generated: '2026-07-25' method: derived source: openapi/acma-spectrum-licensing-openapi.yml also_derived_from: - wsdl/acma-spectrum-licensing.wsdl - wsdl/acma-dncr-realtime-washing.wsdl - conventions/acma-conventions.yml summary: >- ACMA's public API surface conforms to the 2000s SOAP/WCF stack, not to the modern REST standards layer. It is genuinely standards-based — WSDL 1.1, SOAP 1.1/1.2, XML Schema, TLS 1.2+ — and genuinely absent from every standard the current API ecosystem takes for granted: no OpenAPI, no OAuth2, no OIDC, no RFC 9457 problem details, no RFC 8594 sunset headers, no RFC 9116 security.txt, no RateLimit header fields. No compliance certification (SOC 2, ISO 27001, IRAP) is published for these services. standards: - id: wsdl-1.1 conforms: true evidence: >- Live WSDL 1.1 documents at api.acma.gov.au/SpectrumLicensingAPIOuterService/OuterService.svc?wsdl (22 operations) and www.donotcall.gov.au/dncrtelem/rtw/washing.cfc?wsdl (3 operations), both retrieved anonymously with HTTP 200 on 2026-07-25. - id: soap-1.1 conforms: true evidence: WSDL declares soap and soap12 bindings; ACMA documents a dedicated SOAP endpoint path. - id: xml-schema conforms: true evidence: >- XSD documents served from the endpoint at ?xsd=xsd0, ?xsd=xsd1, ?xsd=xsd2 and harvested to wsdl/acma-spectrum-licensing-xsd*.xsd. - id: rest conforms: partial evidence: >- Resource-ish GET-only URLs with a WCF UriTemplate, but format is selected by operation-name suffix (…XML / …JSON) rather than by Accept header, JSON is served as application/octet-stream, and there is no hypermedia beyond a DETAILS_URL string pointing at the human web register. - id: openapi conforms: false evidence: >- ACMA publishes no OpenAPI or Swagger document on any host. Probed /openapi.json, /openapi.yaml, /swagger.json, /v1/openapi.json, /swagger/v1/swagger.json, /api-docs, /docs and /redoc against api.acma.gov.au, developer.acma.gov.au, www.donotcall.gov.au and thenumberingsystem.com.au — all 404 or SPA shell. The OpenAPI in this repo is an API Evangelist reconstruction from ACMA's published guide plus the live WSDL and live responses. - id: oauth2 conforms: false evidence: No oauth2 security scheme anywhere; the open API is unauthenticated and the gated one uses SOAP-body credentials. - id: oidc conforms: false evidence: >- developer.acma.gov.au/.well-known/openid-configuration returns HTTP 200 with text/html — the Azure APIM portal SPA shell, not OIDC metadata. - id: rfc8414-oauth-authorization-server-metadata conforms: false evidence: Same SPA-shell false positive; no JSON metadata served on any host. - id: rfc9457-problem-details conforms: false evidence: >- Errors are WCF/IIS HTML fault pages. No application/problem+json response is defined or returned. See errors/acma-problem-types.yml. - id: rfc8594-sunset-header conforms: false evidence: >- No Sunset or Deprecation header. Deprecation is communicated as the word "Deprecated" printed beside a method in a DOCX guide; the methods were later removed from the WSDL outright. - id: rfc9116-security-txt conforms: false evidence: >- No /.well-known/security.txt on any host, despite a real published vulnerability disclosure policy and a dedicated responsible.disclosure@acma.gov.au mailbox. - id: rfc9727-api-catalog conforms: false evidence: No /.well-known/api-catalog document; the 200 on developer.acma.gov.au is the SPA shell. - id: ietf-ratelimit-headers conforms: false evidence: >- No RateLimit or Retry-After headers. The only limit is a silent 2,000-record response truncation. See rate-limits/acma-rate-limits.yml. - id: pagination conforms: true evidence: >- Offset/limit paging is implemented and documented (offset/resultsLimit and strOffset/strLimit), with TOTAL_RESULT and RESULTS_INDEX denormalised onto each record so a client can plan pages. - id: idempotency conforms: not-applicable evidence: >- Read-only surface — no writes exist to be made idempotent. The metered DNCR WashNumbers call uses a caller-supplied ClientReferenceId as its dedupe/recovery key. - id: tls-1.2 conforms: true evidence: >- ACMA mandates TLS 1.2 or above for the Do Not Call Register SOAP services; live probes of www.acma.gov.au, developer.acma.gov.au and www.donotcall.gov.au all negotiated TLSv1.3. - id: hsts conforms: partial evidence: >- developer.acma.gov.au and www.donotcall.gov.au send HSTS with max-age 31536000; www.acma.gov.au returned no HSTS header to the probe. - id: dnssec conforms: false evidence: Neither acma.gov.au nor donotcall.gov.au is DNSSEC-signed (probed 2026-07-25). - id: caa conforms: false evidence: No CAA records on acma.gov.au or donotcall.gov.au. - id: spf-dmarc conforms: true evidence: Both acma.gov.au and donotcall.gov.au publish SPF and DMARC with policy p=reject. - id: asyncapi conforms: false evidence: >- No event, streaming or webhook surface of any kind. The Do Not Call Register returns washed lists by download and emails a receipt — a batch return, not an event. Not penalised: there is genuinely nothing to describe. - id: camara conforms: false evidence: >- No CAMARA reference anywhere in ACMA's public surface. ACMA is a regulator, not a carrier; CAMARA and GSMA Open Gateway are operator-side commitments. ACMA's bearing on that surface is regulatory — it administers the numbering plan, carrier licences and the anti-scam and identity-verification rules Australian operators must satisfy when exposing network APIs. - id: tmforum-open-api conforms: false evidence: No TM Forum conformance certification or TMF specification reference; not applicable to a regulator. certifications: published: false detail: >- No SOC 2, ISO 27001, PCI DSS, IRAP or FedRAMP-equivalent attestation is published for the Spectrum Licensing API, the Do Not Call Register or the developer portal, and no trust centre exists at trust.acma.gov.au or security.acma.gov.au (both probed, no host). As a Commonwealth entity ACMA operates under the Australian Government Protective Security Policy Framework rather than publishing commercial attestations. legal_instruments: - name: Licence to use the Register of Radiocommunications Licences url: https://www.acma.gov.au/radiocomms-licence-data#terms-and-conditions detail: >- The Spectrum Licensing API's real access control. Grants a non-transferable, non-exclusive licence to use, reproduce, adapt, merge and redistribute derivatives of the Register, but forbids using licensee personal information for unsolicited commercial electronic messages (Spam Act 2003), unsolicited telemarketing (Do Not Call Register Act 2006) or unsolicited mail advertising, and forbids redistributing a natural person's client information in any derivative. Attribution required: "Based on Australian Communications and Media Authority information". - name: Do Not Call Register Act 2006 url: https://www.donotcall.gov.au/industry/industry-overview/register-legislation detail: The statutory basis for the washing service, its subscription fees and the 30-day wash validity window. - name: Radiocommunications Act 1992 detail: The statutory basis for the Register of Radiocommunications Licences that the Spectrum Licensing API projects.