generated: '2026-07-27' method: searched source: >- PJM OASIS API User Guide (Rev 04), https://pjmoasis.pjm.com/OASIS/PJM/INFO.HTM, PJM Data Miner API Guide (v15), and anonymous probes on 2026-07-27. standards: - id: naesb-weq-002 name: NAESB WEQ-002 Open Access Same-Time Information System (Standards and Communication Protocol) conforms: true versions: ['2.0', '2.1', '2.2', '3.3'] evidence: >- PJM's OASIS API User Guide states support for NAESB WEQ-002 versions 2.0, 2.1, 2.2 and 3.3, and documents template submission per WEQ-002-4.2.4 through 4.2.7 (GET with Content-type text/plain, POST with application/x-www-form-urlencoded). The WEQ-002-4.5.2 mandated public Online Resources posting is served anonymously at https://pjmoasis.pjm.com/OASIS/PJM/INFO.HTM (HTTP 200, 2026-07-27) and carries numbered standard references 001-13.1.4, 001-C, 002-4.3.4.2, 002-4.5.1A, 002-4.5.1B, 002-4.5.1C, 002-4.5.1D and 002-4.5.2. standard_url: https://www.naesb.org/weq/default.asp - id: naesb-weq-003 name: NAESB WEQ-003 OASIS Data Dictionary conforms: true versions: ['2.0', '2.1', '2.2', '3.3'] evidence: PJM OASIS API User Guide Rev 04 states support for WEQ-003 at the same versions. - id: ferc-order-889 name: FERC Order 889 (Open Access Same-Time Information System) conforms: true evidence: >- PJM operates an OASIS node as the transmission-provider obligation under FERC Order 889; the node is live and standards-conformant. This is the one machine-readable interface PJM is mandated to publish. - id: pjm-custom-oasis-templates name: PJM custom OASIS templates conforms: true templates: [pjmannulment, pjmtransreq, pjmtsrcomment] evidence: Documented as PJM extensions in the OASIS API User Guide Rev 04. - id: tls-1.2 name: TLS 1.2 minimum transport security conforms: true evidence: >- "In general, Tls1.2 is required for all PJM tools, including Data Miner." TLS 1.0/1.1 were retired from internet-facing PJM applications in Data Miner release 22.04. Live probe on 2026-07-27 negotiated TLSv1.3 on www.pjm.com and api.pjm.com, TLSv1.2 on pjmoasis.pjm.com. - id: rfc9116-security-txt name: RFC 9116 security.txt conforms: true evidence: >- https://www.pjm.com/.well-known/security.txt returns a valid RFC 9116 document with Contact, Expires, Preferred-Languages, Canonical and Policy fields. - id: oauth2 name: OAuth 2.0 conforms: false evidence: >- No OAuth 2.0 surface is published. /.well-known/oauth-authorization-server returns 404 on api.pjm.com, sso.pjm.com, apiportal.pjm.com, pjmoasis.pjm.com and services.pjm.com, and a soft 404 on www.pjm.com. - id: openid-connect name: OpenID Connect conforms: false evidence: >- PJM single sign-on is ForgeRock OpenAM but exposes a proprietary X-OpenAM-Username/X-OpenAM-Password authenticate call and a pjmauth cookie rather than OIDC. /.well-known/openid-configuration returns 404 on sso.pjm.com. - id: rfc9457-problem-details name: RFC 9457 Problem Details for HTTP APIs conforms: false evidence: >- Data Miner 2 returns a proprietary {"errors":[{"field","message","detail"}]} envelope; the eTools JAX-RS surfaces return a RESTEasy XML document. Neither uses application/problem+json. - id: rfc8594-sunset-header name: RFC 8594 Sunset HTTP Header conforms: false evidence: No Sunset or Deprecation headers are documented or observed; retirements are announced in release notes. - id: rfc9727-api-catalog name: RFC 9727 /.well-known/api-catalog conforms: false evidence: /.well-known/api-catalog returns 404 or the pjm.com HTML shell on every PJM host probed. - id: openapi name: OpenAPI Specification conforms: partial evidence: >- PJM generates an OpenAPI/Swagger definition for Data Miner 2 — the API Guide says "The API definition is also available in Swagger and WADL formats located in API definition drop down menu" of the Azure API Management portal, and a public Swashbuckle Swagger UI shell exists at https://services.pjm.com/PJMDataminerApi/swagger. It is not anonymously retrievable — the Swashbuckle discovery path swagger/docs/v1 returns HTTP 500 and the APIM portal returns an empty API list to anonymous callers (/developer/apis?api-version=2022-04-01-preview -> {"value":[],"nextLink":null}). Recorded as partial: a spec exists behind the login wall; nothing has been fabricated to stand in for it. - id: asyncapi name: AsyncAPI conforms: false evidence: >- No event, streaming or webhook surface is published. Notices are polled over REST (messages.pjm.com) or subscribed to by email; there is no callback registration. - id: green-button-espi name: Green Button / NAESB REQ.21 ESPI conforms: false applicable: false evidence: >- PJM is a wholesale RTO with no retail customers, so no consumer energy data right applies. See review.yml. - id: iec-cim-61968-61970 name: IEC CIM 61968/61970 conforms: false evidence: >- No CIM reference was found anywhere on the PJM developer surface. Data Miner uses a proprietary feed shape and eDART a PJM-proprietary XML document set. - id: ieee-2030.5 name: IEEE 2030.5 (Smart Energy Profile) conforms: false evidence: No reference found on the PJM developer surface. - id: openadr name: OpenADR conforms: false evidence: >- No reference found; PJM's demand response participation runs through DR Hub, a member-only eTool, not an OpenADR interface. compliance_program: published: false certifications: [] trust_center: null note: >- PJM publishes no SOC 2 / ISO 27001 / PCI DSS / FedRAMP style trust center. Its compliance posture is regulatory rather than commercial — FERC, NERC reliability standards and the NAESB business practice standards — with a PJM Compliance Line and an online reporting tool for reporting concerns. No `Compliance` pointer is emitted, because no certification or compliance-program page was found. probe: >- probe-security-programs.py found no trust center on trust.pjm.com, security.pjm.com or pjm.com/trust|/security|/compliance on 2026-07-27.