ORC fined GHC240,000 for engaging unlicensed cybersecurity provider
The Cyber Security Authority (CSA) has fined the Office of the Registrar of Companies (ORC) and cybersecurity service provider Purpleline Solutions Limited a combined GH¢360,000 for breaches of Ghana’s cybersecurity requirements. The ORC was fined GH¢240,000 for failing to comply with two directives issued by the CSA r...

The Cyber Security Authority (CSA) has fined the Office of the Registrar of Companies (ORC) and cybersecurity service provider Purpleline Solutions Limited a combined GH¢360,000 for breaches of Ghana’s cybersecurity requirements.
The ORC was fined GH¢240,000 for failing to comply with two directives issued by the CSA requiring it, as a designated critical information infrastructure (CII) institution, to engage only appropriately licensed cybersecurity service providers.
The CSA said the ORC was specifically directed to engage a Tier 1 licensed cybersecurity service provider to strengthen the security and resilience of its critical information infrastructure.
The directive, issued on June 15, 2026, also required the ORC to provide details of its cybersecurity service providers, the terms of reference for its proposed security operations centre and relevant Public Procurement Authority approvals.
According to the CSA, the ORC instead engaged Purpleline Solutions Limited, which was not licensed by the authority at the time.
The authority said the conduct constituted a breach of Section 92 of the Cybersecurity Act, 2020 (Act 1038).
The ORC was consequently fined 10,000 penalty units for each of the two instances of non-compliance, amounting to GH¢240,000.
The CSA has also directed the ORC to comply with the outstanding directives within one month of receiving the sanction letter.
Purpleline Solutions Limited was separately fined GH¢120,000 for providing regulated cybersecurity services without the required licence.
The CSA said investigations showed that Purpleline had already been engaged by the ORC before applying for a cybersecurity service provider licence on July 15, 2026.
The authority stressed that applying for a licence does not authorise a company to begin operating as a cybersecurity service provider.
“Entities are required to obtain the requisite license before commencing the provision of regulated cybersecurity services,” the CSA said.
The authority cautioned organisations against engaging unlicensed cybersecurity providers and service providers against commencing regulated operations without the appropriate licence.
It urged designated critical information infrastructure institutions, public-sector organisations and other entities covered by the Cybersecurity Act to verify both the licensing status and appropriate licence tier of cybersecurity providers before awarding contracts or allowing them to commence work.
The CSA said it would continue monitoring compliance and take enforcement action against institutions that engage unlicensed providers and companies that provide cybersecurity services without the requisite licence.
“Cybersecurity licensing is a legal requirement, not an administrative formality,” the authority said.