Home
About
Core Pillars
Frameworks
Platforms
Solutions
Paxley Insights Contact
Request a briefing →
Core Pillar 3 · Proprietary Framework & Platform

NS-CTAF v1.0

A cryptographically grounded, continuously measurable standard for software trust — ending code trust theatre and establishing a unified architecture for proving that software is trustworthy across identity, integrity, supply chain, and runtime.

86Trust Controls
6Trust Domains
30+Frameworks Aligned
430Maturity Interpretations
CTA 1–4Certification Levels
Framework NS-CTAF v1.0 · 86 Trust Controls · 6 Domains Certification CTA-1 Entry · CTA-2 Standard · CTA-3 Advanced · CTA-4 Highest Assurance Coverage SBOM · Secrets Management · SCA · SAST · Dependency Governance AI Code 430 Maturity Interpretations · AI-Generated Code Auditing Aligned NIST SSDF · SLSA · OpenSSF · CycloneDX · SPDX · OWASP Supply Chain Software Supply Chain Risk · Third-Party Open-Source Governance Platform Paxley · GitHub-Native · Every Commit · Every PR · Every Release Framework NS-CTAF v1.0 · 86 Trust Controls · 6 Domains Certification CTA-1 Entry · CTA-2 Standard · CTA-3 Advanced · CTA-4 Highest Assurance Coverage SBOM · Secrets Management · SCA · SAST · Dependency Governance AI Code 430 Maturity Interpretations · AI-Generated Code Auditing Aligned NIST SSDF · SLSA · OpenSSF · CycloneDX · SPDX · OWASP Supply Chain Software Supply Chain Risk · Third-Party Open-Source Governance Platform Paxley · GitHub-Native · Every Commit · Every PR · Every Release
What Is NS-CTAF v1.0 and Why Was It Built?

NS-CTAF introduces Code Trust Assurance (CTA) as a distinct discipline — the practice of establishing, measuring, and continuously maintaining evidence-based trust in software across its full lifecycle: from developer identity and build integrity to deployment, runtime behaviour, and software supply-chain assurance.

Built for the supply-chain attack reality of 2026 — SolarWinds SUNBURST, Log4Shell, XZ Utils, Polyfill.io — where traditional scanning and compliance programmes cannot answer the trust questions now being asked by regulators, enterprise customers, investors, and acquirers.

Can you prove your code is what it claims to be?
Can you provide cryptographic evidence your build pipeline was not compromised?
Do you maintain independently verifiable SBOMs and software provenance records?
Can you continuously demonstrate the integrity, authenticity, and trustworthiness of your software supply chain?
The Problem
Code trust is assumed, not proven
Point-in-time scanning and compliance declarations cannot answer modern supply-chain trust questions
The Framework
86 controls · 6 domains · cryptographic evidence
Identity · Integrity · Secure Dev · Supply Chain · Runtime · Governance
The Outcome
Software trust as a measurable business capability
Operational resilience, customer confidence, regulatory readiness, and acquisition defensibility — provable, not claimed
Framework Architecture

Framework Domains & Coverage

6 integrated trust domains, 86 controls, one unified trust score. Each domain targets a critical layer of software trust exposure identified through real-world supply-chain attacks — together they sum to 100%.

D118%
D218%
D322%
D420%
D514%
D68%
D1 — Identity Developer Identity & Contributor Trust Controls covering developer identity verification, cryptographic code signing, contributor trust weighting, third-party identity vetting, and trust lineage graph maintenance. Addresses the XZ Utils-class attack vector.
18%IDENTITY LAYER
D2 — Integrity Build Pipeline Integrity & Artifact Signing Controls covering tamper-evident pipeline design, build provenance attestation, artifact signing (Sigstore/cosign), in-toto framework implementation, and pipeline security monitoring. Addresses the SolarWinds-class attack vector.
18%INTEGRITY LAYER
D3 — Secure Development SDLC Security & Code Quality Controls covering secure coding standards, SAST integration, code review governance, security training, threat modelling, automated security testing gates, and AI-generated code governance.
22%HIGHEST WEIGHT
D4 — Supply Chain Dependency Governance & SBOM Controls covering dependency inventory management, transitive dependency analysis, SBOM generation (CycloneDX/SPDX), dependency risk scoring, component origin verification, and SBOM correlation with CVEs. Addresses the Log4Shell-class attack vector.
20%SUPPLY CHAIN LAYER
D5 — Runtime Runtime Assurance & Behavioural Monitoring Controls covering runtime behavioural monitoring, anomaly detection in production, container and infrastructure security, DAST integration, incident traceability to code commits, and runtime policy enforcement.
14%RUNTIME LAYER
D6 — Governance Organisational Software Trust Governance Controls covering software trust policy framework, executive accountability, regulatory compliance reporting, customer-facing SBOM disclosure, supply chain contractual obligations, and continuous improvement.
8%GOVERNANCE LAYER

Framework Specification

NS-CTAF combines cryptographic assurance, software supply chain governance, secure development maturity, and continuous operational validation into a single, measurable Code Trust Assurance model.

