to submit information on its cybersecurity service provider, proposed Security Operations Centre, and relevant Public Procurement Authority approvals.
Ghana’s Cyber Security Authority (CSA) has sanctioned the Office of the Registrar of Companies (ORC) and Purpleline Solutions Limited for engaging in cybersecurity activities in violation of the country’s licensing requirements.
The CSA said the ORC engaged Purpleline Solutions, a company that was not licensed by the Authority to provide cybersecurity services, despite directives requiring institutions designated as Critical Information Infrastructure (CII) to work only with appropriately licensed Cybersecurity Service Providers (CSPs).
According to the Authority, on 15 June 2026, it directed the ORC to engage a Tier 1 licensed CSP to strengthen the security and resilience of its Critical Information Infrastructure. The directive required the ORC to submit information on its cybersecurity service provider, proposed Security Operations Centre, and relevant Public Procurement Authority approvals.
The CSA said the ORC subsequently proceeded to engage Purpleline Solutions despite the directives. The Authority determined that this amounted to non-compliance with Section 92 of the Cybersecurity Act, 2020 (Act 1038).
As a result, the ORC was fined GH¢240,000, comprising two penalties of GH¢120,000 for separate instances of non-compliance. The organisation was also ordered to comply with the outstanding directives within one month of receiving the sanction letter.
The CSA also sanctioned Purpleline Solutions for providing cybersecurity services without the required licence. The company had applied for a cybersecurity service provider licence on 15 July 2026, but the application was made after the Authority had determined that it was already providing cybersecurity services to the ORC.
The Authority imposed a further GH¢120,000 fine on Purpleline Solutions for providing cybersecurity services without the required licence.
The CSA stressed that submitting an application for a licence does not constitute a licence to operate. Entities must obtain the appropriate licence before commencing the provision of regulated cybersecurity services.
The Authority has issued a strong warning to CII institutions, public-sector organisations and other entities covered by the Cybersecurity Act to verify the licensing status and appropriate licence tier of cybersecurity providers before awarding contracts or allowing them to begin work.
The CSA also cautioned organisations against engaging unlicensed providers first and expecting them to regularise their status afterwards, noting that an application for a licence does not authorise an entity to conduct cybersecurity operations.
The Authority said it will continue monitoring compliance and taking enforcement action against both organisations that engage unlicensed cybersecurity providers and providers that offer cybersecurity services without the required licence.
The CSA reiterated that cybersecurity licensing is a legal requirement and urged institutions and service providers to ensure they meet their regulatory obligations before commencing operations.

