
The Ghana Cyber Security Authority has fined EY Ghana GH¢360,000 for providing regulated services without valid cybersecurity licensing in Ghana. This enforcement action follows the country’s efforts to strengthen regulatory oversight, particularly for firms serving Critical Information Infrastructure (CII).
According to the CSA, EY Ghana continued offering services to CII owners despite repeated directives to comply with the Cybersecurity Act, 2020 (Act 1038). The Authority had issued correspondence on 20 March 2026, granting a 15-day window to apply for a CSP license, which the company failed to meet across three separate regulatory mandates.
Also Read: Kenya, AWS Partner to Train 10,000+ Digital Talent Annually
Understanding Cybersecurity Licensing in Ghana
The CSA determined that the firm’s conduct violated Sections 49 and 92 of Act 1038. These sections prohibit the provision of regulated cybersecurity services without a valid permit and establish clear sanctions for non-compliance.
EY Ghana incurred a penalty of GH¢120,000 for each of the three instances, totaling GH¢360,000, payable within 14 calendar days.
Beyond the financial penalty, the CSA has ordered the firm to immediately cease all regulated services, including Governance, Risk and Compliance (GRC) activities. EY Ghana must provide written confirmation that these services have been discontinued while concurrently completing the formal CSP licensing application process.
The CSA emphasized that submitting an application does not grant temporary permission to operate. Providers are strictly required to secure full licensure before initiating any regulated cybersecurity activities within the country.
Implications for Critical Infrastructure
This enforcement action carries significant weight for organizations operating within Ghana's critical infrastructure ecosystem. The Authority maintains that compliance is non-negotiable for providers working with systems essential to national security and the economy.
Go deeper on GCC & Africa tech — $9.99/month.
Deep dives and investor insights the free digest doesn't cover.
The CSA warned that a provider's global reputation or prior expertise does not grant an exemption from local laws. Unlicensed entities are currently being urged to cease operations immediately to avoid further administrative sanctions or potential court proceedings.
Regulators also advised CII owners to vet their vendors carefully, ensuring they only engage with officially licensed professionals. Cybersecurity licensing is categorized as a legal requirement rather than a simple administrative formality.
Why it Matters to Africa
This enforcement action is significant beyond Ghana because it demonstrates the increasing shift across African markets from cybersecurity policy to active regulatory enforcement.
As governments digitise public services, financial systems, telecommunications networks and other critical infrastructure, cybersecurity providers are becoming part of the infrastructure protecting those systems.
Regulators therefore have a growing interest in ensuring that companies offering sensitive services meet defined standards before they can operate. For businesses, the case is also a reminder that international reputation and technical expertise do not automatically translate into regulatory approval.
Local licensing requirements can apply even to large professional services firms operating in highly regulated areas. The decision could encourage other African regulators to strengthen oversight of cybersecurity service providers and could push businesses operating across multiple markets to pay closer attention to country-specific cybersecurity licensing and compliance requirements.
For CII operators, the message is equally clear: selecting a cybersecurity provider is no longer only a question of expertise or cost. Regulatory status and licensing are becoming critical parts of third-party risk management.
Engagement


