generated: '2026-07-26' method: searched description: >- Which industry and cross-cutting standards the Ordnance Survey API estate conforms to. Ordnance Survey is one of the few providers in this catalogue that publishes MACHINE-READABLE conformance assertions: OS NGD API - Features and OS NGD API - Tiles both serve an OGC /conformance document listing the exact conformance classes they implement. Those documents were fetched live and are quoted verbatim below. Everything else is derived from the OpenAPI in openapi/ or from the OS documentation. sources: - https://api.os.uk/features/ngd/ofa/v1/conformance - https://api.os.uk/maps/vector/ngd/ota/v1/conformance - https://docs.os.uk/os-apis/core-concepts/authentication - https://docs.os.uk/os-apis/core-concepts/error-codes - https://docs.os.uk/os-apis/accessing-os-apis/os-features-api/technical-specification standards: - id: ogc-api-features-1 name: OGC API - Features - Part 1 - Core 1.0 conforms: true api: OS NGD API - Features evidence: >- Live /conformance declares http://www.opengis.net/spec/ogcapi-features-1/1.0/conf/core, .../conf/oas3 and .../conf/geojson - id: ogc-api-features-2 name: OGC API - Features - Part 2 - Coordinate Reference Systems by Reference 1.0 conforms: true api: OS NGD API - Features evidence: Live /conformance declares http://www.opengis.net/spec/ogcapi-features-2/1.0/conf/crs - id: ogc-api-features-3 name: OGC API - Features - Part 3 - Filtering / CQL2 conforms: true api: OS NGD API - Features evidence: >- Live /conformance declares .../ogcapi-features-3/0.0/conf/filter, /conf/features-filter, /conf/simple-cql, /conf/cql-text and /conf/arrays (draft 0.0 conformance classes) - id: ogc-api-tiles-1 name: OGC API - Tiles - Part 1 - Core 1.0 conforms: true api: OS NGD API - Tiles evidence: >- Live /conformance declares .../ogcapi-tiles-1/1.0/conf/core, /conf/oas30, /conf/tileset, /conf/tilesets-list and /req/geodata-tilesets - id: ogc-tilematrixset-2 name: OGC Two Dimensional Tile Matrix Set and Tile Set Metadata 2.0 conforms: true api: OS NGD API - Tiles evidence: Live /conformance declares http://www.opengis.net/spec/tms/2.0/conf/tilematrixset - id: ogc-wfs-2 name: OGC Web Feature Service 2.0.0 conforms: true api: OS Features API evidence: >- GetCapabilities / DescribeFeatureType / GetFeature with service=WFS and version=2.0.0 parameters, documented at https://docs.os.uk/os-apis/accessing-os-apis/os-features-api/technical-specification - id: ogc-wmts-1 name: OGC Web Map Tile Service 1.0.0 conforms: true api: OS Maps API evidence: >- /wmts operation with service=WMTS, version=1.0.0, request=GetTile | GetCapabilities parameters in openapi/ordnance-survey-maps-openapi.json - id: ogc-filter-encoding-2 name: OGC Filter Encoding 2.0 conforms: true api: OS Features API evidence: >- filter parameter carrying OGC Filter Encoding XML, documented at https://docs.os.uk/os-apis/accessing-os-apis/os-features-api/technical-specification/filtering - id: openapi-3 name: OpenAPI 3.0 conforms: true evidence: >- Ten OpenAPI 3.0.x documents in openapi/. Two are served live and anonymously by the provider (OS NGD API - Features at /api, OS Downloads API and OS Net API at /openapi.yaml); the remaining seven are published inline on the docs.os.uk technical-specification pages. - id: geojson name: GeoJSON (RFC 7946) conforms: true evidence: >- OS NGD API - Features declares the ogcapi-features-1 geojson conformance class; OS Places POST /polygon accepts a GeoJSON polygon request body. - id: mapbox-style-spec name: Mapbox / MapLibre Style Specification conforms: true api: OS NGD API - Tiles, OS Vector Tile API evidence: >- Style documents served from /collections/{collectionId}/styles/{styleId} and /vts/resources/styles; OS publishes stylesheets for these in github.com/OrdnanceSurvey/OS-Vector-Tile-API-Stylesheets and OS-NGD-Stylesheets. - id: mapbox-vector-tile name: Mapbox Vector Tile 2.1 (.pbf) conforms: true api: OS NGD API - Tiles, OS Vector Tile API evidence: /vts/tile/{z}/{y}/{x}.pbf and the NGD tile operations return application/vnd.mapbox-vector-tile - id: oauth2-client-credentials name: OAuth 2.0 Client Credentials Grant (RFC 