generated: '2026-07-28' method: searched source: >- https://ndc.virginatlantic.com/help/how-to-start-your-build, https://ndc.virginatlantic.com/docs, https://ndc.virginatlantic.com/docs/DataLists/Error, https://ndc.virginatlantic.com/certification, https://ndc.virginatlantic.com/news/2023/news-virgin-atlantic-iata-certification, https://ndc.virginatlantic.com/file-lists/schema-assets, plus the harvested XSDs in schemas/ description: >- Which industry and cross-cutting standards the Virgin Atlantic distribution API conforms to. This is an airline distribution API, so its centre of gravity is IATA rather than the web-API standards stack: it is a full IATA NDC 21.3 implementation with IATA-certified retailing maturity, and it implements essentially none of the OAuth/OIDC/JSON-web-API conventions. standards: - id: iata-ndc-21.3 conforms: true evidence: >- "Virgin Atlantic currently develops and supports the NDC 21.3 API Schema." Twelve NDC 21.3 messages are documented publicly and the downloadable XSDs carry targetNamespace http://www.iata.org/IATA/2015/EASD/00/IATA_OffersAndOrdersMessage, schema version 9.001, id IATA2021.3 (schemas/). - id: iata-arm-index conforms: true evidence: >- Certified under the IATA Airline Retailing Maturity (ARM) Index using 21.3 NDC schema capability across 18 capabilities, announced 21 April 2023 (https://ndc.virginatlantic.com/news/2023/news-virgin-atlantic-iata-certification). Previously the first airline to achieve NDC Level 3 certification on the 18.1 standard. - id: iata-padis-9321 conforms: true evidence: >- Error codes are "PADIS error code based on 9321" per the Error common type (https://ndc.virginatlantic.com/docs/DataLists/Error); 71 distinct codes are published across the message set (errors/virgin-atlantic-error-codes.yml). - id: w3c-xml-schema conforms: true evidence: >- The published contract is a set of W3C XML Schema (XSD) documents, downloadable anonymously from https://ndc.virginatlantic.com/file-lists/schema-assets and harvested to schemas/. - id: xmldsig-core conforms: true evidence: >- xmldsig-core-schema.xsd ships with the IATA NDC 21.3.3 schema assets (schemas/xmldsig-core-schema.xsd), the standard XML Signature import in the IATA message set. - id: emv-3ds2 conforms: true evidence: >- OrderCreate accepts "Payment card details with 3DS2 authenticated details for online travel agents"; the testing documentation publishes 3DS AuthenticationValue and DirectoryServerTrxID test values and states that all online travel agents are expected to complete 3DS2 authentication upfront (https://ndc.virginatlantic.com/capability/offer/prime-sale-without-seat). - id: iata-bsp-settlement conforms: true evidence: >- IATA BSP Cash and IATA BSP EasyPay are documented payment workflows on the portal; ARC reporting and settlement for US agents is on the 2026 roadmap. - id: uk-gdpr conforms: true evidence: >- A Data Processing Agreement is a mandatory part of NDC access, and the NDC Novation Policy commits to assisting data-subject requests covering "access, rectification, erasure, portability, objection or other applicable privacy rights" (https://flywith.virginatlantic.com/gb/en/partner-hub/policies/NDC_Novation_Policy.html). Recorded as a contractual commitment; Virgin Atlantic publishes no compliance/trust centre or named security certifications. - id: openapi conforms: false evidence: >- No OpenAPI or Swagger document exists on any Virgin Atlantic host. /openapi.json, /swagger.json and /api-docs return 404 or the portal's HTML catch-all on both ndc.virginatlantic.com and www.virginatlantic.com. - id: oauth2 conforms: false evidence: Authentication is a single API key header (Ocp-Apim-Subscription-Key); no OAuth surface is documented. - id: oidc conforms: false evidence: No /.well-known/openid-configuration document on any host (well-known/virgin-atlantic-well-known.yml). - id: rfc8414-oauth-metadata conforms: false evidence: /.well-known/oauth-authorization-server returns the portal HTML catch-all, not a metadata document. - id: rfc9116-security-txt conforms: false evidence: >- No /.well-known/security.txt on ndc.virginatlantic.com (404), www.virginatlantic.com (403), api.virginatlantic.com (444) or flywith.virginatlantic.com (404). - id: rfc9457-problem-details conforms: false evidence: >- Errors are IATA NDC XML elements with PADIS codes, not application/problem+json. - id: rfc8594-sunset-header conforms: false evidence: No Sunset or Deprecation header support, and no deprecation policy, is published. - id: asyncapi conforms: false evidence: >- An asynchronous push surface exists (OrderChangeNotif) but no AsyncAPI document is published; the surface is captured as a webhook catalog instead (asyncapi/virgin-atlantic-orderchangenotif-webhooks.yml). - id: graphql conforms: false evidence: No GraphQL endpoint or SDL is published for the distribution API. - id: mcp conforms: false evidence: No Model Context Protocol server is published. - id: json-api conforms: false - id: odata conforms: false - id: scim conforms: false - id: fhir-r4 conforms: false - id: fapi conforms: false - id: psd2-sca conforms: false evidence: >- Card payments run 3DS2 but Virgin Atlantic publishes no PSD2 SCA conformance claim on the NDC portal; not asserted. certification_programme: docs: https://ndc.virginatlantic.com/certification note: >- Virgin Atlantic runs its own partner certification programme on top of the IATA standard. Three tiers - RED and SILVER are live, GOLD is scheduled for February 2026. RED Tier is the minimum to apply for a production API key, and each tier requires submitting sample implementations for its published use cases (RED Cert-1-1 to Cert-1-6; SILVER Cert-2-1 to Cert-2-5). An NDC Certification Tool is on the 2026 roadmap. no_published_security_certifications: >- No SOC 2, ISO 27001, PCI DSS, HIPAA, FedRAMP or CSA STAR certification is published on any Virgin Atlantic developer or partner surface, and no trust centre exists (probe-security-programs found none). No Compliance pointer is therefore emitted for this provider.