generated: '2026-07-27' method: derived source: - openapi/trolie-standard-openapi.yml - probes of portal.spp.org, pricecontourmap.spp.org, rms.spp.org on 2026-07-27 - https://www.spp.org/documents/72496/spp%20lep%20api%20data%20exchange%20guide.pdf note: >- Two kinds of conformance apply to SPP and they must not be conflated. Regulatory conformance is real and central — SPP is a FERC-regulated Regional Transmission Organization and a NERC-registered entity, and FERC Order 881 is the mandate that produced its one modern REST API. Technical HTTP conformance is inherited, not authored: the RFC 9457, conditional-GET and OAuth patterns below come from the LF Energy TROLIE community specification SPP adopted, and are attributed as such. No security certification (SOC 2, ISO 27001, PCI DSS, HIPAA, FedRAMP) is published anywhere on an SPP host — probes for a trust centre, security page and security.txt all missed. standards: - id: ferc-order-881 conforms: true scope: regulatory evidence: >- SPP published the "SPP LEP/TROLIE API Data Exchange Guide" v1.0 (2024-11-08), a versioned implementation guide for ambient-adjusted transmission ratings exchange, citing FERC Order 881 as the driver. Implementation is documented; the running endpoint was not observable anonymously. status: live-claimed-unverified - id: lf-energy-trolie conforms: true version: 1.1.0 scope: data-exchange evidence: >- SPP's LEP guide directs implementers to https://trolie.energy/spec and https://github.com/TROLIE/spec as the contract for its ratings API rather than defining a proprietary one. Spec harvested to openapi/trolie-standard-openapi.yml. attribution: community specification, not SPP-authored - id: openapi-3 conforms: true version: 3.0.3 scope: description-format evidence: openapi/trolie-standard-openapi.yml declares openapi 3.0.3 with 28 operations across 16 paths attribution: the specification SPP adopts is OpenAPI-described; SPP publishes no OpenAPI of its own - id: rfc9457-problem-details conforms: true scope: errors evidence: >- Component responses 400-problem, 406-problem, 409, 410-problem, 415-problem and 422-problem return application/problem+json against components.schemas.problem attribution: inherited from the TROLIE specification - id: rfc7232-conditional-requests conforms: true scope: caching evidence: >- Snapshot operations return ETag and the spec instructs clients to poll with If-None-Match, with 304 Not Modified defined as a component response attribution: inherited from the TROLIE specification - id: oauth2 conforms: partial scope: authorization evidence: >- The TROLIE spec declares a single oauth2 clientCredentials scheme (oauth2-primary-flow) with 15 scopes and RFC 8725 JWT guidance. SPP hosts no OAuth authorization server for it — its LEP implementation authenticates with an OATI webCARES x.509 certificate over mTLS plus an SPP UAA role. - id: openid-connect conforms: partial scope: identity evidence: >- A valid OIDC discovery document is served at https://rms.spp.org/.well-known/openid-configuration for SPP's Request Management System (Salesforce Experience Cloud). No SPP data or market API is fronted by an OIDC provider; www.spp.org and portal.spp.org expose no discovery document. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returned 404 on www.spp.org, spp.org and pricecontourmap.spp.org; 401 on rms.spp.org; the 200 on portal.spp.org is the 609-byte SPA shell, not a policy file - id: rfc8594-sunset-header conforms: false evidence: no Sunset or Deprecation header support and no deprecation policy found - id: esri-arcgis-rest conforms: true scope: geospatial evidence: >- pricecontourmap.spp.org serves a standard ArcGIS Server 11.5 REST directory; /arcgis/rest/info?f=json returns currentVersion 11.5 and token-service metadata; PCM MapServer services respond to the standard ?f=json contract attribution: Esri product contract, not SPP-authored - id: iec-60870-6-tase2-iccp conforms: true scope: operational-telemetry evidence: named in the SPP System Interfaces Stakeholder Reference Guide as the control-centre to control-centre telemetry interface; the ICCP handbook itself is password-gated to members - id: ieee-c37-118-pmu conforms: true scope: operational-telemetry evidence: PMU streaming over TCP/IP named in the same guide (PMU Communication Handbook, member-gated) - id: soap-wsdl conforms: true scope: participant-apis evidence: SPP states it uses SOAP and REST web services over HTTPS for market systems; WSDL/XSD contracts are distributed only in the member-facing Change User Forum - id: green-button-espi conforms: false not_applicable: true evidence: retail-utility consumer data standard; SPP is a wholesale RTO with no retail customers - id: iec-cim-61968-61970 conforms: unknown evidence: no public reference found in SPP stakeholder documentation - id: json-api conforms: false - id: odata conforms: false - id: fapi conforms: false - id: scim2 conforms: false regulatory_program: url: https://www.spp.org/stakeholder-center/spp-rto-compliance/ regulators: [FERC, NERC] note: >- SPP publishes an RTO Compliance section covering its obligations as a FERC-regulated Regional Transmission Organization and a NERC-registered entity. This is regulatory compliance, not a security-certification trust centre — no SOC 2, ISO 27001, PCI DSS, HIPAA or FedRAMP attestation is published on any SPP host (probe-security-programs.py found no trust centre and no vulnerability-disclosure programme on 2026-07-27). certifications_published: []