generated: '2026-07-27' method: searched source: >- Derived from openapi/energy-queensland-cds-energy-openapi.yml and openapi/energy-queensland-cds-common-openapi.yml (DSB Consumer Data Standards v1.36.0), the CDR Register entry for Ergon Energy Retail, and live standards-conformance probes of both anonymous surfaces on 2026-07-27. description: >- Which cross-cutting and industry standards Ergon Energy Retail's API surface actually conforms to - and, just as importantly, which energy-sector standards are entirely absent from Energy Queensland's public estate. Conformance here is unusually well evidenced because the Consumer Data Standards make it behavioural: version negotiation, pagination bounds and error URNs can all be tested anonymously, and were. standards: - id: cds-au-consumer-data-standards name: CDR Consumer Data Standards (energy) v1.36.0 conforms: true evidence: >- Live behavioural conformance confirmed 2026-07-27, not claimed. The registered public base URI serves the Common API discovery endpoints with the correct CDS envelope; the AER-hosted Ergon brand path serves Get Generic Plans (36 REGULATED plans, correct meta/links); version negotiation returns the exact standardised URNs (Header/UnsupportedVersion at 406, Header/InvalidVersion and Header/Missing at 400); pagination enforces the 1000-record page-size ceiling with Field/InvalidPageSize and out-of-range pages with Field/InvalidPage at 422. docs: https://consumerdatastandardsaustralia.github.io/standards/ - id: cdr-register-listed name: ACCC CDR Register - designated energy data holder brand conforms: true evidence: >- GET https://api.cdr.gov.au/cdr-register/v1/energy/data-holders/brands/summary (x-v 2) returned HTTP 200 on 2026-07-27 with 84 energy brands. Ergon Energy Retail present - dataHolderBrandId 3a732abd-b2e1-ee11-a73d-6045bd4001ae, abn 11121177802, publicBaseUri https://public.cdr.ergonretail.com.au, productBaseUri https://cdr.energymadeeasy.gov.au/ergon, lastUpdated 2026-07-01T12:15:26Z. Neither Energex nor Ergon Energy Network appears - distribution network service providers are not designated. - id: oauth2 conforms: true evidence: >- The consumer-authorised surface uses OAuth2 authorization code flow with PKCE and PAR per the CDS Security Profile. Documented, not observed - the authorisation and token endpoints are published only through the authenticated portion of the CDR Register. docs: https://consumerdatastandardsaustralia.github.io/standards/#security-profile - id: oidc name: OpenID Connect conforms: true evidence: >- Required by the CDS Security Profile (openid + profile scopes, id_token). Anonymous discovery is deliberately unavailable - /.well-known/openid-configuration returned HTTP 404 on public.cdr.ergonretail.com.au on 2026-07-27. - id: fapi-1-advanced name: FAPI 1.0 Advanced security profile conforms: true evidence: >- Mandated by the CDS Security Profile for all CDR data holders; private_key_jwt client authentication and mTLS sender-constrained tokens. Behavioural corroboration - x-fapi-interaction-id is honoured and played back on the anonymous surface, and api.cdr.ergonretail.com.au demands a client certificate. - id: mutual-tls name: Mutual TLS (RFC 8705 style transport binding) conforms: true evidence: >- The resource host api.cdr.ergonretail.com.au emits "Request CERT (13)" in its TLS handshake with a private CDR certificate chain - observed directly. - id: rfc4122-uuid-correlation conforms: true evidence: x-fapi-interaction-id RFC 4122 UUID sent and played back verbatim on 2026-07-27. - id: rfc9457-problem-details conforms: false evidence: >- The Consumer Data Standards define their own error envelope ({"errors":[{code,title,detail}]} with urn:au-cds:error:... codes) served as application/json. No application/problem+json anywhere in either spec or in any live response. - id: pagination-page-number conforms: true evidence: >- page / page-size query parameters with meta.totalRecords, meta.totalPages and links first/prev/self/next/last; 1000-record ceiling enforced live. - id: idempotency conforms: false evidence: >- No idempotency key header in either specification and none documented in the standard. The surface is read-only; the four POST operations are id-list queries that create nothing. - id: openapi-3 conforms: true evidence: >- Both harvested contracts are OpenAPI 3.0.3. They are the shared DSB standard documents, not Energy Queensland publications - no entity in the group publishes an OpenAPI of its own. - id: asyncapi conforms: false evidence: >- No event, streaming or webhook surface of any kind. The CDR outage disclosure is a polled GET /discovery/outages endpoint, not an event feed. - id: green-button-espi name: Green Button / NAESB ESPI conforms: false evidence: No Green Button or ESPI reference anywhere on the Energy Queensland estate. - id: ieee-2030-5 name: IEEE 2030.5 (SEP2) conforms: false evidence: Not published in any developer-facing form. - id: openadr conforms: false evidence: Not published in any developer-facing form. - id: ocpp-ocpi name: OCPP / OCPI (EV charging) conforms: false evidence: Not published in any developer-facing form. - id: iec-cim-61968-61970 name: IEC CIM 61968 / 61970 conforms: false evidence: >- No public CIM-based interface. This is the notable absence for a 2.3-million-connection distribution network operator. - id: iso-19115 name: ISO 19115 geospatial metadata conforms: true evidence: >- The one open-licensed Ergon distribution network dataset on the Queensland Government CKAN portal carries an ISO 19115 XML metadata record in the Queensland Spatial catalogue (HTTP 200, 2026-07-27 round). A cataloguing standard, not an API standard. - id: nem12-nem13 name: AEMO NEM12 / NEM13 metering file formats conforms: partial evidence: >- Not an API contract. The group's GitHub organisation forks nem-reader (NEM12/NEM13 parser) and SparkMMS (AEMO MMS data model), which evidences the internal data formats it works in. No public interface implements them. compliance: program: statutory - Consumer Data Right designation under Part IVD of the Competition and Consumer Act 2010 (Cth) regulator: Australian Competition and Consumer Commission (ACCC) standards_body: Treasury Data Standards Body verifiable_register: https://api.cdr.gov.au/cdr-register/v1/energy/data-holders/brands/summary status: live-implemented conformance_testing: >- CDR Conformance Test Suite (CTS) testing is required of participants by the ACCC. No CTS result for Ergon Energy Retail is published publicly; the register listing plus the live standards-conformant responses are the evidence relied on here. certifications_published: [] certifications_note: >- NO security or privacy certification is published anywhere on the Energy Queensland estate - no SOC 2, ISO 27001, PCI DSS, HIPAA, FedRAMP or CSA STAR claim, and no trust centre. The corporate sites sit behind a Cloudflare challenge that returns 403 to every programmatic client, so even if such a page exists it is not publicly observable. The compliance posture recorded here is regulatory, not certification-based.