Nucleus Systems
The framework

Where software trust is defined and measured

Code Trust Assurance Intelligence — creating public trust in the modern software supply chain. Six domains, 86 controls, five maturity levels, and a single 0–100 Trust Score.

Six domains

Each domain is a trust boundary

Domain weights reflect their relative impact on overall software trust posture. Together they span identity, integrity, development, dependencies, runtime, and governance.

D1 · 18%

Identity & Provenance

Developer and build identity cryptography, SBOM generation, contributor trust weighting, AI-generated code attribution, and cross-organisation identity federation.

18%
weight
15
controls
D2 · 18%

Integrity & Immutability

Artifact signing, build provenance attestation, reproducible builds, immutable artifact storage, SLSA level achievement, and binary transparency logging.

18%
weight
15
controls
D3 · 22%

Secure Development Practices

Threat modeling, SAST/DAST/IAST/RASP integration, secure coding standards, developer security training, Security Champions Programme, and penetration testing.

22%
weight
18
controls
D4 · 20%

Dependency & Supply Chain

CVE monitoring, dependency risk scoring, patch SLA management, private registry controls, SBOM-CVE correlation, and supplier contractual security obligations.

20%
weight
16
controls
D5 · 14%

Runtime Behavior Assurance

Runtime anomaly detection, behavioural baselines, drift detection, container runtime security, process behavior analytics, and runtime Trust Score updates.

14%
weight
12
controls
D6 · 8%

Governance & Accountability

CTA Governance Charter, executive accountability assignment, RACI matrix, audit trail management, policy-as-code enforcement, and regulatory compliance mapping.

8%
weight
10
controls
Control library

All 86 controls, searchable

Filter by domain or search by control ID, name, or what it assesses. This is the same control set an assessment scores independently, L1–L5.

