Nucleus Systems
What is NS-CTAF

A measurable architecture for software trust

NS-CTAF measures whether software can be trusted across its full lifecycle — from developer identity and code integrity to secure development, dependencies, runtime behaviour, and governance accountability.

Definition

Not a checklist. Not a scan.

NS-CTAF is not a simple checklist or a vulnerability scanning method. It is a measurable trust assurance architecture that evaluates evidence quality, implementation coverage, operating effectiveness, monitoring, and automation.

It treats every stage of software production and distribution as an independently assessable trust boundary — producing a single quantified Trust Score (0–100) and a four-level CTA certification you can show customers, partners, regulators, and insurers.

Why NS-CTAF exists

Every input is a trust decision

Modern software is assembled from internal code, open-source components, build tools, CI/CD pipelines, containers, cloud services, APIs, and increasingly AI-generated code. NS-CTAF exists because most organisations cannot prove, continuously and with evidence, that those trust decisions are controlled.

Software supply chain attacks increasingly exploit trusted identities, components, and pipelines.

SBOM and dependency visibility are becoming procurement and regulatory expectations.

AI-generated code introduces new attribution, review, and trust-classification challenges.

Customers, regulators, investors, and acquirers increasingly need evidence-backed assurance.

Who created NS-CTAF

Built by Nucleus Systems

NS-CTAF was created by Nucleus Systems as part of its work in software assurance, code security, secure delivery, supply-chain risk, and evidence-based maturity measurement.

The framework

The NS-CTAF model itself — 86 controls, six domains, and the Trust Score methodology.

The assessment

A fixed-fee, evidence-first engagement that independently scores your posture.

The certification

A public CTA-1 to CTA-4 signal, listed in the Trust Registry and independently verifiable.

As adoption grows, Nucleus Systems is introducing independent advisors, accredited assessors, and a partner ecosystem to sustain the framework’s independence and rigour.

Real-life use cases

Who NS-CTAF helps

From software vendors to regulators, NS-CTAF turns software trust into something measurable and comparable.

Software vendors
Demonstrate trust posture to customers and procurement teams.
Banks & financial institutions
Assess ICT supplier and software supply-chain risk.
Open-source projects
Show maturity around identity, provenance, and secure development.
Enterprises
Build a measurable code-trust programme across internal applications.
Regulators & auditors
Review evidence-backed maturity against applicable obligations.
M&A and investors
Assess software product risk during due diligence.
Boards
Understand code trust as a business, operational, and regulatory metric.

Security tools find issues. NS-CTAF proves trust.

Fixed fee $5,000 USD · ~20 business days · Final report, CTA certificate, and improvement roadmap.