Role-based pathways to code trust
From boards to build engineers to accredited assessors — enablement that makes the Nucleus Systems Code Trust Assurance Framework operational across your organisation.
Code Trust Assurance Executive Briefing
Boards, CEOs, CIOs, CISOs, audit committees
Understand code trust as a business, operational, and regulatory risk.
Enrolment opening soonCode Trust Assurance Practitioner
Security engineers, DevSecOps, AppSec teams
Operate the framework's controls across the delivery lifecycle.
Enrolment opening soonCode Trust Assurance Developer Foundation
Software engineers and engineering managers
Build trust-by-design into everyday development.
Enrolment opening soonCode Trust Assurance Security Champion
Nominated champions in engineering teams
Drive secure development from within the team.
Enrolment opening soonCode Trust Assurance Assessor Training
Internal and external accredited assessors
Assess evidence, apply hard gates, and score consistently.
Enrolment opening soonCode Trust Assurance Procurement Training
Vendor risk, procurement, compliance teams
Use Nucleus Systems Code Trust Assurance Framework to evaluate and compare software suppliers.
Enrolment opening soonMaturity is a people problem before it is a tooling problem
A control reaches L3 when the practice is defined and consistently followed, and L4 when it is measured and managed. Neither is achievable if the people operating the pipeline do not know what the control requires or why it exists.
Someone knows how the control is meant to work, and it happens more often than not. Usually a single person or team.
The practice is written down and followed consistently across teams. This is where enablement stops being optional.
The practice is measured. Exceptions are visible, owned, and closed — which requires people who understand what the measurement means.
The practice improves on evidence. Teams change the control because the data told them to, not because an auditor did.
What every pathway includes
Tracks differ in depth and audience, not in structure. Each is built around the controls that role actually touches.
Role-scoped content
Only the domains and controls that role is accountable for — a board briefing and a build engineer course share no material.
Evidence literacy
What counts as T1 cryptographic evidence versus a T4 assertion, and how to produce the former as a by-product of normal work.
Worked assessment
Scoring real controls against the five axes, so the maturity levels stop being abstract.
Assessed completion
A check at the end. For the assessor track this is the accreditation examination.
The pathway to assessing on behalf of the framework
Certification is only worth what the assessor behind it is worth. The accreditation route is deliberately the most demanding pathway, and it carries ongoing obligations rather than a one-off qualification.
- 01
Complete the practitioner track and demonstrate working knowledge of all six domains.
- 02
Pass the accreditation examination, including scoring worked controls across the five axes.
- 03
Shadow supervised assessments before leading one independently.
- 04
Accept the assessor independence and conflict-of-interest policy in writing.
- 05
Submit to quality-assurance review of completed assessments, and to re-accreditation on each framework version.
Assessor accreditation is run through the partner programme, alongside consulting, technology, and regional representation tracks.
Partner & assessor programmeEnable your teams to build trust by design.
Ask about executive briefings and assessor accreditation.
