generated: '2026-09-01' method: searched source: https://www.ubicquia.com/insights/the-ubicquia-security-program; openapi/ubicquia-config-api-openapi-original.json standards: - id: openapi-3.0 conforms: true evidence: 'config.api.ubicquia.com/docs serves openapi: 3.0.0 with 39 operations and 14 component schemas (generated by L5-Swagger for Laravel).' - id: rfc9116-security-txt conforms: true evidence: https://www.ubicquia.com/.well-known/security.txt returns 200 with Contact, Preferred-Languages, Canonical and Expires fields. - id: iso-27001 conforms: true evidence: The Ubicquia Security Program page states "Full Information Security Management System (ISMS) certification with recurring external audits." - id: soc2-type-2 conforms: true evidence: The Ubicquia Security Program page states SOC 2 Type 2 "attests to operational effectiveness of security controls over a sustained period." - id: nist-csf conforms: true evidence: Named on the Ubicquia Security Program page as an alignment framework. - id: nist-800-171 conforms: true evidence: Named on the Ubicquia Security Program page (controlled unclassified information). - id: cmmc-level-1 conforms: true evidence: Named on the Ubicquia Security Program page. - id: pci-dss-saq-c conforms: true evidence: PCI SAQ-C named on the Ubicquia Security Program page. - id: ctia-iot-cybersecurity-certification conforms: true evidence: The Ubicquia Security Program page states UbiCell is certified under CTIA IoT Cybersecurity level 1 v1.2.3 - a device-level certification specific to the cellular IoT market Ubicquia sells into. domain_standard: true - id: oauth2 conforms: false evidence: The only securityScheme is apiKey in header (x-api-key). No OAuth2 flows are declared. - id: oidc conforms: false evidence: /.well-known/openid-configuration returns 404 on every Ubicquia host probed. - id: rfc9457-problem-details conforms: false evidence: Errors use a flat vendor envelope (status/code/message/data/version) served as application/json, not application/problem+json. - id: rfc8594-sunset-header conforms: false evidence: No Sunset or Deprecation header support is documented. - id: idempotency-key conforms: false evidence: No Idempotency-Key parameter appears in any of the 39 operations. - id: pagination conforms: true evidence: 'Laravel length-aware paginator: page + per_page request params, links{first,last,prev,next} and meta{current_page,per_page,total} in responses.' - id: ieee-2030.5 conforms: false evidence: No smart-energy profile / IEEE 2030.5 surface is declared. Recorded as a probed negative for the utility sector, not a penalty. - id: multispeak conforms: false evidence: No MultiSpeak (utility enterprise integration) SOAP or REST endpoint was found; ?wsdl probes on both API hosts missed. - id: ansi-c136.41 conforms: false evidence: The NEMA/ANSI C136.41 dimming receptacle is the PHYSICAL interface UbiCell plugs into and is referenced in Ubicquia product material, but it is a hardware standard with no contract representation, so it is not asserted as an API conformance. domain_standard_conformance: sector: utilities / smart cities / IoT declared_in_contract: false note: The published OpenAPI is a manufacturing and provisioning contract (sales orders, serial numbers, ICCID inventory, transformer file uploads). It declares no domain-standard signature - no IEEE 2030.5, no MultiSpeak, no CIM/IEC 61968 message types, no Sparkplug topic namespace. The one genuine domain certification Ubicquia publishes, CTIA IoT Cybersecurity level 1 for UbiCell, is a device certification rather than a contract shape, and is recorded above rather than claimed as contract conformance. compliance_program: published: true url: https://www.ubicquia.com/insights/the-ubicquia-security-program certifications: - ISO 27001 - SOC 2 Type 2 - NIST CSF - NIST 800-171 - CMMC Level 1 - PCI SAQ-C - CTIA IoT Cybersecurity Level 1 v1.2.3 practices: - Periodic external penetration testing - Vulnerability management with tracked remediation ownership - Documented incident response with a pre-designated ISIRT and root cause analysis per incident