An evidence-first assessment, end to end
A structured engagement that collects evidence, scores all 86 controls, applies hard gates, and delivers a Trust Score, board-ready report, and certification recommendation.
Six phases from scope to certification readiness
Automated tooling structures the scoring; independent assessors validate the evidence.
Scoping
Define systems, repositories, pipelines, products, environments, and regulatory context.
→ Assessment scope and priority domain list.
Evidence Collection
Collect SBOMs, CI/CD logs, signing evidence, policies, scan outputs, attestations, runtime data, and governance documents.
→ Evidence register and gap log.
Automated Tool Review
Use the NS-CTAF assessment tool to structure scoring, dashboards, recommendations, roadmap, and readiness.
→ Draft scorecard and preliminary roadmap.
Assessor Validation
Review evidence quality, test claims, apply hard scoring gates, and validate control maturity.
→ Validated maturity scores.
Reporting
Produce Trust Score, domain scores, control gaps, roadmap, board report, and regulatory view.
→ Final report pack.
Certification Readiness
Determine whether the assessed organisation qualifies for CTA-1, CTA-2, CTA-3, or CTA-4.
→ Certification recommendation.
What you receive
- NS-CTAF Trust Score and domain maturity scores
- Control-level maturity analysis across applicable controls
- Evidence quality review and evidence register
- Certification readiness assessment
- Prioritised 12-month improvement roadmap
- Board-ready report written in non-technical language
- Optional public certificate and shareable assurance report
How we keep it rigorous
- Evidence-first assessment, cryptographic evidence preferred
- No maturity inflation through policy-only evidence
- Clear scope definition before scoring begins
- Repeatable scoring across the five NS-CTAF axes
- Hard scoring gates cap maturity where trust conditions are absent
- Independent review before certification is issued
Cryptographic proof beats assertion
Higher maturity levels require higher-tier evidence — there is no maturity inflation through policy-only documentation.
Cryptographic evidence
Signatures, attestations, hashes, transparency-log entries, SBOMs, provenance records.
System-generated artefacts
CI/CD logs, automated scan reports, pipeline execution records, monitoring dashboards.
Structured documentation
Policies, standards, process documents, architecture diagrams, manual records.
Management attestation
Interview responses, declarations, and unverified assertions.
Eight stages, ~20 business days
From first contact to CTA certification — a predictable path with a fixed fee and defined deliverables at each stage.
Awareness & Research
Client · Self-paced
- · Read the NS-CTAF framework overview and domain summaries
- · Review CTA certification levels and minimum requirements
- · Identify applicable regulations (EU CRA, DORA, EO 14028)
Framework understanding · Target CTA level identified
Initial Contact & Session
Client + NS
- · Reach out via info@nucleus-systems.com or the website
- · Introductory session or email exchange on scope
- · NS confirms eligibility and target CTA level
Agreed scope · Confirmed target CTA level
Proposal & Agreement
Client + NS
- · NS issues a fixed-fee proposal — $5,000 USD all-inclusive
- · Covers form, verification, session, report, and certificate
- · Client signs the engagement letter and processes payment
Signed agreement · Payment confirmed · Scheduled
Assessment Pack Issued
Nucleus Systems
- · NS issues the Client Assessment Guide and Excel Form
- · Client completes all domain tabs and the Scoping tab
- · Evidence Register populated · EV-IDs assigned
Completed form returned to Nucleus Systems
Validation Session
Client + NS
- · Walkthrough of all form answers with the client team
- · NS requests evidence samples for L3+ rated controls
- · Clarifications recorded · Ambiguous ratings confirmed
Verified answers · Evidence log · Outstanding items
Internal Analysis & Scoring
Nucleus Systems
- · NS independently scores all 86 controls
- · Trust Score computed · Domain scores weighted 0–100
- · CTA level determined · 7 hard gates verified
Trust Score · Domain scores · CTA level · Gap analysis
Draft Report Review
Client + NS
- · Draft report shared for factual-accuracy review
- · Client may correct context — not verified ratings
- · NS incorporates corrections and finalises content
Agreed findings · Finalised roadmap · Approved draft
Final Report & Certificate
Nucleus Systems
- · Signed final report issued with verified Trust Score
- · CTA Certificate issued at achieved level (CTA-1 → CTA-4)
- · Improvement roadmap and next assessment date confirmed
Final Report · CTA Certificate · Improvement Roadmap
Turn software assurance into an external trust signal.
Fixed fee $5,000 USD · ~20 business days · Final report, CTA certificate, and improvement roadmap.