6749 s4.4) conforms: true evidence: >- Every OpenAPI declares an oauth2 securityScheme with a clientCredentials flow against https://api.os.uk/oauth2/token/v1; the token endpoint takes HTTP Basic (Project API Key : Project API Secret) and grant_type=client_credentials and returns a Bearer access_token with expires_in. - id: oauth2-bearer-token name: OAuth 2.0 Bearer Token Usage (RFC 6750) conforms: true evidence: 'Authorization: Bearer documented at https://docs.os.uk/os-apis/core-concepts/authentication' - id: oidc name: OpenID Connect conforms: false evidence: >- No /.well-known/openid-configuration is published; the OAuth 2 service is a bare client-credentials token endpoint with no identity layer. - id: rfc8414-as-metadata name: OAuth 2.0 Authorization Server Metadata (RFC 8414) conforms: false evidence: /.well-known/oauth-authorization-server returns the api.os.uk catch-all landing document, not RFC 8414 metadata. - id: rfc9457-problem-details name: RFC 9457 Problem Details for HTTP APIs conforms: partial api: OS Net API only evidence: >- OS Net API is the ONE OS API that returns application/problem+json - on 12 of its error responses (400/403/404 across /stations and /rinex), though the spec types the body only as a bare object with no type/title/detail properties. Every other OS API returns application/json with an API-specific error body, or an OGC/OWS XML ExceptionReport for the WFS/WMTS/vector-tile surfaces. See errors/ordnance-survey-problem-types.yml. - id: rfc9116-security-txt name: RFC 9116 security.txt conforms: false evidence: >- No security.txt resolves on any OS host, although the OS vulnerability disclosure policy refers to "the published security.txt". - id: rfc8594-sunset-header name: RFC 8594 Sunset HTTP Header conforms: false evidence: >- Deprecation is communicated through dated end-of-life documentation pages and the change log, not through Sunset/Deprecation response headers. - id: rfc9116-well-known-api-catalog name: RFC 9727 api-catalog well-known URI conforms: false partial: true evidence: >- OS DOES publish a machine-readable API catalogue - a link-relation index at the api.os.uk root enumerating every API, service endpoint and documentation page - but it is not served at /.well-known/api-catalog and it is not an RFC 8288 linkset media type. Captured in well-known/ordnance-survey-api-catalog.json. - id: json-api name: JSON:API conforms: false - id: odata name: OData conforms: false - id: scim2 name: SCIM 2.0 conforms: false - id: fhir-r4 name: FHIR R4 conforms: false - id: fapi name: FAPI conforms: false - id: psd2 name: PSD2 conforms: false - id: reso name: RESO Data Dictionary / Web API conforms: false evidence: >- RESO is a US MLS construct and appears nowhere in the Ordnance Survey estate. UK property addressing is anchored on UPRN/TOID/USRN instead. - id: inspire name: INSPIRE Directive (EU 2007/2/EC) view and download services conforms: unknown evidence: >- Ordnance Survey historically published INSPIRE-compliant services, but no INSPIRE conformance claim appears anywhere in the current OS Data Hub API documentation, so this is recorded as unverified rather than asserted. identifier_standards: - id: uprn name: Unique Property Reference Number role: The GB national property identifier; the primary key of AddressBase and OS Open UPRN. - id: toid name: TOID (Topographic Identifier) role: The OS MasterMap feature identifier. - id: usrn name: Unique Street Reference Number role: The GB national street identifier. - id: bng name: British National Grid (EPSG:27700) role: >- Native OS coordinate reference system; OS also serves EPSG:3857 and EPSG:4326. First-party grid-indexing libraries published as osbng (PyPI and CRAN). compliance_program: published: false note: >- No trust centre, SOC 2, ISO 27001, PCI DSS or FedRAMP certification page is published for the OS Data Hub. Ordnance Survey publishes governance policies (data protection, privacy, vulnerability disclosure, PSGA standards, public sector information) rather than a security certification programme. Because no named certification was verified, no Compliance pointer is emitted for this provider.