The EU Digital Operational Resilience Act (DORA — Regulation EU 2022/2554) entered into force on 17 January 2025. If your managing agent firm processes financial transactions, handles service charge accounts for leaseholders, or relies on third-party PropTech software, you need to understand what ICT third-party risk management means in practice — and whether any of your obligations have just changed.
DORA (EU 2022/2554): A directly applicable EU regulation requiring financial entities and their critical ICT third-party service providers to meet binding standards for digital operational resilience — covering risk management, incident reporting, testing, and third-party oversight. It applies across all EU member states from January 2025.
73%
"of financial services firms reported at least one significant ICT third-party incident in the past 24 months, driving the European Commission to mandate DORA"
— European Banking Authority, Digital Resilience Report 2025
Which property management firms fall within DORA's scope?
DORA's primary targets are financial entities as defined in Article 2: credit institutions, payment institutions, insurance companies, investment firms, and crypto-asset service providers. Most residential managing agents are not financial entities under this definition.
However, you are affected in two indirect but significant ways:
1. You manage service charge accounts for financial-sector clients. If you manage properties owned or operated by regulated financial entities (banks, insurers, investment funds), those clients may pass DORA-derived contractual obligations down to you as a supplier. Expect ICT questionnaires, supplier audits, and mandatory incident notification clauses in your management agreements.
2. Your PropTech software providers may be designated Critical Third-Party ICT Providers (CTPPs). Under Article 31, the European Supervisory Authorities can designate large cloud providers and software vendors as CTPPs. If your property management software sits on a cloud infrastructure designated as a CTPP, your provider faces direct oversight — and you benefit from greater transparency about their resilience posture.
What is ICT third-party risk management (TPRM) and why does it matter for managing agents?
Third-party risk management means systematically assessing, monitoring, and contractually governing every external supplier that touches your digital operations. For a managing agent, that includes:
- Your property management software (accounting, meeting minutes, document storage)
- Payment processors handling service charge collections
- Cloud storage providers holding leaseholder data
- Communication platforms for resident portals or WhatsApp integration
- AI assistants trained on community documents
Even if you are not directly in scope, best-practice TPRM protects you. An outage at your software provider on the day of an AGM, or a data breach exposing leaseholder financial records, creates liability under UK GDPR and erodes trust with your clients.
What does Article 30 of DORA require in supplier contracts?
Article 30 sets out mandatory contractual provisions for ICT third-party service agreements entered into by in-scope financial entities. These provisions are increasingly being mirrored in supplier contracts throughout the PropTech supply chain. When reviewing your software agreements, look for:
- Service level descriptions: Clear, measurable uptime and performance commitments (not vague best-efforts language).
- Incident notification: The provider must notify you of any ICT incident that could affect the services you receive, within defined timelines.
- Data location and access rights: You must be able to audit the provider and access your data on termination without penalty.
- Sub-contracting chains: The provider must disclose any sub-processors and obtain your consent before making material changes.
- Business continuity: The supplier must maintain and test a business continuity plan relevant to the services you use.
- Termination rights: You must be able to exit the contract if the provider can no longer meet resilience standards, without prohibitive exit fees.
If your current PropTech contracts lack these clauses, you face gaps that a sophisticated client — or their compliance team — will flag at the next contract renewal.
What incident notification timelines apply under DORA?
For entities directly in scope, DORA mandates a three-step reporting sequence. Even as an out-of-scope managing agent, understanding these timelines helps you set contractual expectations with your own software providers:
Initial notification: Within 4 hours of classifying an incident as major. This requires your provider to have detection and classification procedures that operate 24/7.
Intermediate report: Within 72 hours. Updated details on the incident's scope, affected services, and initial root-cause analysis.
Final report: Within one month of the incident being resolved. Full post-incident review, root-cause determination, and remediation steps.
In practice, when negotiating your PropTech contracts, request contractual commitments for a 4-hour initial notification and a 72-hour detailed update for any incident that affects your ability to access leaseholder data or collect service charges.
How should you conduct due diligence on your PropTech suppliers?
Formal due diligence does not require an enterprise security team. Start with these practical steps:
Request their ICT security documentation. Reputable providers should supply ISO 27001 certification, SOC 2 Type II reports, or equivalent. If a provider cannot produce any third-party security assurance, treat that as a material risk.
Ask about their disaster recovery (DR) and business continuity plan (BCP). Specifically: what is their recovery time objective (RTO) and recovery point objective (RPO)? If their RTO is 72 hours and you have AGMs to run, that matters.
Review data residency. Post-Brexit UK GDPR requires appropriate safeguards for data transferred to non-adequate countries. Confirm where your leaseholder data sits and what transfer mechanism the provider relies on.
Check sub-processor lists. A property management platform built on AWS or Azure with a payment module from a third provider means at least three organisations hold your data. Each link in the chain is a risk.
Annual reassessment. Third-party risk is not a one-off exercise. Build supplier reassessment into your annual compliance calendar.
What should you do if your software provider has an outage?
No platform is immune to downtime. Your business continuity plan should cover the following scenarios:
Short outage (under 4 hours): Communicate proactively to leaseholders via SMS or email. Delay non-urgent tasks. Document the outage for your own incident log.
Extended outage (4–24 hours): Activate manual fallback procedures for service charge payment processing. Notify any leaseholders with urgent maintenance queries through an alternative channel. Trigger your contractual right to a formal incident notification from your provider.
