A measurable architecture for software trust
NS-CTAF measures whether software can be trusted across its full lifecycle — from developer identity and code integrity to secure development, dependencies, runtime behaviour, and governance accountability.
Not a checklist. Not a scan.
NS-CTAF is not a simple checklist or a vulnerability scanning method. It is a measurable trust assurance architecture that evaluates evidence quality, implementation coverage, operating effectiveness, monitoring, and automation.
It treats every stage of software production and distribution as an independently assessable trust boundary — producing a single quantified Trust Score (0–100) and a four-level CTA certification you can show customers, partners, regulators, and insurers.
Every input is a trust decision
Modern software is assembled from internal code, open-source components, build tools, CI/CD pipelines, containers, cloud services, APIs, and increasingly AI-generated code. NS-CTAF exists because most organisations cannot prove, continuously and with evidence, that those trust decisions are controlled.
Software supply chain attacks increasingly exploit trusted identities, components, and pipelines.
SBOM and dependency visibility are becoming procurement and regulatory expectations.
AI-generated code introduces new attribution, review, and trust-classification challenges.
Customers, regulators, investors, and acquirers increasingly need evidence-backed assurance.
Six domains of software trust
NS-CTAF structures trust into six weighted domains, each an independently assessable dimension of the software supply chain.
Identity & Provenance
Who wrote the code, and where it came from.
Integrity & Immutability
Whether builds and artifacts are tamper-proof.
Secure Development Practices
Whether secure engineering stops vulnerabilities at the source.
Dependency & Supply Chain
Whether third-party components are governed and controlled.
Runtime Behavior Assurance
Whether deployed software keeps behaving as expected.
Governance & Accountability
Whether ownership and policy sustain trust over time.
Built by Nucleus Systems
NS-CTAF was created by Nucleus Systems as part of its work in software assurance, code security, secure delivery, supply-chain risk, and evidence-based maturity measurement.
The framework
The NS-CTAF model itself — 86 controls, six domains, and the Trust Score methodology.
The assessment
A fixed-fee, evidence-first engagement that independently scores your posture.
The certification
A public CTA-1 to CTA-4 signal, listed in the Trust Registry and independently verifiable.
As adoption grows, Nucleus Systems is introducing independent advisors, accredited assessors, and a partner ecosystem to sustain the framework’s independence and rigour.
Who NS-CTAF helps
From software vendors to regulators, NS-CTAF turns software trust into something measurable and comparable.
Security tools find issues. NS-CTAF proves trust.
Fixed fee $5,000 USD · ~20 business days · Final report, CTA certificate, and improvement roadmap.
