generated: '2026-06-20' method: searched source: >- Derived from openapi/uk-power-networks-explore-api-v2-1-openapi.json and live probes of the API host, then enriched from the UK Power Networks Data Best Practice portal page and the Ofgem decision it cites. Probed 2026-07-27. summary: >- Strong on description and cataloguing standards, absent on identity standards, and absent on every energy-sector consumer data standard — which is the correct shape for a distribution network operator in a market that mandated network transparency but never legislated a consumer energy data right. IEC CIM appears here as payload, not as an API shape. standards: - id: openapi-3.0 conforms: true version: 3.0.3 evidence: >- Two OpenAPI 3.0.3 documents served from the company's own domain at /api/explore/v2.1/swagger.json and /api/explore/v2.0/swagger.json, both HTTP 200, both parse, 16 paths each, saved verbatim to openapi/. - id: dcat-ap conforms: true evidence: >- /api/explore/v2.1/catalog/exports/dcat returns HTTP 200 application/rdf+xml with dcat: and dcatap: (data.europa.eu/r5r) namespaces declared at the document root. The whole 136-dataset catalogue is exportable as DCAT-AP RDF. - id: rfc9116-security-txt conforms: true evidence: >- /.well-known/security.txt returns HTTP 200 with Contact, Expires and Preferred-Languages fields. Saved to well-known/uk-power-networks-security.txt. The contact is the platform vendor's, not UK Power Networks'. - id: rest conforms: true evidence: GET-only resource hierarchy under /catalog with hypermedia links controlled by include_links. - id: cors conforms: true evidence: 'access-control-allow-origin: * with the rate-limit and deprecation headers exposed to browsers.' - id: hsts conforms: true evidence: 'strict-transport-security: max-age=31536000;includeSubdomains on the API host.' - id: ofgem-data-best-practice conforms: true scope: regulatory transparency obligation on GB energy network licensees evidence: >- UK Power Networks publishes its own maturity ratings against Ofgem's Data Best Practice Principles as the queryable dataset ukpn-data-best-practice-live-maturity (CC BY 4.0, 11 records), and hosts a Maturity Framework page at https://ukpowernetworks.opendatasoft.com/pages/data-best-practice/ (HTTP 200). This is the obligation that actually produced the API. reference: https://www.ofgem.gov.uk/decision/decision-updates-data-best-practice-guidance-and-digitalisation-strategy-and-action-plan-guidance - id: iec-cim conforms: partial as: payload evidence: >- The dataset ukpn-ltds-cim ("Long Term Development Statement - Common Information Model") publishes CIM network models, and one of the portal's licence types is "UK Power Networks Shared Data Licence - Common Information Model". CIM is the content, not the interface — the API shape is Opendatasoft Explore, not a CIM service. - id: creative-commons-by-4.0 conforms: true evidence: >- 122 of 136 datasets are licensed CC BY 4.0; 6 under Open Government Licence v3.0. Facet counts read live from /catalog/facets?facet=license on 2026-07-27. - id: oauth2 conforms: false evidence: >- securitySchemes declares a single apiKey scheme in the query string. /.well-known/oauth-authorization-server returns HTTP 404. - id: oidc conforms: false evidence: /.well-known/openid-configuration returns HTTP 404 on the API host. - id: fapi conforms: false - id: mtls conforms: false - id: rfc9457-problem-details conforms: false evidence: >- Errors use a custom {"error_code", "message"} envelope with content-type application/json, not application/problem+json. The 429 response uses a third, incompatible shape. - id: rfc8594-sunset conforms: false evidence: >- Deprecation is signalled through a vendor header (ODS-Explore-API-Deprecation), not the RFC 8594 Sunset header or the RFC 9745 Deprecation header. - id: json-api conforms: false - id: odata conforms: false note: The query dialect is ODSQL, a platform-specific language, not OData. - id: asyncapi conforms: false evidence: No event, streaming or webhook surface exists. Not applicable rather than missing. - id: green-button conforms: false evidence: >- Grepped across both OpenAPI documents, the catalogue metadata for all 136 datasets and the portal pages probed. No Green Button, ESPI or consumer usage-sharing surface. Britain never created the obligation and a DNO holds no retail customer account to expose. - id: espi conforms: false - id: cdr-consumer-data-standards conforms: false evidence: The UK has no Consumer Data Right equivalent for energy. Nothing to conform to. - id: ocpp conforms: false - id: ocpi conforms: false evidence: >- The OZEV National Chargepoint Register is republished as a dataset under Open Government Licence v3.0, but it is served through the Explore API, not as an OCPI endpoint. - id: openadr conforms: false - id: ieee-2030.5 conforms: false - id: smart-energy-code conforms: not-applicable-to-this-api note: >- UK Power Networks is a user party to the Smart DCC under the Smart Energy Code, but that regime produces no public API and no consumer portability. It is recorded so the two mandates are never conflated: the mandate that gets cited is not the mandate that produced this endpoint. compliance_program: published: true url: https://ukpowernetworks.opendatasoft.com/pages/data-best-practice/ kind: regulatory data-transparency maturity framework certifications: [] certifications_note: >- No SOC 2, ISO 27001, PCI DSS, HIPAA or FedRAMP attestation is published for this API, and none would be expected for a free open-data portal. What is published, and published unusually well, is a self-assessed maturity rating against a regulator's principles — exposed as a dataset through the same API those principles produced.