CSA sanctions ORC, Purpleline Solutions over cybersecurity breaches


The Cyber Security Authority (CSA) has sanctioned the Office of the Registrar of Companies (ORC) and Purpleline Solutions Limited Company for breaches of Ghana’s cybersecurity regulatory requirements.
The sanctions follow the Authority’s determination that the ORC engaged Purpleline Solutions, a company that was not licensed by the CSA to provide cybersecurity services, while Purpleline had commenced providing such services without first obtaining the mandatory licence.
According to the CSA, institutions designated as Critical Information Infrastructure (CII) are required to engage only appropriately licensed Cybersecurity Service Providers (CSPs).
The Authority said it directed the ORC on June 15, 2026, to engage Tier 1 licensed CSPs to strengthen the security and resilience of its Critical Information Infrastructure.
The ORC was also required to submit information on its cybersecurity service providers, the Terms of Reference for its proposed Security Operations Centre (SOC), and relevant approvals from the Public Procurement Authority.
However, the CSA said the ORC proceeded to engage Purpleline Solutions Limited Company despite the directive.
The Authority consequently determined that the ORC had failed to comply with two separate directives, constituting a violation of Section 92 of the Cybersecurity Act, 2020 (Act 1038).

Under Section 92(2) of the Act, the ORC has been fined 10,000 penalty units for each instance of non-compliance, bringing the total financial sanction to GH¢240,000.
The ORC has also been directed to comply with the outstanding CSA directives within one month of receiving the sanction letter.
The CSA also sanctioned Purpleline Solutions Limited Company for providing regulated cybersecurity services without the required licence.
The Authority noted that Purpleline applied for a cybersecurity service provider licence on July 15, 2026, after the CSA had established that the company had already been engaged by the ORC to provide cybersecurity services.
The CSA stressed that submitting an application for a licence does not authorise a company to operate as a Cybersecurity Service Provider.
Purpleline has therefore been fined 10,000 penalty units, equivalent to GH¢120,000, for providing cybersecurity services without the requisite licence.
The Authority has warned institutions and cybersecurity companies that it will not tolerate the engagement or provision of regulated cybersecurity services without the appropriate licence.

It cautioned organisations against contracting unlicensed cybersecurity providers and warned service providers that they must obtain the necessary licence before commencing operations.
The CSA further urged designated CII institutions, public-sector organisations and other entities covered by the Cybersecurity Act to verify both the licensing status and appropriate licence tier of cybersecurity service providers before awarding contracts or allowing them to begin work.
The Authority said it would continue monitoring compliance and take enforcement action against institutions that engage unlicensed providers as well as companies that offer cybersecurity services without the required licence.
The CSA emphasised that cybersecurity licensing is a legal requirement rather than an administrative formality, adding that it remains committed to protecting Ghana’s digital ecosystem and ensuring that organisations responsible for critical systems and sensitive information comply with their cybersecurity obligations.
Story by: Joshua Kwabena Smith




Comments