Menu

CSA Sanctions ORC and Purpleline Solutions over Cybersecurity Violations

2 MIN READ

The Cyber Security Authority (CSA) has sanctioned the Office of the Registrar of Companies (ORC) and Purpleline Solutions Limited Company for breaching provisions of the Cybersecurity Act, 2020 (Act 1038).

According to the Authority on Wednesday, the ORC failed to comply with lawful directives requiring institutions designated as Critical Information Infrastructure (CII) to engage only appropriately licensed Cybersecurity Service Providers (CSPs).

Despite being instructed on 15 June 2026 to engage Tier 1 licensed CSPs, the ORC contracted Purpleline Solutions, which was not licensed by the CSA. The CSA determined that the ORC violated two separate directives and, pursuant to Section 92(2) of Act 1038, fined the institution 10,000 penalty units per violation, amounting to GH¢240,000.00.

“The ORC has also been directed to comply with outstanding directives within one month of receiving the sanction letter,” the statement read.

Purpleline Solutions Limited Company was separately sanctioned for providing cybersecurity services without a license. Although the company applied for a license on 15 July 2026, this was after it had already been engaged by the ORC.

The CSA noted that an application does not confer operating rights, and entities must obtain a license before commencing regulated services.

“Purpleline has been fined 10,000 penalty units amounting to GH¢120,000.00,” it added.

The CSA issued a strong warning to all designated CII institutions, public-sector organisations, and other entities subject to the Cybersecurity Act to verify the licensing status and appropriate tier of any CSP before awarding contracts.

The Authority said that licensing is a legal requirement, not an administrative formality, and vowed to continue monitoring compliance and enforcing sanctions where necessary.

Margaret Adjeley Sowah, ISD