ORC challenges CSA cybersecurity penalty over timing and fairness concerns
The Office of the Registrar of Companies (ORC) has launched a formal challenge against a cybersecurity sanction imposed by the Cyber Security Authority (CSA), arguing that the penalty was premature and violated procedural fairness principles enshrined in Ghana's Constitution.
The dispute centres on the ORC's procurement of a Network Operations Centre (NOC) and Security Operations Centre (SOC). The ORC contends that its entire procurement process—from evaluation to contract award—was completed months before the CSA issued directives requiring Critical Information Infrastructure institutions to engage only Tier One licensed cybersecurity service providers.
Timeline of events and the ORC's Defence
According to the ORC, the Ministry of Finance issued a Commitment Authorisation for the NOC/SOC project on 28 November 2025. The Office then advertised the procurement in the Daily Graphic and on the Public Procurement Authority's GHANEPS platform on 4 December 2025, with a bid deadline of 19 December. Following evaluation on 22 December, Purpleline Solutions Limited was recommended for the contract.
The Central Tender Review Committee of the Ministry of Finance approved the procurement on 31 December 2025, and the contract was executed on 11 February 2026. Crucially, the ORC maintains that the CSA's directives requiring Tier One compliance were not issued until 20 May and 15 June 2026—several months after the procurement process had concluded and the contract was already in force.
The ORC's core argument is that it could not reasonably have complied with a requirement during procurement that had not yet been communicated. The Office also contends that retrospectively applying the directive to an already-concluded contract would constitute an improper retrospective application of law, a principle fundamental to administrative fairness in Ghana.
Why it matters for Ghana
This dispute highlights a significant tension in Ghana's cybersecurity governance and raises important questions about the application of regulatory requirements. The case illustrates the challenges facing public institutions when regulatory directives change mid-project or are enforced retroactively.
For Ghana's critical information infrastructure sector, the ORC-CSA dispute underscores the need for clear timelines, advance notice, and grace periods when new compliance obligations are introduced. If institutions cannot reasonably prepare for new requirements, blanket enforcement risks disrupting essential government services.
The ORC has further emphasised that the CSA announced the sanction publicly on 12 August 2026, only 57 days into the 90-day compliance period it had been given to address deficiencies. This left just 33 days before the deadline, yet the ORC claims it had already begun implementing corrective measures and had resolved some identified issues. The premature public announcement, according to the ORC, caused reputational damage to a critical government institution and could paradoxically expose it to greater cybersecurity risk.
Constitutional fairness and next steps
The ORC has cited Articles 23 and 296 of Ghana's 1992 Constitution, which require public administrative bodies to exercise their powers fairly, reasonably and without arbitrariness. The Office is seeking intervention from the Attorney-General's Office and has called on the CSA to issue a public clarification and apology regarding what it describes as a premature and unfair enforcement action.
The ORC has explicitly stated that its challenge should not be construed as a rejection of Ghana's cybersecurity framework. Rather, the Office remains committed to compliance with cybersecurity laws and cooperation with the CSA on legitimate concerns. The dispute now hinges on whether regulatory bodies can impose sanctions before compliance deadlines expire and whether retroactive application of new directives meets constitutional standards of fairness.
Source: MyJoyOnline

Comments (0)
Be the first to comment.