The Cyber Security Authority (CSA) has sanctioned the Office of the Registrar of Companies (ORC) for failing to comply with cybersecurity directives requiring institutions designated as Critical Information Infrastructure (CII) to engage only licensed Cybersecurity Service Providers.
The CSA has also fined Purpleline Solutions Limited Company GH¢120,000 for providing cybersecurity services without a licence from the Authority.
According to the CSA, the sanction against the ORC followed its decision to engage Purpleline Solutions Limited Company despite being directed to use a Tier 1 licensed Cybersecurity Service Provider.
The Authority said it directed the ORC on June 15, 2026, to engage Tier 1 licensed Cybersecurity Service Providers to strengthen the security and resilience of its Critical Information Infrastructure.
The ORC was subsequently required to provide information on its cybersecurity service providers, the Terms of Reference for its proposed Security Operations Centre (SOC), and relevant Public Procurement Authority approvals.
However, the CSA said the ORC proceeded to engage Purpleline Solutions Limited Company, which was not licensed to provide cybersecurity services.
The Authority determined that the ORC had failed to comply with two separate directives, constituting a violation of Section 92 of the Cybersecurity Act, 2020 (Act 1038).
As a result, the ORC was fined 10,000 penalty units for each instance of non-compliance, amounting to GH¢240,000, and directed to comply with the outstanding directives within one month of receiving the sanction letter.
Meanwhile, Purpleline Solutions Limited Company was sanctioned for providing cybersecurity services without the required licence.
The CSA said Purpleline applied for a cybersecurity service provider licence on July 15, 2026, after the Authority had determined that the company had already been engaged by the ORC to provide cybersecurity services.
The Authority stressed that submitting an application does not amount to obtaining a licence and does not authorise an entity to provide regulated cybersecurity services.
Purpleline Solutions Limited Company was therefore fined 10,000 penalty units, equivalent to GH¢120,000, for operating without the required licence.
The CSA has warned institutions and cybersecurity service providers against violating the licensing requirements under the Cybersecurity Act.
It said public-sector organisations, designated CII institutions and other entities covered by the law must verify the licensing status and appropriate licence tier of cybersecurity service providers before awarding contracts or allowing them to commence operations.
The Authority further warned that organisations cannot engage an unlicensed provider and expect the company to regularise its status afterwards.
The CSA said it will continue monitoring compliance and take enforcement action against institutions that engage unlicensed providers as well as companies that provide cybersecurity services without the requisite licence.
Read the full statement below:
READ ALSO:
I was shocked – Kofi Tonto denies involvement in alleged US$19.4m Ghana Embassy fraud
Four alleged fake National Security officials arrested at Sawla checkpoint

![Omotola’s daughter Meraiah gets engaged in romantic beachside proposal [Video]](https://www.adomonline.com/wp-content/uploads/2026/08/image_2026-08-12_194542128-100x70.png)