86 of 86 controls
IDControlEvidenceMin. maturityRelevance
D1-01
Developer identity verification
NIST SSDFSLSAin-toto
T3L2+CTA-1
D1-02
Cryptographic commit signing
NIST SSDFSLSAin-toto
T1L2+CTA-1
D1-03
Contribution attribution & audit trail
NIST SSDFSLSAin-toto
T3L2+CTA-1
D1-04
Signing key lifecycle management
NIST SSDFSLSAin-toto
T1L2+CTA-1
D1-05
Build identity attestations
NIST SSDFSLSAin-toto
T1L2+CTA-1
D1-06
Pipeline identity & credentials
NIST SSDFSLSAin-toto
T3L2+CTA-1
D1-07
Automated SBOM generation
NIST SSDFSLSAin-toto
T1L2+CTA-1
D1-08
SBOM lifecycle management
NIST SSDFSLSAin-toto
T1L2+CTA-1
D1-09
Component origin verification
NIST SSDFSLSAin-toto
T3L2+CTA-1
D1-10
Contributor trust weighting
NIST SSDFSLSAin-toto
T3L2+CTA-1
D1-11
External contributor vetting
NIST SSDFSLSAin-toto
T3L2+CTA-1
D1-12
Credential revocation
NIST SSDFSLSAin-toto
T3L2+CTA-1
D1-13
Trust Lineage Graph
NIST SSDFSLSAin-toto
T3L4+CTA-3
D1-14
AI-generated code attribution
NIST SSDFSLSAin-toto
T3L4+CTA-3
D1-15
Federated identity standards
NIST SSDFSLSAin-toto
T1L5+CTA-4
D2-01
Signed commits enforcement
SLSAin-totoEU CRA
T1L3+CTA-2
D2-02
Artifact signing
SLSAin-totoEU CRA
T1L3+CTA-2
D2-03
Build provenance attestation
SLSAin-totoEU CRA
T1L3+CTA-2
D2-04
Tamper-evident pipeline
SLSAin-totoEU CRA
T3L3+CTA-2
D2-05
Reproducible builds
SLSAin-totoEU CRA
T1L5+CTA-4
D2-06
Immutable artifact storage
SLSAin-totoEU CRA
T1L3+CTA-2
D2-07
Pipeline integrity monitoring
SLSAin-totoEU CRA
T2L3+CTA-2
D2-08
Dependency hash verification
SLSAin-totoEU CRA
T1L3+CTA-2
D2-09
Release integrity gates
SLSAin-totoEU CRA
T3L3+CTA-2
D2-10
Container image signing
SLSAin-totoEU CRA
T1L3+CTA-2
D2-11
Package hash verification
SLSAin-totoEU CRA
T1L3+CTA-2
D2-12
Integrity exception governance
SLSAin-totoEU CRA
T3L3+CTA-2
D2-13
in-toto framework adoption
SLSAin-totoEU CRA
T1L3+CTA-2
D2-14
SLSA level achievement
SLSAin-totoEU CRA
T1L4+CTA-3
D2-15
Binary transparency logging
SLSAin-totoEU CRA
T1L5+CTA-4
D3-01
Threat modelling
NIST SSDFOWASP SAMM v2ISO 27001
T3L3+CTA-2
D3-02
Security requirements definition
NIST SSDFOWASP SAMM v2ISO 27001
T3L3+CTA-2
D3-03
Secure coding standards
NIST SSDFOWASP SAMM v2ISO 27001
T3L3+CTA-2
D3-04
Security training (role-specific)
NIST SSDFOWASP SAMM v2ISO 27001
T3L3+CTA-2
D3-05
SAST as CI/CD gate
NIST SSDFOWASP SAMM v2ISO 27001
T2L3+CTA-2
D3-06
DAST integration
NIST SSDFOWASP SAMM v2ISO 27001
T2L3+CTA-2
D3-07
IAST & RASP deployment
NIST SSDFOWASP SAMM v2ISO 27001
T2L4+CTA-3
D3-08
Fuzz testing programme
NIST SSDFOWASP SAMM v2ISO 27001
T2L4+CTA-3
D3-09
Security peer review
NIST SSDFOWASP SAMM v2ISO 27001
T3L3+CTA-2
D3-10
Pre-commit security hooks
NIST SSDFOWASP SAMM v2ISO 27001
T3L3+CTA-2
D3-11
Security Champions programme
NIST SSDFOWASP SAMM v2ISO 27001
T3L3+CTA-2
D3-12
Security requirements traceability
NIST SSDFOWASP SAMM v2ISO 27001
T3L3+CTA-2
D3-13
AI-generated code review policy
NIST SSDFOWASP SAMM v2ISO 27001
T3L3+CTA-2
D3-14
IaC security scanning
NIST SSDFOWASP SAMM v2ISO 27001
T2L3+CTA-2
D3-15
Container vulnerability scanning
NIST SSDFOWASP SAMM v2ISO 27001
T2L3+CTA-2
D3-16
API security testing
NIST SSDFOWASP SAMM v2ISO 27001
T2L3+CTA-2
D3-17
Security regression testing
NIST SSDFOWASP SAMM v2ISO 27001
T2L3+CTA-2
D3-18
Penetration testing
NIST SSDFOWASP SAMM v2ISO 27001
T2L3+CTA-2
D4-01
Dependency inventory
EU CRANIST SSDFSOC 2
T3L2+CTA-1
D4-02
Automated CVE monitoring
EU CRANIST SSDFSOC 2
T2L2+CTA-1
D4-03
Dependency risk scoring
EU CRANIST SSDFSOC 2
T3L2+CTA-1
D4-04
Patch SLA enforcement
EU CRANIST SSDFSOC 2
T3L2+CTA-1
D4-05
Licence compliance
EU CRANIST SSDFSOC 2
T3L2+CTA-1
D4-06
Transitive dependency analysis
EU CRANIST SSDFSOC 2
T3L2+CTA-1
D4-07
Vendor / OSS assessment
EU CRANIST SSDFSOC 2
T3L2+CTA-1
D4-08
Supply chain attack detection
EU CRANIST SSDFSOC 2
T2L2+CTA-1
D4-09
Automated dependency updates
EU CRANIST SSDFSOC 2
T2L2+CTA-1
D4-10
End-of-life tracking
EU CRANIST SSDFSOC 2
T3L2+CTA-1
D4-11
Private registry control
EU CRANIST SSDFSOC 2
T3L2+CTA-1
D4-12
Dependency pinning
EU CRANIST SSDFSOC 2
T3L2+CTA-1
D4-13
SBOM-CVE correlation
EU CRANIST SSDFSOC 2
T1L2+CTA-1
D4-14
Policy-as-code enforcement
EU CRANIST SSDFSOC 2
T3L4+CTA-3
D4-15
Dependency vetting workflow
EU CRANIST SSDFSOC 2
T3L2+CTA-1
D4-16
Contractual SBOM obligations
EU CRANIST SSDFSOC 2
T1L2+CTA-1
D5-01
Runtime anomaly detection
SOC 2ISO 27001PCI DSS
T2L4+CTA-3
D5-02
Behavioral baseline
SOC 2ISO 27001PCI DSS
T2L4+CTA-3
D5-03
Drift detection
SOC 2ISO 27001PCI DSS
T2L4+CTA-3
D5-04
RASP protection
SOC 2ISO 27001PCI DSS
T2L4+CTA-3
D5-05
Application behavioral monitoring
SOC 2ISO 27001PCI DSS
T2L4+CTA-3
D5-06
Kernel-level restrictions
SOC 2ISO 27001PCI DSS
T3L4+CTA-3
D5-07
Audit logging & distributed tracing
SOC 2ISO 27001PCI DSS
T2L4+CTA-3
D5-08
Runtime exploit detection
SOC 2ISO 27001PCI DSS
T2L4+CTA-3
D5-09
Memory safety controls
SOC 2ISO 27001PCI DSS
T3L4+CTA-3
D5-10
Process behavior analytics
SOC 2ISO 27001PCI DSS
T2L4+CTA-3
D5-11
Runtime trust score updates
SOC 2ISO 27001PCI DSS
T2L5+CTA-4
D5-12
Cloud-native runtime controls
SOC 2ISO 27001PCI DSS
T3L5+CTA-4
D6-01
CTA Governance Charter
ISO 27001DORANIS2
T3L2+CTA-1
D6-02
Executive accountability
ISO 27001DORANIS2
T3L2+CTA-1
D6-03
RACI matrix
ISO 27001DORANIS2
T3L2+CTA-1
D6-04
Audit trail management
ISO 27001DORANIS2
T3L2+CTA-1
D6-05
Compliance reporting
ISO 27001DORANIS2
T3L2+CTA-1
D6-06
Policy-as-code
ISO 27001DORANIS2
T3L2+CTA-1
D6-07
Certification programme management
ISO 27001DORANIS2
T3L2+CTA-1
D6-08
Third-party trust obligations
ISO 27001DORANIS2
T3L2+CTA-1
D6-09
Regulatory compliance matrix
ISO 27001DORANIS2
T3L2+CTA-1
D6-10
Continuous improvement programme
ISO 27001DORANIS2
T3L5+CTA-4
Maturity model

Five levels, applied per control

A maturity level is not an organisation-wide score — it characterises how well a specific capability is embedded. The same organisation may be L4 on one control and L1 on another.

L1
Initial· Ad Hoc

No documented process. The control is absent, informal, or exists only as individual knowledge. No named owner. Evidence is anecdotal. Risk is unmanaged.

L2
Developing· Basic

A process exists but is inconsistently applied. Manually executed and individual-dependent. Basic evidence exists but is not structured or regularly captured.

L3
Defined· Standard

Standardised, documented, and consistently applied across the organisation. Named owner. Structured evidence retained. The minimum regulatory baseline for most obligations.

L4
Managed· Measured

KPI-driven with continuous measurement. Performance tracked and reported. Exceptions formally managed with time-bounded resolution. System-generated evidence.

L5
Optimised· Automated

Fully automated, self-healing, and continuously evidenced. Independently assured by third-party attestation. Self-improving from measured outcomes and threat intelligence.

Scoring model

From maturity ratings to one Trust Score

Each control is scored across five axes, aggregated into weighted domain scores, then composed into a single executive-readable Trust Score.

The five scoring axes

01
Coverage
How much of the estate the control actually reaches.
02
Automation
How far the control runs without human intervention.
03
Integration
How deeply it is embedded into the delivery pipeline.
04
Verification
How independently the control’s operation can be proven.
05
Continuous Assurance
How continuously the control is evidenced over time.

How the Trust Score is built

  1. 1 · Each applicable control is rated L1–L5 (1–5 points).
  2. 2 · A domain score is the weighted average of its control scores.
  3. 3 · The Trust Score sums each domain score × its domain weight.
  4. 4 · 7 hard gates must pass before any CTA level is awarded.

Hard gates address foundational security requirements that cannot be compensated for by high scores elsewhere — no amount of maturity in one domain can buy a certification level if a gate fails.

80–100
Optimised · CTA-4 readiness
Sustain, validate through advanced testing, and publish high-assurance trust signals.
65–79
Managed · CTA-3 readiness
Increase automation and progress priority domains toward CTA-4.
50–64
Defined · CTA-2 readiness
Address gaps systematically and fund the maturity roadmap.
30–49
Developing · CTA-1 readiness
Create executive focus and fund remediation.
Below 30
Initial · High exposure
Escalate to leadership and establish a CTA-1 baseline first.
Evidence tiers

Not all evidence is equal

Assessment is evidence-first. Cryptographic proof outranks documentation, which outranks assertion — and higher maturity levels require higher-tier evidence.

T1

Cryptographic evidence

The strongest, machine-verifiable proof.

Signatures, attestations, hashes, transparency-log entries, SBOMs, provenance records.

T2

System-generated artefacts

Automated output from tooling and pipelines.

CI/CD logs, automated scan reports, pipeline execution records, monitoring dashboards.

T3

Structured documentation

Maintained records and process artefacts.

Policies, standards, process documents, architecture diagrams, manual records.

T4

Management attestation

The weakest tier — assertions only.

Interview responses, declarations, and unverified assertions.

Framework alignment

One assessment, many obligations

NS-CTAF maps to the standards and regulations that shape software security worldwide.

SLSA

Framework

Supply-chain Levels for Software Artifacts — build integrity levels.

NIST SSDF (SP 800-218)

Framework

Secure Software Development Framework practices.

OWASP SAMM v2

Framework

Software Assurance Maturity Model.

in-toto

Framework

Supply-chain step attestation framework.

EU Cyber Resilience Act

Regulation

EU product cybersecurity and SBOM obligations.

DORA

Regulation

Digital Operational Resilience Act for EU financial entities.

NIS2

Regulation

EU network & information security directive.

US EO 14028

Regulation

Executive Order on improving the nation’s cybersecurity.

ISO/IEC 27001:2022

Standard

Information security management systems.

SOC 2

Standard

Trust services criteria for service organisations.

PCI DSS v4.0.1

Standard

Payment card industry data security standard.

Turn software assurance into an external trust signal.

Fixed fee $5,000 USD · ~20 business days · Final report, CTA certificate, and improvement roadmap.