Menu

CSA, Ernst & Young Ghana resolve GH¢360,000 cybersecurity licensing dispute

Ernst & Young Ghana  The development follows enforcement action by the CSA, which had fined EY Ghana GH¢360,000

Wed, 19 Aug 2026 Source: www.ghanaweb.com

The Cyber Security Authority (CSA) and Ernst & Young Ghana (EY Ghana) have resolved regulatory issues over the firm’s licensing requirements for providing cybersecurity services in Ghana.

The resolution follows engagements between the two institutions over licence fees and other administrative requirements associated with the cybersecurity licensing regime.

In a joint statement issued on Tuesday, August 18, 2026, the CSA and EY Ghana said the regulatory issues had been “satisfactorily resolved” after discussions and steps were taken to clarify and address the outstanding matters.

EY Ghana fined GH¢360,000 by CSA over unlicensed cybersecurity services

The development follows enforcement action by the CSA, which had fined EY Ghana GH¢360,000 for providing regulated cybersecurity services without a valid licence.

The Authority said EY Ghana continued to provide cybersecurity services, including services to owners of Critical Information Infrastructure (CII), despite directives to comply with the country’s cybersecurity licensing requirements.

According to the CSA, it directed EY Ghana in a letter dated March 20, 2026, to apply for a Cybersecurity Service Provider (CSP) licence within 15 days.

The Authority subsequently determined that EY Ghana had failed to comply with three separate regulatory directives.

The CSA said the breaches violated Sections 49 and 92 of the Cybersecurity Act, 2020 (Act 1038), which require providers of regulated cybersecurity services to obtain the necessary licence and comply with directives issued by the Authority.

The GH¢360,000 penalty was imposed at GH¢120,000 for each of the three instances of non-compliance.

EY Ghana was also directed to immediately stop providing regulated cybersecurity services without a licence, including Governance, Risk and Compliance (GRC) services, and to provide written confirmation that the affected services had ceased.

The firm was further directed to complete its application for a CSP licence.

The CSA stressed that submitting a licence application does not authorise an entity to operate as a cybersecurity service provider.

“Entities are required to obtain the requisite licence from the CSA before commencing the provision of regulated cybersecurity services,” it said.

The Authority also warned that the size, reputation, expertise or clientele of a service provider does not exempt it from Ghana’s cybersecurity laws.

“All Cybersecurity Service Providers operating in Ghana are subject to the same regulatory requirements under Act 1038 and directives issued by the CSA,” it said.

Under the Cybersecurity Act, persons or entities providing regulated cybersecurity services are required to obtain a licence from the CSA. The licensing regime covers services including vulnerability assessment and penetration testing, digital forensics, managed cybersecurity services, and cybersecurity governance, risk and compliance.

The CSA commenced licensing CSPs and accrediting cybersecurity establishments and professionals in March 2023.

Following the resolution, the CSA and EY Ghana said they remained committed to supporting Ghana’s cybersecurity regulatory framework.

The CSA reiterated that its mandate is not only to enforce compliance but also to help organisations understand and meet their regulatory obligations.

The Authority said it would continue monitoring compliance and take action against institutions and service providers that breach the law, including through administrative sanctions and court proceedings where necessary.

MA

Source: www.ghanaweb.com
Related Articles: