Where software trust is defined and measured
The Nucleus Systems Code Trust Assurance Framework (NS-CTAF) is the standard for proving software can be trusted. It measures how well an organisation controls its software — from who writes the code to how it behaves in production — and turns that into one evidence-backed score.
What the Framework is, and what it actually does
The NS-CTAF exists to answer one question a customer, regulator, or insurer will eventually ask you: can your software be trusted — and can you prove it?
What it is
A structured, independently assessable standard for software trust. Not a scan and not a checklist — it measures whether the controls that protect your software genuinely work, and whether you can evidence it.
What it does
An independent assessor rates 86 controls across six domains, each on a five-level maturity scale. Those ratings roll up into a single Trust Score from 0 to 100 that a non-technical reader can act on.
What you get
A certification level from CTA-1 to CTA-4, a signed certificate, a board-ready report, a 12-month improvement roadmap, and a public Trust Registry listing anyone can verify.
How it works, step by step
You are assessed
You complete a structured assessment and provide evidence — SBOMs, signing records, scan output, policies, and pipeline logs.
Every control is rated
An assessor independently rates each control from L1 (ad hoc) to L5 (automated and continuously evidenced).
You get a Trust Score
Ratings are weighted by domain into a single 0–100 Trust Score, plus a gap analysis showing exactly what to fix first.
You are certified
Clear the score thresholds and the seven hard gates and you are certified CTA-1 to CTA-4, and listed publicly.
The terms, in one line each
Each domain is a trust boundary
Domain weights reflect their relative impact on overall software trust posture. Together they span identity, integrity, development, dependencies, runtime, and governance.
- D1Identity & Provenance18%
- D2Integrity & Immutability18%
- D3Secure Development Practices22%
- D4Dependency & Supply Chain20%
- D5Runtime Behavior Assurance14%
- D6Governance & Accountability8%
Identity & Provenance
Who wrote the code, and where it came from.
Developer and build identity cryptography, SBOM generation, contributor trust weighting, AI-generated code attribution, and cross-organisation identity federation.
Every software artifact inherits trust from its creators and origins. Without cryptographically verified developer identity, commit authorship cannot be attributed and dependency origins cannot be traced.
Maturity measures how well a control performs, not whether it exists
A control that exists on paper but fails under pressure, operates inconsistently, or lacks verifiable evidence does not represent maturity — it represents risk. Each of the 86 controls is rated independently, so the same organisation may be L4 on one and L1 on another.
L3 — Defined
Score 3.0Standardised, documented, and consistently applied across the full in-scope population, with a named owner and systematic evidence collection.
- Named owner with documented accountability
- Consistent application across all in-scope systems
- Regular review cycle with structured evidence
- Performance expectations formally defined
- Cryptographic controls fully deployed and verified
Maturity therefore represents a progression from ad hoc, reactive activity to continuous, automated, and independently verifiable assurance. At the highest levels trust is no longer assessed periodically — it is continuously computed, monitored, and improved.
From maturity ratings to one Trust Score
A control is only as strong as its weakest dimension, so each is scored across five weighted axes rather than given one subjective rating. Those roll into weighted domain scores and a single executive-readable Trust Score.
The five scoring axes
How the Trust Score is built
- 1 · Each applicable control is rated L1–L5 (1–5 points).
- 2 · A domain score is the weighted average of its control scores.
- 3 · The Trust Score sums each domain score × its domain weight.
- 4 · 7 hard gates must pass before any CTA level is awarded.
Hard gates address foundational security requirements that cannot be compensated for by high scores elsewhere — no amount of maturity in one domain can buy a certification level if a gate fails.
See how maturity moves the Trust Score
Drag each domain to the maturity level you believe you are at today. The weighted Trust Score and the certification level it would clear update as you go.
Set your maturity
Rate each domain from L1 to L5.
Indicative result
Indicative only. A real assessment rates all 86 controls individually across five scoring axes, and 7 hard gates must pass before any level is awarded — regardless of score.
Not all evidence is equal
Assessment is evidence-first. Cryptographic proof outranks documentation, which outranks assertion — and higher maturity levels require higher-tier evidence.
Cryptographic evidence
The strongest, machine-verifiable proof.
Signatures, attestations, hashes, transparency-log entries, SBOMs, provenance records.
System-generated artefacts
Automated output from tooling and pipelines.
CI/CD logs, automated scan reports, pipeline execution records, monitoring dashboards.
Structured documentation
Maintained records and process artefacts.
Policies, standards, process documents, architecture diagrams, manual records.
Management attestation
The weakest tier — assertions only.
Interview responses, declarations, and unverified assertions.
One assessment, many obligations
NS-CTAF maps to the standards and regulations that shape software security worldwide.
SLSA
FrameworkSupply-chain Levels for Software Artifacts — build integrity levels.
NIST SSDF (SP 800-218)
FrameworkSecure Software Development Framework practices.
OWASP SAMM v2
FrameworkSoftware Assurance Maturity Model.
in-toto
FrameworkSupply-chain step attestation framework.
EU Cyber Resilience Act
RegulationEU product cybersecurity and SBOM obligations.
DORA
RegulationDigital Operational Resilience Act for EU financial entities.
NIS2
RegulationEU network & information security directive.
US EO 14028
RegulationExecutive Order on improving the nation’s cybersecurity.
ISO/IEC 27001:2022
StandardInformation security management systems.
SOC 2
StandardTrust services criteria for service organisations.
PCI DSS v4.0.1
StandardPayment card industry data security standard.
NS-CTAF v1.0 in one table
The Nucleus Systems Code Trust Assurance Framework & Maturity Measurement Model v1.0 is a continuous, cryptographically verifiable, and measurable standard for software code trust — spanning identity, integrity, secure development, supply chain, runtime assurance, and governance.
Turn software assurance into an external trust signal.
Fixed fee $15,000 USD · ~20 business days · Final report, CTA certificate, and improvement roadmap.
