DORA for Real Estate: ICT Risk Management for PropTech and Property Managers
The Digital Operational Resilience Act (DORA, EU Regulation 2022/2554) became fully applicable on 17 January 2025. Designed to ensure that Europe's financial sector can withstand, respond to and recover from all ICT-related disruptions and threats, DORA has a reach that extends far beyond traditional banks and insurers — and the real estate sector is no exception.
From REITs and real estate investment funds to mortgage fintechs, crowdfunding platforms and PropTech companies supplying services to regulated financial entities, the obligations under DORA are creating a new compliance landscape across the entire real estate value chain. This guide explains who is affected, what they must do, and how IgeraRegTech helps you stay on top of every requirement.
What is DORA and who is directly in scope?
DORA creates a comprehensive, binding framework for ICT risk management across more than 22,000 EU financial entities. Directly in-scope entities include:
- Credit institutions (banks, credit unions, savings banks)
- Payment and e-money institutions
- Insurance and reinsurance undertakings
- Investment firms and asset managers (including REITs and real estate investment funds)
- Crowdfunding service providers (including real estate crowdfunding platforms licensed under ECSP Regulation)
- Crypto-asset service providers
- Central counterparties and central securities depositories
For the real estate sector, the key in-scope entities are REITs (SOCIMIs in Spain, SIICs in France, UK-REITs in the United Kingdom), real estate investment funds, mortgage fintechs operating as credit intermediaries, and real estate crowdfunding platforms authorised under the ECSP Regulation (EU 2020/1503).
The ICT supply chain: where PropTech fits in
Chapter V of DORA — on third-party ICT risk management — is the most transformative provision for the broader PropTech ecosystem. Any technology company providing services to an in-scope financial entity must now meet new contractual and operational standards. PropTech companies that may be affected as ICT third-party providers include:
- Asset management platforms used by real estate funds or REITs
- Automated Valuation Model (AVM) providers integrated into mortgage underwriting processes
- Digital due diligence platforms for real estate private equity funds
- E-signature and document management solutions for financial-grade contracts
- Building management system (BMS) and IoT cybersecurity providers serving regulated entities
- Cloud providers hosting financial data related to real estate portfolios
Key point: If your PropTech company provides services to a bank, insurer or investment fund, you will almost certainly be asked to comply with DORA-derived contractual clauses. Failure to do so may cost you the contract.
The five pillars of DORA and their real estate implications
1. ICT risk management framework
Financial entities must maintain a robust ICT risk management framework covering identification, protection, detection, response and recovery (the DORA version of NIST's Cybersecurity Framework). For a REIT or real estate fund, this means mapping every digital system that supports operations — from the asset management ERP to online leasing platforms and investor portals.
2. ICT-related incident management, classification and reporting
DORA establishes a clear taxonomy of ICT incidents. Major ICT incidents must be reported to competent supervisory authorities following a three-step process:
- Initial notification: within 4 hours of detection (or a maximum of 24 hours)
- Intermediate report: within 72 hours with impact analysis and current status
- Final report: within 30 days with root cause analysis and remediation measures
For real estate fund managers, a ransomware attack that compromises investor data or blocks access to NAV calculation systems could qualify as a major incident under DORA, triggering mandatory reporting obligations.
3. Digital operational resilience testing
DORA mandates regular testing of ICT systems. For most entities, this includes annual vulnerability assessments and penetration tests. Significant entities must additionally conduct advanced Threat-Led Penetration Tests (TLPT) every three years, following the TIBER-EU framework.
4. Third-party ICT risk management
This is the pillar that most impacts the PropTech supply chain. In-scope financial entities must:
- Maintain a complete register of all contractual arrangements with ICT third-party providers
- Distinguish between providers supporting «critical or important functions» and those that do not
- Include mandatory minimum contractual clauses (audit rights, SLAs, exit plans)
- Perform pre-contract due diligence and periodic reviews of critical ICT providers
Critical third-party providers (CTPPs) can be designated directly by the European Supervisory Authorities (EBA, ESMA, EIOPA) and placed under a direct oversight framework that includes on-site inspections and information requirements.
5. Information and intelligence sharing
DORA actively encourages voluntary sharing of cyber threat intelligence between financial entities. For the real estate sector, participating in these arrangements can be a competitive advantage, enabling earlier detection of vulnerabilities before they are exploited.
When does DORA apply to property managers and estate agents?
The most common question we receive: does a traditional property management firm or estate agency need to comply with DORA?
The short answer is: not directly, unless the firm manages third-party assets under a financial licence. A property management company managing residential communities or commercial leases is not a regulated financial entity under DORA.
