DORA and the Cybersecurity Act: CNB and NUKIB Clarify the Rules

Legal

By: Michaela Voitco

Contents

On June 24, 2026, the Czech National Bank (CNB) and the National Cyber and Information Security Agency (NUKIB) published a joint statement aimed at clarifying the relationship between the DORA Regulation and the Cybersecurity Act (ZKB) regarding financial market entities subject to both legal regimes.

The core issue stems from the fact that certain financial institutions are simultaneously addressees of obligations under both DORA and the Cybersecurity Act. In practice, these so-called "DORA entities" face the question of whether they must comply with both sets of rules in parallel or whether one takes precedence. The joint statement provides an answer precisely to this question.

The CNB and NUKIB base their approach on the principle of lex specialis derogat legi generali, meaning the principle that special legal provisions take precedence over general ones. Pursuant to Article 1(2) of DORA, the regulation is considered a sector-specific Union legal act for the purposes of Article 4 of the NIS 2 Directive. Therefore, where DORA regulates a specific area of cybersecurity in a manner equivalent in effect to the requirements of NIS 2 or the Cybersecurity Act, DORA applies with priority.

At the same time, the statement emphasizes that the priority of DORA cannot be understood as absolute. It does not mean that the Cybersecurity Act is entirely excluded for DORA entities. On the contrary, where DORA does not regulate a certain area, or does not regulate it equivalently, the relevant obligations under the Cybersecurity Act continue to apply to DORA entities. As examples, the CNB and NUKIB cite, in particular, the registration of the entity with NUKIB or rules relating to a state of cyber danger.

Also significant is the conclusion regarding situations where Czech or other relevant legislation establishes different, more detailed, or stricter requirements that cannot be considered equivalent to DORA requirements. In such cases, a DORA entity must simultaneously fulfill both the requirements arising from DORA and these additional obligations. In other words, DORA acts as a baseline regulatory framework enriched by stricter or specialized rules for specific areas of activity. The overarching meaning and purpose of such arrangements is to ensure a cohesive European cybersecurity regime and protection of the confidentiality, integrity, and availability of information.

Equally interesting is the section of the statement dedicated to the enforcement of supervision. Financial entities subject to DORA are primarily supervised by the CNB. However, if they perform specific activities that are regulated non-equivalently by other legislation, they may also be subject to supervision by other authorities, notably NUKIB or the Digital and Information Agency (DIA). Both authorities explicitly state that they will coordinate their supervisory procedures and, depending on the circumstances, utilize tools such as joint inspections, the sharing of inspection results, or other forms of cooperation. The objective is to prevent duplication while streamlining the enforcement of cybersecurity and resilience requirements.

The joint statement thus serves as an important interpretative document for financial market entities situated at the intersection of DORA and Cybersecurity Act regulation. It provides a relatively clear guideline stipulating that where the requirements of both regimes are substantively equivalent, DORA takes precedence as a special regulation. However, where the Cybersecurity Act or other special regulations establish additional or stricter obligations, it is necessary to apply both regimes in parallel. At the same time, it confirms that supervision over the fulfillment of these obligations will henceforth take place in heightened coordination between the CNB and NUKIB, which should contribute to greater legal certainty for entities and more efficient supervisory enforcement.