The Cyber Security Authority (CSA) has imposed an administrative penalty of GH₵360,000 on Ernst & Young (EY) Ghana for providing cybersecurity services without a valid Cybersecurity Service Provider (CSP) licence.
The action follows EY Ghana’s continued provision of cybersecurity services, including services to owners of Critical Information Infrastructure (CII), despite repeated directives from the CSA requiring compliance with the licensing regime under the Cybersecurity Act, 2020 (Act 1038).
The CSA said it had specifically directed EY Ghana, by correspondence dated 20 March 2026, to submit an application for a CSP licence within fifteen (15) days. The Authority subsequently determined that EY Ghana failed to comply with three separate regul atory directives.
“This conduct constitutes a breach of Sections 49 and 92 of Act 1038, which prohibit the provision of regulated cybersecurity services without the requisite licence and provide sanctions for failure to comply with directives issued by the Authority,” a statement issued on Tuesday, August 18 said.
GH₵360,000 Administrative Penalty
Pursuant to Sections 49(2), 92(2) and 93 of Act 1038, the CSA said it imposed a penalty of 10,000 penalty units, equivalent to GH₵ 120,000, for each of the three instances of non-compliance, resulting in a total administrative penalty of GH₵ 360,000.
EY Ghana has been directed to pay the penalty within fourteen calendar days from the date of the final enforcement directive.
Immediate Cease-and-Desist Directive
With immediate effect, EY Ghana has also been directed to:
1. Cease and desist from providing all regulated cybersecurity services without the requisite licence, including Governance, Risk and Compliance (GRC) services;
2. Provide written confirmation to the CSA that the affected services have ceased; and 3. Complete the application process for a Cybersecurity Service Provider licence.
The CSA emphasises that an application for a licence does not confer a licence to operate as a Cybersecurity Service Provider. Entities are required to obtain the requisite licence from the CSA before commencing the provision of regulated cybersecurity services.
The CSA considers compliance particularly critical where cybersecurity services are provided to owners of Critical Information Infrastructure. The security and resilience of these systems are essential to Ghana’s national security, economy and delivery of essential services.
The Authority therefore makes clear that the size, reputation, expertise or clientele of a service provider does not exempt it from Ghana’s cybersecurity laws.
All Cybersecurity Service Providers operating in Ghana are subject to the same regulatory requirements under Act 1038 and directives issued by the CSA.
The CSA hereby issues a strong warning to all organisations and professionals providing regulated cybersecurity services without the requisite licence to cease such services and regularise their operations immediately.
The Authority will continue to monitor compliance and take enforcement action against both institutions that engage unlicensed providers and entities that provide cybersecurity services without the requisite licence.
Where necessary, such action may include administrative sanctions, court proceedings and publication of the names of unlicensed service providers, as permitted by law.
The CSA further urges organisations, particularly owners of Critical Information
Infrastructure, to ensure that cybersecurity services are procured only from appropriately licensed service providers.
The message is clear: cybersecurity licensing is a legal requirement, not an administrative formality. Institutions must comply, and service providers must be licensed before they operate.
The CSA remains committed to protecting Ghana’s digital ecosystem and will use its regulatory powers to ensure that organisations entrusted with critical systems and sensitive information meet their cybersecurity obligations. Organisations requiring clarification on licensing requirements or the scope of regulated cybersecurity services should contact the Cyber Security Authority.






