CSA and Ernst & Young Ghana Resolve GHS360,000 Cybersecurity Licensing Dispute

Accra: The Cyber Security Authority (CSA) and Ernst and Young Ghana (EY Ghana) have resolved regulatory issues over the firm's licensing requirements for providing cybersecurity services in Ghana. The resolution follows engagements between the two institutions over licence fees and other administrative requirements associated with the cybersecurity licensing regime.

According to Ghana Web, the CSA had initially fined EY Ghana GHS360,000 for providing regulated cybersecurity services without a valid licence. The Authority noted that EY Ghana continued to offer services, including those to owners of Critical Information Infrastructure (CII), despite directives to comply with the country's cybersecurity licensing requirements.

The CSA revealed that it had instructed EY Ghana in a letter dated March 20, 2026, to apply for a Cybersecurity Service Provider (CSP) licence within 15 days. However, EY Ghana failed to comply with three separate regulatory directives, violating Sections 49 and 92 of the Cybersecurity Act, 2020 (Act 1038). These sections require providers of regulated cybersecurity services to obtain the necessary licence and adhere to directives issued by the Authority.

The fine of GHS360,000 was imposed at GHS120,000 for each of the three instances of non-compliance. EY Ghana was ordered to immediately cease providing regulated cybersecurity services without a licence, including Governance, Risk and Compliance (GRC) services, and to provide written confirmation that these services had stopped. The firm was further directed to complete its application for a CSP licence.

The CSA emphasized that merely submitting a licence application does not authorize an entity to operate as a cybersecurity service provider. It stated, 'Entities are required to obtain the requisite licence from the CSA before commencing the provision of regulated cybersecurity services.' Additionally, the Authority warned that the size, reputation, expertise, or clientele of a service provider does not exempt it from Ghana's cybersecurity laws.

Under the Cybersecurity Act, any person or entity providing regulated cybersecurity services must obtain a licence from the CSA. The licensing regime encompasses services such as vulnerability assessment and penetration testing, digital forensics, managed cybersecurity services, and cybersecurity governance, risk, and compliance. The CSA began licensing CSPs and accrediting cybersecurity establishments and professionals in March 2023.

Following the resolution, both the CSA and EY Ghana expressed their commitment to supporting Ghana's cybersecurity regulatory framework. The CSA reiterated that its mandate is not only to enforce compliance but also to assist organizations in understanding and fulfilling their regulatory obligations. The Authority assured that it would continue monitoring compliance and take action against institutions and service providers that breach the law, including through administrative sanctions and court proceedings if necessary.