Nucleus Systems
Resources & knowledge hub

Thought leadership for software trust

Guides, whitepapers, checklists, and references that educate the market, support assessment readiness, and build confidence in the framework.

Whitepaper

Code Trust Assurance Executive Whitepaper

The case for code trust assurance intelligence, for boards and executives.

Coming soon
Guide

Code Trust Assurance Certification Guide

How the CTA-1 to CTA-4 certification programme works, end to end.

Coming soon
Checklist

Assessment Preparation Checklist

Get your evidence, scope, and teams ready before assessment.

Coming soon
Guide

Buyer’s Guide to Software Trust

For procurement and vendor-risk teams evaluating software suppliers.

Coming soon
Guide

SBOM & Dependency Assurance Guide

Practical guidance on SBOMs, CVE correlation, and supply-chain control.

Coming soon
Guide

Secure Build Pipeline Guide

Signing, provenance, reproducible builds, and SLSA in practice.

Coming soon
Guide

AI-Generated Code Assurance Guide

Attribution, enhanced review, and trust classification for AI code.

Coming soon
Reference

Code Trust Assurance Glossary

Definitions for every term used across the framework.

Coming soon
FAQ

Frequently Asked Questions

Common questions on assessment, scoring, and certification.

Coming soon
Available now

Glossary

The vocabulary the framework uses, in one line each. If a term below is unfamiliar, start here before reading the methodology.

Domain
One of the six areas of software trust the framework measures — who writes your code, whether artefacts are tamper-evident, how you build, what you depend on, how it behaves in production, and how it is governed.
Control
A single specific practice that gets rated. For example, whether every release is cryptographically signed. There are 86 of them.
Maturity level (L1–L5)
How well one control actually works, from ad hoc and undocumented (L1) through to continuously measured and improved (L5).
Scoring axis
One of the five dimensions each control is rated on: design adequacy, implementation coverage, operating effectiveness, monitoring and assurance, and automation and resilience.
Trust Score (0–100)
Every control rating, weighted by domain, rolled into one number that summarises overall software trust posture.
Hard gate
A foundational requirement that must pass regardless of the overall score. Strength elsewhere cannot compensate for it.
CTA level (CTA-1 to CTA-4)
The certification earned, from CTA-1 Transparent through to CTA-4 Adaptive Trust. Each has a Trust Score threshold and minimum domain maturities.
Evidence tier (T1–T4)
How strong a piece of evidence is. T1 is cryptographic and machine-verifiable; T4 is asserted. Weaker evidence caps the maturity a control can reach.
SBOM
Software Bill of Materials — a machine-readable inventory of every component in a piece of software, including transitive dependencies.
Provenance attestation
A signed, verifiable statement about how an artefact was built: by which pipeline, from which source, at which commit.
Drift
Divergence between what was assessed and what is actually running — a dependency that changed, a pipeline that was modified, a runtime that no longer matches its baseline.
Trust Registry
The public directory where a certified company, its level, and its certificate status can be verified by anyone.
Regulatory briefings

What the law already requires

These are in force now, with defined obligations and defined penalties. Each maps directly onto controls the framework scores.

EU Cyber Resilience Act

In force since December 2024

Article 13 mandates SBOM provision, Article 14 vulnerability handling with defined notification timelines, and Article 18 supply chain security for integrated components. Fines reach €15 million or 2.5% of global annual turnover.

US Executive Order 14028

Signed May 2021, implemented 2022–2024

Suppliers to the US federal government must attest to their software development practices, provide SBOMs for all delivered software, and demonstrate compliance with NIST SSDF SP 800-218.

DORA

Effective January 2025

Articles 28–30 require EU financial entities and their ICT providers to implement contractual security obligations, conduct supply chain risk assessments, and evidence third-party risk management.

Common questions

Frequently asked

The questions that come up most often before an assessment is commissioned.

How long does an assessment take?

Roughly 20 business days from kick-off to final report, assuming evidence is made available promptly. The elapsed time is driven mostly by evidence collection on your side, not by review time on ours.

What does it cost?

$15,000 USD, fixed and all-inclusive — scoping, evidence verification, the assessment session, the final report, the certificate, and the 12-month roadmap. There is no per-control or per-repository pricing.

Do we need to be certified to be assessed?

No. An assessment produces a Trust Score and a roadmap regardless of whether you clear a certification threshold. Many organisations do a first assessment specifically to find out where they stand.

Is our source code shared or stored?

No. The assessment works from evidence about your pipeline and controls — attestations, SBOMs, signing configuration, scan output, policy and process records. Sensitive technical evidence stays private; only the certificate and registry entry are public.

What happens if we fail a hard gate?

No CTA level is awarded, regardless of the overall Trust Score. The report identifies exactly which gate failed and what closing it requires. Hard gates exist precisely because strength elsewhere should not paper over a structural weakness.

How long is a certificate valid?

Certificates carry a validity period and a published status — Active, Expiring Soon, Expired, Suspended, Withdrawn, or Superseded. Anyone can check the current status in the Trust Registry at any time.

Does this replace our existing security tooling?

No, and it is not intended to. Scanner and pipeline output is an input to the assessment. The framework measures whether the system producing your software can be trusted — tooling tells you what is broken inside it.

How does it relate to ISO 27001, SOC 2, or NIST SSDF?

It maps to 30-plus frameworks and regulations rather than competing with them. Evidence collected once can be reused across overlapping obligations, which is most of the value for organisations already carrying several.

Prepare for assessment with the right resources.

Get the executive whitepaper, certification guide, and readiness checklist.