However, indirect application may arise when:
- The property manager acts as a service provider for a real estate investment fund (a DORA-regulated client)
- The company has obtained a licence to manage investment funds or financial assets
- The firm operates a real estate crowdfunding platform with an ECSP licence
- The technology platforms used by the property manager are themselves ICT providers to financial entities
Real-world scenario: A property management firm that also manages a real estate investment fund with €15 million in assets under management is directly in scope for DORA. The «simplified regime» for small entities under DORA does not exempt firms from core ICT risk management requirements.
Mandatory contractual clauses: what ICT vendors must provide
If your PropTech or real estate software company provides services to a financial entity, you have likely already received — or will soon receive — a request to update your contract to include the minimum clauses required by DORA (Article 30). These mandatory provisions include:
- Full description of services with measurable quality levels (SLAs)
- Locations (countries) from which services will be provided and data stored
- Provisions on availability, authenticity, integrity and confidentiality of data
- Audit rights for the client and supervisory authorities
- Business continuity and incident management plans
- Exit strategies and data portability provisions at contract termination
- Obligation to cooperate with European Supervisory Authorities if designated as a CTPP
Resilience testing requirements for PropTech vendors
While DORA testing obligations fall formally on the in-scope financial entity, ICT third-party providers must participate in tests and, in many cases, provide evidence of their own security testing programmes. The most relevant tests for PropTech companies include:
- Vulnerability assessments: Regular scanning of applications and infrastructure for known vulnerabilities
- Penetration testing: At least annual penetration tests of production systems
- Tabletop exercises: Incident simulation exercises with response teams
- Business continuity tests: Verification that declared RTO/RPO targets are achievable
Holding certifications such as ISO 27001 or SOC 2 Type II significantly simplifies demonstrating compliance to financial clients and can become a key commercial differentiator in the professional real estate market.
DORA compliance at a glance: real estate entity types
| Entity type | DORA scope | Supervisor (EU) | Requirement level |
|---|---|---|---|
| REIT / Real estate investment fund | Yes, directly | ESMA / national NCA | Full |
| Real estate crowdfunding platform (ECSP) | Yes, directly | ESMA / national NCA | Proportionate |
| Mortgage fintech (credit intermediary) | Partially | EBA / national NCA | Simplified |
| Traditional property management firm | Not directly | — | No own requirements |
| PropTech serving a financial entity | Yes, indirectly | Via financial client | Contractual |
For more information and a reference guide about this vertical, visit our Igera pillar page.
How IgeraRegTech helps you navigate DORA
IgeraRegTech is the regulatory intelligence platform that indexes, updates and synthesises the full body of European financial regulation — including the complete text of DORA Regulation 2022/2554, all derived Regulatory Technical Standards (RTS) and Implementing Technical Standards (ITS), plus EBA, ESMA and EIOPA guidelines on DORA.
With IgeraRegTech you can:
- Ask natural-language questions about DORA and receive answers citing the exact article and paragraph
- Map DORA requirements to your specific situation (entity type, size, services provided)
- Receive automatic alerts when new supervisory guidance on DORA is published
- Generate board-level executive summaries on your DORA compliance status
- Access validated templates for DORA minimum contractual clauses
Start complying with DORA without wasting time searching for regulations
IgeraRegTech indexes the complete DORA documentation: regulation, RTS, ITS, supervisory Q&As and sector-specific case studies. Ask what you need and get the answer with an exact article reference.
Explore IgeraRegTechWhat is Igera and how does its technology work?
Igera provides AI-driven SaaS solutions based on RAG (Retrieval-Augmented Generation) that answer complex queries by securely indexing internal company documents.
Do Igera's chatbots experience hallucinations?
No. By limiting the model's knowledge base to authorized client documents uploaded by the customer, Igera prevents the generation of fictional information by design.
How is sensitive corporate data protected?
All information is processed and stored on secure servers within the European Union, complying with the most demanding encryption standards and with GDPR.
Which sectors benefit from Igera's solutions?
We offer optimized verticals for community management (IgeraFincas), law firms (IgeraLegal), accountancy (IgeraGestories), human resources (IgeraHR), hospitality (IgeraHospit), and regulation (IgeraRegTech).
Does it support integration with existing enterprise systems?
Yes, our tools are ready to integrate via APIs and native connectors with the most common CRM, ERP, and database systems in each sector.
What languages does the platform support?
The platform automatically detects the end user's query language and is capable of interacting in English, Spanish, Catalan, Portuguese, French, and German.