Critical outage (over 24 hours or data loss): Assess whether the incident triggers a UK GDPR data breach notification obligation (72 hours to the ICO if personal data is at risk). Engage your professional indemnity insurer. Review your exit rights under the supplier contract.
How IgeraFincas resolves this
Managing agent's question:
"Our cloud provider had a 6-hour outage last month. What are our notification obligations and how do we prove to clients we have resilience controls?"
IgeraFincas responds:
"Under your supplier contract (Art. 30 DORA-aligned clause), a 6-hour service disruption triggers the 4-hour initial notification obligation. IgeraFincas maintains a 99.9% SLA with automated incident alerts, geo-redundant data storage in EU-compliant data centres, and a documented RTO of under 2 hours. Your incident log for this event has been automatically generated. Would you like to export it for your client compliance report?"
How does DORA interact with UK regulation after Brexit?
DORA is EU law and does not apply directly in Great Britain. The UK's equivalent framework is the FCA's Operational Resilience rules (PS21/3), which share many of the same principles — impact tolerance setting, important business service identification, and third-party risk governance — but follow a different timeline and scope.
For managing agents operating across both jurisdictions, or serving EU-based property funds, maintaining DORA-aligned supplier contracts is sensible. The substantive requirements of Article 30 are broadly consistent with what the FCA expects of regulated firms anyway. Aligning your supplier governance to the higher standard protects you in both markets.
Does your current property management platform have the resilience documentation your clients are starting to ask for?
IgeraFincas provides ISO-aligned security documentation, EU-resident data storage, and automated incident logs — ready for your next client audit.
Try free for 14 days — no credit cardIn summary: DORA and ICT third-party risk for property managers
- Most managing agents are not directly in scope, but are indirectly affected through client contracts and PropTech supplier chains.
- Article 30 contractual clauses — covering incident notification, audit rights, sub-processors, and exit rights — are now standard expectations in any serious software agreement.
- Conduct annual due diligence on your PropTech providers: request ISO 27001 or SOC 2 reports, confirm data residency, and check BCP/RTO commitments.
- Have a written outage response plan: short, extended, and critical scenarios each require different actions, including potential UK GDPR breach notification.
- Choosing a provider that documents its resilience posture proactively reduces your compliance burden significantly.
FAQ
Does DORA apply to UK managing agents after Brexit?
DORA applies directly only to entities operating within the EU regulatory perimeter. UK-based managing agents are not in scope unless they also hold authorisations from an EU financial regulator. However, UK-regulated counterparts face similar obligations under the FCA's Operational Resilience rules (PS21/3). Managing agents with EU clients or operating cross-border should align supplier contracts to DORA standards as a practical minimum.
What counts as a "critical" ICT third-party provider under DORA?
The European Supervisory Authorities (EBA, ESMA, EIOPA) designate Critical Third-Party ICT Providers (CTPPs) under Article 31 criteria: systemic importance across multiple financial entities, the concentration risk of widespread use, and the difficulty of substitution. Major cloud infrastructure providers (hyperscalers) and large payment processing networks are the most likely candidates. Your niche property management software is unlikely to be designated, but if it runs on hyperscaler infrastructure, that hyperscaler may be.
What happens if our software provider has a data breach affecting leaseholder records?
If personal data held by your processor is compromised, you as the data controller remain responsible under UK GDPR. You must assess whether the breach is notifiable to the ICO within 72 hours and, where the risk to individuals is high, notify affected leaseholders without undue delay. Your processor should have contractual obligations to alert you immediately upon discovering the breach — if your current contract lacks this clause, add it at the next renewal.
How do we assess whether our PropTech supplier meets DORA-aligned standards?
Start with a written questionnaire covering: security certifications (ISO 27001, SOC 2 Type II), data residency and transfer mechanisms, sub-processor disclosures, RTO/RPO commitments, incident notification procedures, and the existence of a tested BCP. Reputable suppliers will answer these questions directly and provide supporting documentation. Suppliers who cannot provide any third-party assurance report should be treated as elevated risk in your supplier register.
Can leaseholders claim compensation if a software outage disrupts service charge management?
Leaseholder rights under the Landlord and Tenant Act 1985 relate to the landlord's obligation to maintain the property, not directly to your software availability. However, if an outage prevents you from issuing demands in the correct statutory form or causes a demonstrable loss, professional indemnity claims are possible. Your management agreement should contain force majeure provisions covering third-party technology failures, and you should maintain comprehensive PI insurance that covers technology-related service failures.
Is there a UK equivalent of DORA for property management firms?
There is no specific UK operational resilience regulation targeting managing agents. The relevant frameworks are UK GDPR (data protection), the FCA's Operational Resilience rules (for regulated firms), and ARMA's professional standards. The Property Institute (TPI) and IRPM both expect members to maintain adequate business continuity arrangements as part of professional conduct obligations. These do not carry the same prescriptive requirements as DORA, but they set the professional standard against which your firm would be judged in a dispute.
Editorial note: This article is for informational purposes only and does not constitute legal or regulatory advice. DORA requirements and their interpretation continue to evolve as technical standards are finalised by the European Supervisory Authorities. Managing agents with clients in regulated financial sectors should seek specialist legal advice on their specific obligations. Last reviewed June 2026.