CSA sanctions Ernst & Young Ghana for operating without cybersecurity licence

In a statement dated August 18, 2026, the CSA said the firm had continued to render such services even after being directed to regularise its operations.

Is allowance instantly strangers applauded

The Cyber Security Authority has warned cybersecurity firms that reputation, size or clientele will not excuse non-compliance with Ghana’s licensing regime, after imposing a GH¢360,000 penalty on Ernst & Young Ghana.

The sanction follows findings by the Authority that EY Ghana provided regulated cybersecurity services without the required Cybersecurity Service Provider licence.

In a statement dated August 18, 2026, the CSA said the firm had continued to render such services even after being directed to regularise its operations.

The Authority said the affected services included work provided to owners of Critical Information Infrastructure, whose systems are considered essential to national security, the economy and public service delivery.

The CSA had, on March 20, 2026, directed EY Ghana to submit an application for a Cybersecurity Service Provider licence within 15 days.

It later determined that the firm had failed to comply with three separate regulatory directives.

The Authority said the breaches fall under Sections 49 and 92 of the Cybersecurity Act, 2020, Act 1038, which regulate the provision of cybersecurity services and provide sanctions for non-compliance.

For each of the three instances of non-compliance, the CSA imposed a penalty of 10,000 penalty units.

Each penalty is equivalent to GH¢120,000.

The total administrative penalty imposed on the firm is therefore GH¢360,000.

EY Ghana has been given 14 calendar days from the date of the final enforcement directive to pay the penalty.

Beyond the fine, the CSA has ordered the firm to immediately stop providing all regulated cybersecurity services until it obtains the required licence.

The directive specifically includes Governance, Risk and Compliance services.

EY Ghana has also been instructed to submit written confirmation to the Authority that it has stopped providing the affected services.

It must also complete the process for obtaining a Cybersecurity Service Provider licence.

The CSA stressed that filing an application is not enough to permit a company to operate in the regulated cybersecurity space.

“An application for a licence does not confer a licence to operate,” the Authority said.

It added that every provider must first obtain the necessary licence before offering regulated cybersecurity services in Ghana.

The enforcement action has also been extended as a warning to other unlicensed operators in the sector.

According to the CSA, all cybersecurity service providers are subject to the same legal obligations under Act 1038 and related regulatory directives.

“The Authority therefore makes clear that the size, reputation, expertise or clientele of a service provider does not exempt it from Ghana's cybersecurity laws,” the statement said.

The CSA has directed all unlicensed providers to stop offering regulated services and take immediate steps to regularise their operations.

It also cautioned institutions that procure cybersecurity services from unlicensed providers.

The Authority said it will continue monitoring compliance and may take action against both unlicensed service providers and organisations that engage them.

Possible enforcement measures include administrative sanctions, court proceedings and publication of the names of unlicensed providers where the law permits.

The CSA urged organisations, especially owners of Critical Information Infrastructure, to ensure that they engage only properly licensed cybersecurity service providers.

“The message is clear: cybersecurity licensing is a legal requirement, not an administrative formality. Institutions must comply, and service providers must be licensed before they operate,” the Authority said.

The action forms part of the CSA’s broader effort to tighten regulation in Ghana’s cybersecurity sector and protect critical digital systems and sensitive information.