generated: '2026-07-27' method: derived source: >- openapi/ferc-data-api-openapi.json, openapi/ferc-eforms-api-openapi-derived.yml, https://www.ferc.gov/media/ferc-vulnerability-disclosure-policy, live probes 2026-07-27 note: >- FERC is a U.S. federal agency, so its compliance posture is statutory rather than certified: there is no SOC 2, no ISO 27001, no PCI DSS and no trust centre, and there never will be. What it does conform to is the federal web/security baseline (BOD 20-01, HTTPS-only, DNSSEC) and, on the filing side, the XBRL standards stack. standards: - id: openapi-3.0 conforms: true evidence: >- FERC publishes an OpenAPI 3.0.0 document at https://data.ferc.gov/openapi.json describing all four Open Data API operations. gaps: >- No `servers` block (uses the Swagger 2.0 `host`/`schemes` keys, and the host recorded is api-staging.data.ferc.gov, not production); no `info.version`; no `info.contact`; no named component schemas — response bodies are inline untyped objects with examples. - id: oauth2 conforms: true evidence: >- eForms POST /api/token implements the RFC 6749 section 4.3 Resource Owner Password Credentials grant (grant_type=password, role=filer) and returns a bearer token. note: Password grant only; no authorization code, no PKCE, no refresh flow published, no scopes. - id: oauth2-security-bcp conforms: false evidence: >- The password grant is deprecated by OAuth 2.0 Security BCP (RFC 9700) and removed in OAuth 2.1. FERC's filing API depends on it. - id: rfc8414-oauth-metadata conforms: false evidence: >- /.well-known/oauth-authorization-server returns the SPA HTML shell (HTTP 200, text/html) on ecollection.ferc.gov and 404 elsewhere. No authorization-server metadata document. - id: oidc conforms: false evidence: /.well-known/openid-configuration not served on any FERC host probed. - id: apikey-auth conforms: true evidence: >- X-Api-Key header (recommended) or api_key query parameter, enforced by the api.data.gov API Umbrella gateway. - id: rfc9457-problem-details conforms: false evidence: >- Errors use custom envelopes — {"error":{"code","message"}} on the Open Data API and {"message"} / {"error"} on eForms. No application/problem+json anywhere. - id: rfc9116-security-txt conforms: false evidence: >- /.well-known/security.txt returns 404 on www.ferc.gov, ferc.gov, data.ferc.gov and api.data.ferc.gov (probed 2026-07-27). FERC publishes a full VDP as a PDF instead. - id: bod-20-01-vulnerability-disclosure conforms: true evidence: >- FERC publishes a Vulnerability Disclosure Policy (v3.0, 25 February 2025) explicitly issued under CISA Binding Operational Directive 20-01, with named scope, safe-harbour authorization, a reporting mailbox and a three-business-day acknowledgement commitment. detail: security/ferc-vulnerability-disclosure.yml - id: rfc8594-sunset-header conforms: false evidence: No Sunset or Deprecation headers observed; no deprecation policy published. - id: rest-pagination conforms: false evidence: >- No pagination on any operation. FERC documents that the Data endpoint returns the entire dataset with no filtering; /PublicSubmissionHistory returns 37,588 records in one response. - id: idempotency-keys conforms: false evidence: No idempotency key on the one published write operation. - id: json-api conforms: false - id: odata conforms: false - id: http-strict-transport-security conforms: true evidence: >- HSTS with max-age=31536000 on www.ferc.gov, data.ferc.gov, api.data.ferc.gov (includeSubDomains + preload) and ecollection.ferc.gov (includeSubDomains). detail: security/ferc-domain-security.yml - id: dnssec conforms: true evidence: DNSSEC enabled on ferc.gov; CAA, SPF and DMARC (p=reject) all published. - id: tls-1.3 conforms: partial evidence: >- TLS 1.3 on www.ferc.gov, data.ferc.gov and api.data.ferc.gov; ecollection.ferc.gov negotiated TLS 1.2 (ECDHE-RSA-AES256-GCM-SHA384) on 2026-07-27. - id: xbrl-2.1 conforms: true evidence: >- FERC eForms filings are XBRL instances validated against FERC-published taxonomies; the submission API accepts a zip containing "the submission and any associated additional files as per XBRL specification". - id: inline-xbrl conforms: true evidence: >- FERC publishes a rendering tool as an Arelle plugin that generates Inline XBRL HTML from a filing, and stores an HTML_RENDERING attachment alongside every XBRL_INSTANCE_FILE. - id: xule-validation conforms: true evidence: >- Validation rules are coded in XULE and published as a ruleset file per form category (Form 1, 2, 6, 60, 714) in the vendor files library. - id: xbrl-taxonomy-packages conforms: true evidence: >- GET /api/TaxonomyHistory exposes dated taxonomy releases with published .xsd URLs per form, and /api/TaxonomyHistory/TaxonomyFile/{versionID} serves the packaged taxonomy. - id: naesb-wgq-weq conforms: true evidence: >- FERC incorporates NAESB Wholesale Gas Quadrant and Wholesale Electric Quadrant business practice standards by reference into its regulations. This is a regulatory adoption, not an API conformance claim — FERC's own APIs do not implement NAESB interfaces. - id: green-button-espi conforms: false evidence: >- Green Button / ESPI is NAESB Retail Electric Quadrant Book 21. FERC has no retail jurisdiction, has not adopted it, and publishes no consumer energy data of any kind. - id: asyncapi conforms: false evidence: No event, streaming or webhook surface on either API — nothing to describe. certifications: [] certifications_note: >- None. FERC publishes no SOC 2, ISO 27001, PCI DSS, HIPAA, FedRAMP or CSA STAR attestation and no trust centre. As a federal agency its assurance regime is FISMA plus OMB Circular A-130, both cited as authority in its own Vulnerability Disclosure Policy. statutory_authority: - Binding Operational Directive 20-01 (CISA) - Federal Information Security Modernization Act (FISMA) of 2014, Pub. L. 113-283 - OMB Circular A-130, Appendix III - 44 U.S.C. 3552(b)(1), 3553, 3554