Nucleus Systems
Code Trust Assurance Intelligence

Nucleus Systems Code Trust Assurance Framework

NS-CTAF

Measure, evidence, and certify software trust across code identity, integrity, secure development, supply chain, runtime behaviour, and governance.

Security tools find issues. NS-CTAF proves trust.

Specimen · Paxley Software
CTA-4
84/100
Trust Score
86/86 controls
L4 overall
Active
86
Controls
6
Domains
5-axis
Scoring model
L1–L5
Maturity
CTA-1→4
Certification
30+
Alignments
The trust gap

Organisations scan code. They still can’t prove software trust.

SolarWinds, Log4Shell, and XZ Utils showed that perimeter-only security fails when the threat originates in trusted software. Every dependency, pipeline, and AI-generated commit is a trust decision — and most organisations cannot demonstrate, continuously and with evidence, that those decisions are controlled.

NS-CTAF treats every stage of software production and distribution as an independently assessable trust boundary — producing a single, quantified Trust Score.

Security tools

Find issues in code you already have.

NS-CTAF

Proves the whole system can be trusted.

A scan

Is a point-in-time snapshot.

A Trust Score

Is a continuous, evidence-backed measure.

How assessment works

From evidence to a public trust signal

Assessment combines evidence, maturity scoring, automated tooling, and independent assessor validation.

01

Evidence

SBOMs, signing, scans, attestations, runtime and governance data collected and registered.

02

Assessment

86 controls scored across 5 axes, hard gates applied, evidence independently validated.

03

Output

Trust Score, domain scores, board report, and a prioritised 12-month roadmap.

04

Certification

A CTA-1 to CTA-4 certificate and a public Trust Registry listing.

Certification

Four levels of Code Trust Assurance

Based on the Trust Score and minimum domain thresholds — with seven hard gates that must pass regardless of overall score.

CTA-1Trust ≥ 30

Transparent

45+ controls

The software supply chain is visible. SBOMs, basic scanning, dependency inventory, and ownership are in place.

CTA-2Trust ≥ 48

Verified

63+ controls

Trust is backed by cryptographic evidence — artifact signing, build provenance, and automated security controls.

CTA-3Trust ≥ 62

Assured

78+ controls

Trust is continuously measured across development, supply chain, runtime, and governance.

CTA-4Trust ≥ 78

Adaptive Trust

86 / 86 controls

Trust is automated, continuously computed, self-healing, and independently verified.

Trust Registry

Verify certified companies

A public directory where the market can verify certified companies by continent, country, sector, year, and certification level.

Search the registry

Basic certificate verification is public. Certificate downloads, bulk checks, API verification, and full reports are available through Report Access bundles.

Verify a Certificate
Executive-readable

One number the board understands

The 0–100 Trust Score summarises true code-trust posture across all six domains — mapped directly to certification readiness.

71/100
Example score
80–100
Optimised · CTA-4 readiness
Sustain, validate through advanced testing, and publish high-assurance trust signals.
65–79
Managed · CTA-3 readiness
Increase automation and progress priority domains toward CTA-4.
50–64
Defined · CTA-2 readiness
Address gaps systematically and fund the maturity roadmap.
30–49
Developing · CTA-1 readiness
Create executive focus and fund remediation.
Below 30
Initial · High exposure
Escalate to leadership and establish a CTA-1 baseline first.
One assessment, many obligations

Aligned with the standards that matter

NS-CTAF maps to major software-security frameworks and regulations — so a single assessment addresses multiple compliance obligations.

SLSANIST SSDF (SP 800-218)OWASP SAMM v2in-totoEU Cyber Resilience ActDORANIS2US EO 14028ISO/IEC 27001:2022SOC 2PCI DSS v4.0.1

Before you trust a vendor’s software, verify its code trust posture.

Fixed fee $5,000 USD · ~20 business days · Final report, CTA certificate, and 12-month roadmap.