Business News of Wednesday, 12 August 2026

Source: www.ghanaweb.com

CSA sanctions ORC, Purpleline Solutions over cybersecurity licensing breaches

The CSA said the ORC was sanctioned for engaging Purpleline Solutions The CSA said the ORC was sanctioned for engaging Purpleline Solutions

The Cyber Security Authority (CSA) has sanctioned the Office of the Registrar of Companies (ORC) and Purpleline Solutions Limited over breaches of Ghana’s cybersecurity licensing requirements.

The CSA said the ORC was sanctioned for engaging Purpleline Solutions, a company that was not licensed by the Authority to provide cybersecurity services.

Purpleline Solutions, on the other hand, was fined for providing cybersecurity services without first obtaining the required licence from the CSA.

According to the Authority, the ORC, which is designated as a Critical Information Infrastructure (CII) institution, had been directed to engage a Tier 1 licensed Cybersecurity Service Provider (CSP) to strengthen the security and resilience of its systems.

The directive was issued on June 15, 2026, with the ORC subsequently required to provide details of its cybersecurity service providers, the Terms of Reference for its proposed Security Operations Centre (SOC) and relevant Public Procurement Authority (PPA) approvals.

However, the CSA said the ORC went ahead to engage Purpleline Solutions despite the directive.

“The Authority determined that the ORC failed to comply with two separate directives issued by the CSA,” the statement said.

As a result, the ORC has been fined 10,000 penalty units for each instance of non-compliance, bringing the total fine to GH¢240,000.

The CSA has also directed the ORC to comply with the outstanding directives within one month of receiving the sanction letter.

Purpleline Solutions Limited has separately been fined GH¢120,000 for operating as a cybersecurity service provider without the required licence.

The CSA noted that Purpleline only applied for a cybersecurity service provider licence on July 15, 2026, after the Authority had determined that the company had already been engaged by the ORC to provide cybersecurity services.

The Authority stressed that applying for a licence does not amount to being licensed.

“An application for a licence does not confer a licence to operate as a Cybersecurity Service Provider,” the CSA said, adding that entities must obtain the requisite licence before commencing regulated cybersecurity services.

The sanctions come with a warning from the cybersecurity regulator to public institutions, businesses and service providers to take licensing requirements seriously.

The CSA said institutions must not engage unlicensed cybersecurity service providers, while companies are prohibited from offering regulated cybersecurity services without first obtaining the appropriate licence.

“Organisations cannot circumvent the licensing requirement by engaging a provider first and expecting the provider to regularise its status afterwards,” the Authority warned.

It further cautioned that applying for a licence “is not the same as holding a licence” and does not authorise a company to begin regulated cybersecurity operations.

The CSA has therefore urged designated CII institutions, public-sector organisations and other entities covered by the Cybersecurity Act to verify the licensing status and appropriate licence tier of cybersecurity providers before awarding contracts or allowing them to begin work.

The Authority said it would continue monitoring compliance and taking enforcement action against both institutions that engage unlicensed providers and companies that provide cybersecurity services without the requisite licence.

“Cybersecurity licensing is a legal requirement, not an administrative formality,” the CSA stressed.

The sanctions were announced in a statement issued by the Cyber Security Authority on Wednesday, August 12, 2026.



NA/MA