The Cyber Security Authority (CSA) has sanctioned the Office of the Registrar of Companies (ORC) for failing to comply with lawful cybersecurity directives requiring institutions designated as Critical Information Infrastructure (CII) to engage only appropriately licensed Cybersecurity Service Providers (CSPs).
The CSA has also sanctioned Purpleline Solutions Limited Company for providing cybersecurity services without a license issued by the Authority.
ORC SANCTIONED FOR ENGAGING AN UNLICENSED SERVICE PROVIDER
The sanction against the ORC follows the CSA’s determination that the institution engaged Purpleline Solutions Limited Company, an entity not licensed by the CSA to provide cybersecurity services, despite being specifically directed to engage a Tier 1 licensed CSP.
On 15 June 2026, the CSA formally directed the ORC to engage Tier 1 licensed CSP(s) to strengthen the security and resilience of its Critical Information Infrastructure. The ORC was subsequently required to provide information on its cybersecurity service providers, the Terms of Reference for its proposed Security Operations Centre (SOC), and relevant Public Procurement Authority (PPA) approvals.
Despite these directives, the ORC proceeded to engage Purpleline Solutions Limited Company. The CSA considers the ORC’s failure to comply with its directives a violation of Section 92 of the Cybersecurity Act, 2020 (Act 1038), which provides for sanctions for non-compliance with directives issued by the Authority.
The Authority determined that the ORC failed to comply with two separate directives issued by the CSA. Consequently, pursuant to Section 92(2) of Act 1038, the ORC has been fined Ten Thousand (10,000) penalty units for each instance of non-compliance, standing at GH₵ 240,000.00, and directed to comply with the outstanding directives within one month of receiving the CSA’s sanction letter.
PURPLELINE SOLUTIONS LIMITED COMPANY SANCTIONED FOR OPERATING WITHOUT A LICENSE
The CSA has further determined that Purpleline Solutions Limited Company provided cybersecurity services without holding the required license from the Authority.
Importantly, Purpleline Solutions Limited Company applied to the CSA for a cybersecurity service provider license on 15 July 2026. This application was made after the Authority had determined that the company had already been engaged by the ORC to provide cybersecurity services.
An application for a license does not confer a license to operate as a Cybersecurity Service Provider. Entities are required to obtain the requisite license before commencing the provision of regulated cybersecurity services.
Accordingly, the CSA has sanctioned Purpleline Solutions Limited Company with a fine of Ten Thousand (10,000) penalty units, amounting to GH₵120,000.00, for providing cybersecurity services without the required license.
CSA’S STRONG WARNING TO ALL INSTITUTIONS AND SERVICE PROVIDERS
The CSA wishes to make it unequivocally clear that the engagement or provision of cybersecurity services without the requisite license will not be tolerated.
Institutions must not engage unlicensed Cybersecurity Service Providers, and companies must not provide regulated cybersecurity services unless they have first obtained the appropriate license from the CSA.
Organisations cannot circumvent the licensing requirement by engaging a provider first and expecting the provider to regularise its status afterwards. Similarly, an application for a license is not the same as holding a license and does not authorise an entity to commence regulated cybersecurity operations.
The CSA therefore issues a strong warning to all designated CII institutions, public-sector organisations and other entities subject to the Cybersecurity Act to verify the licensing status and appropriate license tier of any cybersecurity service provider before awarding a contract or allowing the provider to commence work.
The Authority will continue to monitor compliance and take enforcement action against both institutions that engage unlicensed providers and entities that provide cybersecurity services without the requisite license.
Cybersecurity licensing is a legal requirement, not an administrative formality. Institutions must comply and service providers must be licensed before they operate.
The CSA remains committed to protecting Ghana’s digital ecosystem and will use its regulatory powers to ensure that organisations entrusted with critical systems and sensitive information meet their cybersecurity obligations.
– END –
Issued by the Cyber Security Authority
August 12, 2026
Accra, Ghana
Ref: CSA/COMMS/PR/2026-08/01







