generated: '2026-07-25' method: derived source: openapi/*.yml, well-known/gsma-security.txt, conventions/gsma-conventions.yml note: >- The GSMA is the body that authors and convenes standards rather than one that implements them, so this file records what the specifications it publishes conform to, not what a GSMA-run endpoint does. The GSMA publishes no certification page, no SOC 2 / ISO 27001 attestation and no compliance programme for a developer-facing service, because it runs no developer-facing service — the closest equivalents are the Open Gateway certification programme, which certifies operator deployments (135 of 607 launched instances are marked certified in the GSMA's own feed), and the GSMA Mobile Money API Compliance Platform, which certifies mobile money implementations. standards: - id: openapi-3.0 conforms: true evidence: >- 18 documents: 17 Open Gateway specs at OpenAPI 3.0.3 and the Mobile Money API at OpenAPI 3.0.0. All 18 re-parsed and confirmed to carry an openapi key and a non-empty paths object. - id: camara-commonalities conforms: true evidence: >- Every Open Gateway spec follows the CAMARA Commonalities profile — x-correlator tracing header, the {status, code, message} ErrorInfo envelope with SCREAMING_SNAKE_CASE codes, the device/phoneNumber identifier model, and CloudEvents notification sinks. - id: oidc-core conforms: true evidence: >- All 17 Open Gateway specs declare a single openIdConnect security scheme named openId; scopes are attached per operation using the CAMARA :[:] convention. - id: oauth2 conforms: partial evidence: >- No oauth2 securityScheme is declared in any spec (authorization is expressed as openIdConnect), but the GSMA sandbox page names client_credentials, CIBA, authorization_code and jwt_bearer as the supported flows, and the GSMA deployment feed counts live deployments by flow — 256 client credentials, 190 authorization code, 94 CIBA, 7 JWT bearer. - id: ciba conforms: true evidence: >- Client Initiated Backchannel Authentication is named on the GSMA sandbox page and used in the Number Verification narrative to pass a GSMA TS.43 temporary token via login_hint=operatortoken:; 94 live deployments declare a CIBA flow in the GSMA feed. - id: cloudevents-1.0 conforms: true evidence: >- Carrier Billing, Carrier Billing Refund, Population Density Data and Quality on Demand deliver CloudEvents-shaped notifications to a consumer-supplied sink, with typed event identifiers such as org.camaraproject.quality-on-demand.v0.qos-status-changed. - id: rfc9457-problem-details conforms: false evidence: >- No specification returns application/problem+json. CAMARA uses its own ErrorInfo object and the Mobile Money API uses {errorCategory, errorCode, errorDescription, errorDateTime, errorParameters}. - id: rfc9116-security-txt conforms: true evidence: https://www.gsma.com/.well-known/security.txt returns 200 with Contact, Policy, Encryption, Acknowledgments and Canonical fields. - id: rfc8594-sunset-header conforms: false evidence: No Sunset or Deprecation header is defined in any of the 18 specifications. - id: rfc9727-api-catalog conforms: false evidence: /.well-known/api-catalog returns 404 on www.gsma.com and open-gateway.gsma.com. - id: pagination conforms: partial evidence: >- The Mobile Money API defines limit/offset query parameters (default limit 50) with X-Records-Available-Count and X-Records-Returned-Count response headers. The Open Gateway specs are single-resource and define no collection pagination. - id: idempotency conforms: partial evidence: >- The Mobile Money API Guidelines mandate a client-generated X-CorrelationID on creation requests, require the provider to store it, reject duplicates, and state that all update requests are idempotent. CAMARA has no Idempotency-Key header; Carrier Billing and Quality on Demand accept a clientCorrelator and reject a repeat with "clientCorrelator already exist on server." - id: json-api conforms: false - id: odata conforms: false - id: fhir-r4 conforms: false - id: scim-2.0 conforms: false - id: psd2 conforms: false evidence: >- The Mobile Money API is a mobile-money specification for emerging markets, not an EU open banking API; it makes no PSD2 claim. - id: iso-20022 conforms: false evidence: The Mobile Money API defines its own transaction object rather than an ISO 20022 message set. - id: 3gpp-nef-scef conforms: false evidence: >- The GSMA operates no network and therefore no Network Exposure Function. CAMARA APIs are the northbound abstraction operators map onto their own 3GPP NEF/SCEF infrastructure. - id: tmforum-open-api conforms: false evidence: >- The GSMA is not a TM Forum Open API conformance certificate holder — it publishes no TMF620/TMF622/TMF641 implementation because it operates no BSS/OSS. TM Forum lists CAMARA as an ODA partner, which is an alignment between bodies rather than a GSMA conformance claim. certification_programmes_run_by_gsma: - name: GSMA Open Gateway API certification scope: certifies operator and aggregator deployments of Open Gateway APIs, not the GSMA itself evidence: 135 of 607 launched API instances are marked certified in the GSMA deployment feed (https://d3bj8knxlstxyw.cloudfront.net/assets-map-launches.json) - name: GSMA Mobile Money API Compliance Platform scope: conformance testing for Mobile Money API implementations url: https://github.com/gsmainclusivetechlab/compliance-docs compliance_programme_published: false