Customize Consent Preferences

We use cookies to help you navigate efficiently and perform certain functions. You will find detailed information about all cookies under each consent category below.

The cookies that are categorized as "Necessary" are stored on your browser as they are essential for enabling the basic functionalities of the site. ... 

Always Active

Necessary cookies are required to enable the basic features of this site, such as providing secure log-in or adjusting your consent preferences. These cookies do not store any personally identifiable data.

No cookies to display.

Functional cookies help perform certain functionalities like sharing the content of the website on social media platforms, collecting feedback, and other third-party features.

No cookies to display.

Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics such as the number of visitors, bounce rate, traffic source, etc.

No cookies to display.

Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.

No cookies to display.

Advertisement cookies are used to provide visitors with customized advertisements based on the pages you visited previously and to analyze the effectiveness of the ad campaigns.

No cookies to display.

Source: Joy Online

The Cyber Security Authority (CSA), has served notice that effective January 1, 2024, Cybersecurity Service Providers (CSPs), Cybersecurity Establishments (CEs), and Cybersecurity Professionals (CPs) without a license or accreditation are barred from operating in Ghana.

The CSA in a statement it issued Thursday, January 11, said the decision follows the December 31, 2023, deadline it issued to CSPs, CEs, and CPs to obtain a licence or accreditation to operate lawfully in the country.

Stay well-informed and be the very first to receive all the most recent updates directly in your email! Tap here to join now for free!

The CSA will fully enforce the provisions of the Cybersecurity Act, 2020 (Act 1038) regarding its mandate to regulate Cybersecurity Service Providers (CSPs), Cybersecurity Establishments (CEs), and Cybersecurity Professionals (CPs).

“Accordingly, CSPs, CEs and CPs who offer cybersecurity services without a licence or accreditation granted by the Authority, do so in contravention of Act 1038 and will face the full rigors of the Law including criminal prosecutions and administrative penalties where applicable. Institutions and individuals are consequently advised to engage only licensed CSPs and accredited CEs and CPs,” it cautioned.

One can ascertain whether an entity or individual has been granted a licence or accreditation, the certificate number of the entity or individual online at https://www.csa.gov.gh/licence.

The Authority said its office may also be contacted via email: compliance@csa.gov.gh or Telephone: 0531140408.

“Ghana becomes the first country in Africa and second globally, after Singapore to have taken such a bold and giant step to develop the cybersecurity industry in this regard,” the statement said.

Background The Cybersecurity Act, 2020 (Act 1038), came into force in December 2020 to regulate cybersecurity activities and promote the development of cybersecurity in Ghana. The Act thus mandates the Authority to regulate cybersecurity entities, pursuant to sections 4(k), 49, 50, 51, 57 and 59.

The regulatory regime will among other things ensure:

  • a streamlined mechanism for ensuring that CSPs, CEs and CPs offer their services in accordance with approved standards and procedures in line with domestic requirements and international best practice;
  • greater assurance of cybersecurity and safety to consumers;
  • an improved and maintained standard that offers baseline protection to Ghana’s digital ecosystem and;
  • that national security concerns are addressed.

The CSA and the Public Procurement Authority (PPA) are also collaborating to ensure that public sector entities procuring cybersecurity services do so in accordance with the guidelines developed pursuant to Act 1038.

Stakeholder Engagements Since October 2022, the CSA has been engaging all relevant stakeholders including cybersecurity service providers, establishments and professionals on the regulatory regime by deploying different communication strategies.

There have been more than 30 different industry engagements, leading to the introduction and implementation of the licensing and accreditation regime provided in the Cybersecurity Act, 2020. The Authority further set up dedicated desks to receive all enquiries and to provide prompt feedback on the exercise to stakeholders.

As part of efforts to continuously engage and collaborate with the accredited and licensed cybersecurity professionals and institutions, the CSA says it is compiling a national register of licensed and accredited Cybersecurity Service Providers, Cybersecurity Establishments and Cybersecurity Professionals pursuant to section 4(t) of Act 1038 and will see to the establishment of the Industry Forum pursuant to section 81 of the Cybersecurity Act 2020 (Act 1038).

Stay well-informed and be the very first to receive all the most recent updates directly in your email! Tap here to join now for free!

Source: Joy Online