ACCRA — The Cyber Security Authority (CSA) announced an administrative penalty of GH₵360,000 on Ernst & Young (EY) Ghana on Tuesday, August 18, 2026, for providing commercial cybersecurity services without holding a valid Cybersecurity Service Provider (CSP) licence.
According to regulatory enforcement filings released in Accra, the sanction follows a compliance audit revealing that the firm engaged in professional security assessments and digital auditing services contrary to sections of the Cybersecurity Act. Authority officials emphasized that mandatory licensing protocols are strictly enforced across all corporate consulting practices to ensure national digital infrastructure standards are maintained without compromise.
Regulatory Enforcement Under the Cybersecurity Act
Under the legal framework governing Ghana digital space, corporate entities offering managed security operations, vulnerability testing, or digital forensics must secure official accreditation prior to commercial engagement. The CSA noted that unregistered operations undermine regulatory oversight and expose sensitive enterprise networks to unverified third-party contractors.
Industry observers point out that this administrative action marks one of the most substantial regulatory fines imposed on a major international accounting and advisory network operating within the domestic market, signaling a tightening compliance environment for professional service firms.
Corporate Compliance and Industry Response
Representatives for the affected advisory firm have initiated formal discussions with regulatory compliance officers to review the administrative ruling and clear outstanding licensing requirements. Regional technology associations have urged all member firms to expedite their institutional registrations to avoid similar punitive measures.
The regulatory body has instructed all corporate entities currently providing digital protection services to submit their certification status documentation to the central database before the end of the current quarter.
Why did the Cyber Security Authority fine EY Ghana?
The Cyber Security Authority fined EY Ghana because the firm provided commercial cybersecurity and digital auditing services without obtaining a valid Cybersecurity Service Provider licence as mandated by national cybersecurity regulations. The regulatory penalty was officially announced on August 18, 2026, in Accra.
The CSA published the administrative enforcement decision on August 18, 2026.
All affected corporate service providers are required to settle outstanding compliance fees and finalize licensing documentation by September 30, 2026.