Nucleus Systems
Training & enablement

Role-based pathways to code trust

From boards to build engineers to accredited assessors — enablement that makes the Nucleus Systems Code Trust Assurance Framework operational across your organisation.

Code Trust Assurance Executive Briefing

Boards, CEOs, CIOs, CISOs, audit committees

Understand code trust as a business, operational, and regulatory risk.

Enrolment opening soon

Code Trust Assurance Practitioner

Security engineers, DevSecOps, AppSec teams

Operate the framework's controls across the delivery lifecycle.

Enrolment opening soon

Code Trust Assurance Developer Foundation

Software engineers and engineering managers

Build trust-by-design into everyday development.

Enrolment opening soon

Code Trust Assurance Security Champion

Nominated champions in engineering teams

Drive secure development from within the team.

Enrolment opening soon

Code Trust Assurance Assessor Training

Internal and external accredited assessors

Assess evidence, apply hard gates, and score consistently.

Enrolment opening soon

Code Trust Assurance Procurement Training

Vendor risk, procurement, compliance teams

Use Nucleus Systems Code Trust Assurance Framework to evaluate and compare software suppliers.

Enrolment opening soon
Why this is scored

Maturity is a people problem before it is a tooling problem

A control reaches L3 when the practice is defined and consistently followed, and L4 when it is measured and managed. Neither is achievable if the people operating the pipeline do not know what the control requires or why it exists.

L1 → L2

Someone knows how the control is meant to work, and it happens more often than not. Usually a single person or team.

L2 → L3

The practice is written down and followed consistently across teams. This is where enablement stops being optional.

L3 → L4

The practice is measured. Exceptions are visible, owned, and closed — which requires people who understand what the measurement means.

L4 → L5

The practice improves on evidence. Teams change the control because the data told them to, not because an auditor did.

Format

What every pathway includes

Tracks differ in depth and audience, not in structure. Each is built around the controls that role actually touches.

Role-scoped content

Only the domains and controls that role is accountable for — a board briefing and a build engineer course share no material.

Evidence literacy

What counts as T1 cryptographic evidence versus a T4 assertion, and how to produce the former as a by-product of normal work.

Worked assessment

Scoring real controls against the five axes, so the maturity levels stop being abstract.

Assessed completion

A check at the end. For the assessor track this is the accreditation examination.

Accredited assessors

The pathway to assessing on behalf of the framework

Certification is only worth what the assessor behind it is worth. The accreditation route is deliberately the most demanding pathway, and it carries ongoing obligations rather than a one-off qualification.

  1. 01

    Complete the practitioner track and demonstrate working knowledge of all six domains.

  2. 02

    Pass the accreditation examination, including scoring worked controls across the five axes.

  3. 03

    Shadow supervised assessments before leading one independently.

  4. 04

    Accept the assessor independence and conflict-of-interest policy in writing.

  5. 05

    Submit to quality-assurance review of completed assessments, and to re-accreditation on each framework version.

Assessor accreditation is run through the partner programme, alongside consulting, technology, and regional representation tracks.

Partner & assessor programme

Enable your teams to build trust by design.

Ask about executive briefings and assessor accreditation.