The Office of the Registrar of Companies (ORC) has challenged a cybersecurity sanction imposed by the Cyber Security Authority (CSA), describing the penalty as premature, procedurally unfair and based on a procurement process that predated the Authority’s directive requiring critical information infrastructure (CII) institutions to engage Tier One licensed cybersecurity service providers.
The dispute follows a CSA press release titled “Cyber Security Authority sanctions ORC and Purpleline Solutions Limited Company for cybersecurity non-compliance,” which was widely reported by online media. The ORC says some of the reports created the impression that it had been fined for deliberately engaging an unlicensed cybersecurity service provider, an allegation it disputes.
At the centre of the matter is the procurement of a Network Operations Centre (NOC) and Security Operations Centre (SOC) for the ORC.
According to the Office, the Ministry of Finance issued a Commitment Authorisation for the project on November 28, 2025. The ORC subsequently advertised the procurement in the Daily Graphic and on the Public Procurement Authority’s GHANEPS platform on December 4, 2025, with December 19, 2025 set as the deadline for bids.
Two companies submitted bids, and following an evaluation on December 22, 2025, the ORC’s Entity Tender Committee recommended Purpleline Solutions for the contract. The procurement was subsequently reviewed by the Central Tender Review Committee of the Ministry of Finance, which granted approval on December 31, 2025.
The project was incorporated into the ORC’s 2026 work plan because the approved expenditure became available on the government’s financial management system after the transition into the new financial year.
Following the release of the budget in February 2026, the ORC issued the award and executed the contract with Purpleline Solutions on February 11, 2026.
The ORC’s principal argument is that the procurement and contract predated the CSA directives requiring CII institutions, including the ORC, to engage a Tier One cybersecurity company.
The Office says the directives were issued on May 20 and June 15, 2026, several months after the procurement had been completed and the contract awarded. It therefore contends that it could not reasonably have been expected to comply, at the time of the procurement, with a requirement that had not yet been communicated.
The ORC further argues that the subsequent directive could not properly be applied retrospectively to a procurement in which contractual rights had already accrued.
It also disputes the timing of the sanction, saying the CSA had granted it 90 days to rectify identified cybersecurity deficiencies and that it had begun implementing corrective measures, with some issues already resolved and others being addressed.
The Office says it engaged the CSA on the matter and explained that the NOC/SOC infrastructure and procurement arrangements were already in place before the relevant directives were issued.
It was therefore surprised when the CSA imposed the penalty and issued the accompanying press release on August 12, 2026—57 days into the 90-day compliance period. According to the ORC, the sanction was imposed 33 days before the expiration of the compliance period, depriving it of the full opportunity to complete the corrective measures and submit its comprehensive response to the CSA.
The Office further argues that the manner in which the sanction was imposed and publicly announced raises questions of administrative fairness.
It relies on the constitutional principles governing the exercise of administrative discretion, particularly Articles 23 and 296 of the 1992 Constitution, which require public administrative bodies to act fairly, reasonably and without arbitrariness.
The ORC also says the publication of the sanction before the expiration of the compliance period has caused reputational harm to the institution and could potentially expose it to cybersecurity risks. It contends that the CSA’s public statement did not adequately reflect key facts, including the timing of the procurement, the prior award of the contract and the corrective measures being undertaken within the 90-day compliance window.
The petition is therefore intended to challenge what the ORC considers an unfair and premature sanction and to seek appropriate administrative redress.
Among other reliefs, the Office is seeking the intervention of the Attorney-General’s Office over the circumstances surrounding the sanction and its publication. It is also asking the CSA to issue a public clarification and apology regarding what it describes as the premature publication of the penalty.
The ORC, however, maintains that its position does not amount to a rejection of Ghana’s cybersecurity requirements.
It says it remains committed to complying with the country’s cybersecurity laws and to cooperating with the CSA to address legitimate security concerns.
The central issue in the petition, therefore, is whether the CSA was entitled to sanction and publicly name the ORC before the expiry of the 90-day compliance period, particularly when the procurement in question had been initiated, evaluated and approved before the Authority’s Tier One requirement was communicated to the Office.
BY GORDON WELLU
Follow our WhatsApp Channel now! https://whatsapp.com/channel/0029VbAjG7g3gvWajUAEX12Q
