The five pillars of DORA and their real estate implications
1. ICT risk management framework
Financial entities must maintain a robust ICT risk management framework covering identification, protection, detection, response and recovery (the DORA version of NIST's Cybersecurity Framework). For a REIT or real estate fund, this means mapping every digital system that supports operations — from the asset management ERP to online leasing platforms and investor portals.
DORA establishes a clear taxonomy of ICT incidents. Major ICT incidents must be reported to competent supervisory authorities following a three-step process:
- Initial notification: within 4 hours of detection (or a maximum of 24 hours)
- Intermediate report: within 72 hours with impact analysis and current status
- Final report: within 30 days with root cause analysis and remediation measures
For real estate fund managers, a ransomware attack that compromises investor data or blocks access to NAV calculation systems could qualify as a major incident under DORA, triggering mandatory reporting obligations.
3. Digital operational resilience testing
DORA mandates regular testing of ICT systems. For most entities, this includes annual vulnerability assessments and penetration tests. Significant entities must additionally conduct advanced Threat-Led Penetration Tests (TLPT) every three years, following the TIBER-EU framework.
4. Third-party ICT risk management
This is the pillar that most impacts the PropTech supply chain. In-scope financial entities must:
- Maintain a complete register of all contractual arrangements with ICT third-party providers
- Distinguish between providers supporting «critical or important functions» and those that do not
- Include mandatory minimum contractual clauses (audit rights, SLAs, exit plans)
- Perform pre-contract due diligence and periodic reviews of critical ICT providers
Critical third-party providers (CTPPs) can be designated directly by the European Supervisory Authorities (EBA, ESMA, EIOPA) and placed under a direct oversight framework that includes on-site inspections and information requirements.
DORA actively encourages voluntary sharing of cyber threat intelligence between financial entities. For the real estate sector, participating in these arrangements can be a competitive advantage, enabling earlier detection of vulnerabilities before they are exploited.
When does DORA apply to property managers and estate agents?
The most common question we receive: does a traditional property management firm or estate agency need to comply with DORA?
The short answer is: not directly, unless the firm manages third-party assets under a financial licence. A property management company managing residential communities or commercial leases is not a regulated financial entity under DORA.
However, indirect application may arise when:
- The property manager acts as a service provider for a real estate investment fund (a DORA-regulated client)
- The company has obtained a licence to manage investment funds or financial assets
- The firm operates a real estate crowdfunding platform with an ECSP licence
- The technology platforms used by the property manager are themselves ICT providers to financial entities
Real-world scenario: A property management firm that also manages a real estate investment fund with €15 million in assets under management is directly in scope for DORA. The «simplified regime» for small entities under DORA does not exempt firms from core ICT risk management requirements.
Mandatory contractual clauses: what ICT vendors must provide
If your PropTech or real estate software company provides services to a financial entity, you have likely already received — or will soon receive — a request to update your contract to include the minimum clauses required by DORA (Article 30). These mandatory provisions include:
- Full description of services with measurable quality levels (SLAs)
- Locations (countries) from which services will be provided and data stored
- Provisions on availability, authenticity, integrity and confidentiality of data
- Audit rights for the client and supervisory authorities
- Business continuity and incident management plans
- Exit strategies and data portability provisions at contract termination
- Obligation to cooperate with European Supervisory Authorities if designated as a CTPP
Resilience testing requirements for PropTech vendors
While DORA testing obligations fall formally on the in-scope financial entity, ICT third-party providers must participate in tests and, in many cases, provide evidence of their own security testing programmes. The most relevant tests for PropTech companies include:
- Vulnerability assessments: Regular scanning of applications and infrastructure for known vulnerabilities
- Penetration testing: At least annual penetration tests of production systems
- Tabletop exercises: Incident simulation exercises with response teams
- Business continuity tests: Verification that declared RTO/RPO targets are achievable
Holding certifications such as ISO 27001 or SOC 2 Type II significantly simplifies demonstrating compliance to financial clients and can become a key commercial differentiator in the professional real estate market.
DORA compliance at a glance: real estate entity types
| Entity type | DORA scope | Supervisor (EU) | Requirement level |
|---|
| REIT / Real estate investment fund | Yes, directly | ESMA / national NCA | Full |
| Real estate crowdfunding platform (ECSP) | Yes, directly | ESMA / national NCA | Proportionate |
| Mortgage fintech (credit intermediary) | Partially | EBA / national NCA | Simplified |
| Traditional property management firm | Not directly | — | No own requirements |
| PropTech serving a financial entity | Yes, indirectly | Via financial client | Contractual |
For more information and a reference guide about this vertical, visit our Igera pillar page.
How IgeraRegTech helps you navigate DORA
IgeraRegTech is the regulatory intelligence platform that indexes, updates and synthesises the full body of European financial regulation — including the complete text of DORA Regulation 2022/2554, all derived Regulatory Technical Standards (RTS) and Implementing Technical Standards (ITS), plus EBA, ESMA and EIOPA guidelines on DORA.
With IgeraRegTech you can:
- Ask natural-language questions about DORA and receive answers citing the exact article and paragraph
- Map DORA requirements to your specific situation (entity type, size, services provided)
- Receive automatic alerts when new supervisory guidance on DORA is published
- Generate board-level executive summaries on your DORA compliance status
- Access validated templates for DORA minimum contractual clauses
Start complying with DORA without wasting time searching for regulations
IgeraRegTech indexes the complete DORA documentation: regulation, RTS, ITS, supervisory Q&As and sector-specific case studies. Ask what you need and get the answer with an exact article reference.
Explore IgeraRegTechWhat is Igera and how does its technology work?
Igera provides AI-driven SaaS solutions based on RAG (Retrieval-Augmented Generation) that answer complex queries by securely indexing internal company documents.
Do Igera's chatbots experience hallucinations?
No. By limiting the model's knowledge base to authorized client documents uploaded by the customer, Igera prevents the generation of fictional information by design.
How is sensitive corporate data protected?
All information is processed and stored on secure servers within the European Union, complying with the most demanding encryption standards and with GDPR.
Which sectors benefit from Igera's solutions?
We offer optimized verticals for community management (IgeraFincas), law firms (IgeraLegal), accountancy (IgeraGestories), human resources (IgeraHR), hospitality (IgeraHospit), and regulation (IgeraRegTech).
Does it support integration with existing enterprise systems?
Yes, our tools are ready to integrate via APIs and native connectors with the most common CRM, ERP, and database systems in each sector.
The platform automatically detects the end user's query language and is capable of interacting in English, Spanish, Catalan, Portuguese, French, and German.