The Cyber Security Authority (CSA) has fined the Office of the Registrar of Companies (ORC) GH¢240,000 for failing to comply with directives requiring it to engage only licensed Cybersecurity Service Providers (CSPs).
The Authority has also imposed a separate GH¢120,000 fine on Purpleline Solutions Limited Company for providing cybersecurity services without the required licence.
The sanctions form part of the CSA’s enforcement of the Cybersecurity Act, 2020 (Act 1038), particularly its licensing and compliance requirements for institutions designated as Critical Information Infrastructure (CII).
ORC engaged unlicensed provider
The CSA said the sanction against the ORC followed its decision to engage Purpleline Solutions Limited Company despite an earlier directive to use a Tier 1 licensed cybersecurity service provider.
On June 15, 2026, the Authority directed the ORC to engage Tier 1 licensed CSPs to strengthen the security and resilience of its Critical Information Infrastructure.
The ORC was also required to provide the CSA with information on its cybersecurity service providers, the Terms of Reference for its proposed Security Operations Centre (SOC), and relevant Public Procurement Authority (PPA) approvals.
However, the CSA said the ORC proceeded to engage Purpleline Solutions Limited Company, which was not licensed by the Authority to provide cybersecurity services.
According to the CSA, the ORC failed to comply with two separate directives, constituting violations of Section 92 of Act 1038.
The Authority consequently imposed a fine of 10,000 penalty units for each instance of non-compliance, resulting in a total penalty of GH¢240,000.
The ORC has also been directed to comply with the outstanding directives within one month of receiving the CSA’s sanction letter.
Purpleline fined GH¢120,000
Purpleline Solutions Limited Company was separately sanctioned after the CSA determined that it had provided regulated cybersecurity services without first obtaining a licence from the Authority.
The CSA noted that Purpleline applied for a cybersecurity service provider licence on July 15, 2026, after the Authority had established that the company had already been engaged by the ORC.
The Authority stressed that submitting a licence application does not authorise a company to operate as a Cybersecurity Service Provider.
Entities must obtain the appropriate licence before commencing regulated cybersecurity services.
Purpleline was therefore fined GH¢120,000, equivalent to 10,000 penalty units.
CSA warns institutions, cybersecurity firms
The CSA has warned public institutions, designated CII organisations and other entities subject to the Cybersecurity Act against engaging unlicensed cybersecurity service providers.
It also cautioned companies against providing regulated cybersecurity services without first securing the required licence.
The Authority said organisations could not engage an unlicensed provider and subsequently expect the provider to regularise its status.
Similarly, it said an application for a licence should not be confused with actually holding a licence.
The CSA urged institutions to verify both the licensing status and appropriate licence tier of cybersecurity service providers before awarding contracts or allowing them to commence work.
The Authority said it would continue monitoring compliance and take enforcement action against both organisations that engage unlicensed providers and companies that provide cybersecurity services without the required authorisation.
“Cybersecurity licensing is a legal requirement, not an administrative formality,” the CSA said.








