Thought leadership for software trust
Guides, whitepapers, checklists, and references that educate the market, support assessment readiness, and build confidence in the framework.
Code Trust Assurance Executive Whitepaper
The case for code trust assurance intelligence, for boards and executives.
Coming soonCode Trust Assurance Certification Guide
How the CTA-1 to CTA-4 certification programme works, end to end.
Coming soonAssessment Preparation Checklist
Get your evidence, scope, and teams ready before assessment.
Coming soonBuyer’s Guide to Software Trust
For procurement and vendor-risk teams evaluating software suppliers.
Coming soonSBOM & Dependency Assurance Guide
Practical guidance on SBOMs, CVE correlation, and supply-chain control.
Coming soonSecure Build Pipeline Guide
Signing, provenance, reproducible builds, and SLSA in practice.
Coming soonAI-Generated Code Assurance Guide
Attribution, enhanced review, and trust classification for AI code.
Coming soonCode Trust Assurance Glossary
Definitions for every term used across the framework.
Coming soonFrequently Asked Questions
Common questions on assessment, scoring, and certification.
Coming soonGlossary
The vocabulary the framework uses, in one line each. If a term below is unfamiliar, start here before reading the methodology.
What the law already requires
These are in force now, with defined obligations and defined penalties. Each maps directly onto controls the framework scores.
EU Cyber Resilience Act
In force since December 2024
Article 13 mandates SBOM provision, Article 14 vulnerability handling with defined notification timelines, and Article 18 supply chain security for integrated components. Fines reach €15 million or 2.5% of global annual turnover.
US Executive Order 14028
Signed May 2021, implemented 2022–2024
Suppliers to the US federal government must attest to their software development practices, provide SBOMs for all delivered software, and demonstrate compliance with NIST SSDF SP 800-218.
DORA
Effective January 2025
Articles 28–30 require EU financial entities and their ICT providers to implement contractual security obligations, conduct supply chain risk assessments, and evidence third-party risk management.
Frequently asked
The questions that come up most often before an assessment is commissioned.
How long does an assessment take?
Roughly 20 business days from kick-off to final report, assuming evidence is made available promptly. The elapsed time is driven mostly by evidence collection on your side, not by review time on ours.
What does it cost?
$15,000 USD, fixed and all-inclusive — scoping, evidence verification, the assessment session, the final report, the certificate, and the 12-month roadmap. There is no per-control or per-repository pricing.
Do we need to be certified to be assessed?
No. An assessment produces a Trust Score and a roadmap regardless of whether you clear a certification threshold. Many organisations do a first assessment specifically to find out where they stand.
Is our source code shared or stored?
No. The assessment works from evidence about your pipeline and controls — attestations, SBOMs, signing configuration, scan output, policy and process records. Sensitive technical evidence stays private; only the certificate and registry entry are public.
What happens if we fail a hard gate?
No CTA level is awarded, regardless of the overall Trust Score. The report identifies exactly which gate failed and what closing it requires. Hard gates exist precisely because strength elsewhere should not paper over a structural weakness.
How long is a certificate valid?
Certificates carry a validity period and a published status — Active, Expiring Soon, Expired, Suspended, Withdrawn, or Superseded. Anyone can check the current status in the Trust Registry at any time.
Does this replace our existing security tooling?
No, and it is not intended to. Scanner and pipeline output is an input to the assessment. The framework measures whether the system producing your software can be trusted — tooling tells you what is broken inside it.
How does it relate to ISO 27001, SOC 2, or NIST SSDF?
It maps to 30-plus frameworks and regulations rather than competing with them. Evidence collected once can be reused across overlapping obligations, which is most of the value for organisations already carrying several.
Prepare for assessment with the right resources.
Get the executive whitepaper, certification guide, and readiness checklist.
