BusinessLaw

CSA, EY Ghana resolve licensing dispute

Regulator and audit firm reach agreement after a standoff over cybersecurity licensing requirements.

The Cyber Security Authority (CSA) and Ernst & Young Ghana (EY Ghana) have resolved a regulatory dispute over the firm’s compliance with Ghana’s cybersecurity licensing requirements, bringing an end to tensions between the regulator and the professional services company. In a joint statement issued in Accra on Tuesday, August 18, 2026, the two institutions said they had held “constructive engagements” over issues concerning the licensing requirements for the provision of cybersecurity services. They said the discussions focused particularly on licence fees and related administrative requirements, and that the regulatory issues between them had now been “satisfactorily resolved.”

The resolution comes after the CSA took enforcement action against EY Ghana over its provision of regulated cybersecurity services without what the Authority said was the required Cybersecurity Service Provider (CSP) licence. In the early hours of August 18, the CSA announced an administrative penalty of GH¢360,000 against EY Ghana, saying the firm had continued providing regulated cybersecurity services, including services to owners of Critical Information Infrastructure, despite directives to regularize its operations. The Authority said it had directed EY Ghana in correspondence dated March 20, 2026, to apply for a CSP licence within 15 days, but subsequently determined that the company had failed to comply with three separate regulatory directives.

According to the CSA, the breaches fell under Sections 49 and 92 of the Cybersecurity Act, 2020 (Act 1038), which govern the provision of regulated cybersecurity services and compliance with directives issued by the Authority. The Authority said it imposed 10,000 penalty units, equivalent to GH¢120,000, for each of the three instances of non-compliance, bringing the total administrative penalty to GH¢360,000. EY Ghana was also directed to cease providing regulated cybersecurity services without the requisite licence and to complete the licensing process. However, the subsequent joint statement from the CSA and EY Ghana did not disclose whether the GH¢360,000 penalty had been paid, waived, reduced or otherwise dealt with as part of the resolution. Instead, it said the parties had successfully addressed the outstanding regulatory issues concerning licensing fees and administrative requirements.

The two institutions said the outcome was the product of a constructive and collaborative approach, and reaffirmed their commitment to Ghana’s cybersecurity regulatory framework. “The CSA and EY Ghana value the constructive and collaborative approach that has resulted in the resolution of these regulatory issues,” the statement read. While announcing the resolution, the CSA used the opportunity to clarify that its regulatory mandate goes beyond penalizing organizations that breach cybersecurity requirements.

The Authority said its objective is also to help organizations understand and meet their obligations under Ghana’s cyber security laws. It said it remained committed to developing “a secure, resilient and trusted digital ecosystem” through effective regulation, responsible participation by industry players and strong enforcement of the country’s cybersecurity laws. The position is significant because the CSA has increasingly emphasized that cybersecurity providers must be properly licensed before undertaking regulated activities in Ghana.

In its earlier enforcement notice against EY Ghana, the Authority stressed that merely submitting an application for a CSP licence does not confer the right to operate. Providers are required to obtain the requisite licence before commencing regulated cybersecurity services. The Authority also warned that the size, reputation, expertise or clientele of a service provider does not exempt it from Ghana’s cybersecurity laws. That warning was particularly directed at services provided to Critical Information Infrastructure (CII) owners, whose systems are considered essential to national security, the economy and the delivery of vital services.

The CSA has urged organizations, especially those responsible for critical infrastructure, to procure cybersecurity services only from appropriately licensed providers. The resolution between the regulator and EY Ghana is likely to reinforce the CSA’s position that cybersecurity licensing is a statutory obligation rather than an optional administrative procedure. For cybersecurity firms and other professionals operating in the sector, the dispute underscores the importance of completing the licensing process and complying with directives issued by the regulator. The CSA has said it will continue monitoring compliance and take enforcement action against both unlicensed service providers and organizations that engage them. Possible measures include administrative sanctions, court proceedings and, where legally permitted, publication of the names of unlicensed providers.

For EY Ghana, the joint statement marks a shift from regulatory disagreement to cooperation, with both sides now saying the outstanding issues have been satisfactorily resolved. The CSA and EY Ghana said they would remain committed to supporting Ghana’s cybersecurity regulatory framework as the country strengthens oversight of its rapidly expanding digital ecosystem. The joint statement was issued at 8:30 p.m. GMT on August 18, 2026, in Accra, and was signed jointly by the Cyber Security Authority and Ernst & Young Ghana.

By: Joyce Owusu

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button