Nucleus Systems
Certification programme

Turn assessment results into a trust signal

NS-CTAF certification turns internal software assurance into an external trust signal — four levels, an independent review, and a public, verifiable certificate.

The four levels

CTA-1 Transparent to CTA-4 Adaptive Trust

Levels are earned by Trust Score and minimum domain maturity thresholds — and every level must clear the hard gates.

CTA-1Trust ≥ 30

Transparent

45+ controls

The software supply chain is visible. SBOMs, basic scanning, dependency inventory, and ownership are in place.

  • L2 maturity in D1, D4, and D6
  • Automated SBOM generation
  • Basic identity & governance controls
CTA-2Trust ≥ 48

Verified

63+ controls

Trust is backed by cryptographic evidence — artifact signing, build provenance, and automated security controls.

  • L3 maturity in D1–D3
  • Artifact signing & SLSA Build L2
  • SAST gate and threat modelling in place
CTA-3Trust ≥ 62

Assured

78+ controls

Trust is continuously measured across development, supply chain, runtime, and governance.

  • L3.5+ maturity across all domains
  • SLSA Build L3 and CVE patch SLAs
  • Runtime anomaly detection operating
CTA-4Trust ≥ 78

Adaptive Trust

86 / 86 controls

Trust is automated, continuously computed, self-healing, and independently verified.

  • L4+ maturity across all domains
  • SLSA Build L4 and reproducible builds
  • Trust API and continuous re-certification

Seven hard gates. 7 foundational requirements must pass before any CTA level is awarded — regardless of the overall Trust Score. They cannot be compensated for by strength in other areas.

Certification lifecycle

From application to renewal

Certification is a lifecycle, not a one-off — with annual renewal and, for higher levels, quarterly verification.

1

Application and commercial onboarding

2

Assessment scoping and evidence request

3

Evidence submission through the portal

4

Assessment and scoring

5

Independent review and certification decision

6

Certificate issue and registry listing

7

Annual renewal and, for higher levels, quarterly verification

8

Suspension or withdrawal if conditions degrade

Public certificate status

Status the market can rely on

Every certificate carries a public status. Basic verification is always free; deeper access is available through Report Access.

Active

Certificate is valid and current.

Expiring Soon

Expires within the notification period (e.g. 60 days).

Expired

Certificate validity has ended.

Suspended

Temporarily paused pending review.

Withdrawn

Certification has been removed.

Superseded

Replaced by a newer certificate or assessment.

Earn a trust signal your customers can verify.

Fixed fee $5,000 USD · ~20 business days · Final report, CTA certificate, and improvement roadmap.