Controls
86 fully defined trust controls with requirements, cryptographic grounding requirements, implementation guidance, and framework alignment citations across 30+ standards.
Scoring Model
5-axis maturity with domain weights reflecting supply chain risk concentration: D3 Secure Development at 22% (highest), D4 Supply Chain at 20%, D1/D2 Identity & Integrity at 18% each.
Maturity Scale
L1 Initial → L2 Developing → L3 Defined → L4 Managed → L5 Optimised — with 430 control-specific maturity interpretations (5 levels × 86 controls).
L1 InitialL2 DevelopingL3 DefinedL4 ManagedL5 Optimised
Certification Programme
The first external software trust certification backed by a structured maturity model:
CTA-1 TransparentCTA-2 VerifiedCTA-3 AssuredCTA-4 Adaptive Trust
Framework Alignment
30+ standards including: NIST SSDF SP 800-218 · SLSA · in-toto · Sigstore · OWASP SAMM · BSIMM · ISO/IEC 27001 · EU Cyber Resilience Act · US EO 14028 · NIS2 · DORA · PCI DSS v4
Management Tool
Excel-native workbook with auto-scoring, 340+ improvement recommendations, certification readiness tracker, roadmap generation, and board-ready Trust Score report.
Delivery Model
Repository-based assessment model. First automated results in <5 minutes via Paxley. Full advisory assessment: 1–3 weeks. Ongoing continuous monitoring via the Paxley platform.
Unique Differentiator
The only code security framework requiring cryptographic evidence, not self-reported status. A control cannot be rated above L2 without evidence that cannot be fabricated without computational effort proportional to the security claim.
Code Trust Assurance Platform

Paxley Code Security Platform

The automated delivery engine for NS-CTAF assessments and continuous code trust monitoring. Provides SAST (15+ languages, dataflow analysis), Software Composition Analysis with CVE detection, SBOM generation in CycloneDX and SPDX formats, IaC scanning (Terraform, Kubernetes, Pulumi, CDK), container image scanning, secrets detection (200+ patterns), and policy governance — all in one unified interface. Repository-based pricing from $99/repo/month delivers a 79% cost reduction vs per-seat incumbents. First scan results in under 5 minutes. SaaS or self-hosted deployment.

Services Delivered Under This Pillar

All services anchored to NS-CTAF v1.0 and delivered with the Paxley Code Security Platform as the automated evidence layer.

01

Code Trust Assurance Assessment & Roadmap

NS-CTAF baseline across all 6 trust domains with automated Paxley scanning, Trust Score and Maturity Report, SBOM generation, and prioritised roadmap.

02

CTA Certification Programme Management

Structured pathway from CTA-1 Transparent through CTA-4 Adaptive Trust — Nucleus as advisory partner, delivering a validated software trust signal for procurement.

03

DevSecOps Transformation & Secure Engineering Enablement

Integration of NS-CTAF controls into CI/CD pipelines, engineering workflows, release governance, IaC security, and developer security operating models.

04

Virtual DevSecOps Champion Support Service

Structured retainer for organisations needing practical, independent, sustained secure SDLC leadership without committing to a full-time AppSec or product security function.

05

Code Security Risk Assessment

Automated repository scanning via Paxley — SAST, SCA, SBOM, IaC, container security, and secrets detection as a unified, continuous evidence layer.

06

M&A-Focused Code Risk Assessment

Pre-close assessment of product and supply-chain risk embedded in codebase — IP and licensing exposure identification, attacker-validated evidence for investment committees.

07

DPI & Digital Public Goods Code Trust Service

NS-CTAF assessment and secure development advisory for DPGs and DPI — ensuring community-built software meets regulatory and trust requirements for public-purpose digital systems.

08

SBOM Governance & Continuous Software Transparency

Enterprise SBOM governance, supplier software transparency assessments, continuous dependency trust monitoring, and customer-facing software trust reporting aligned to CRA, NIS2, DORA.

09

Open Source Software Trust & Community Governance Advisory

Governance, contributor trust validation, secure open-source release management, dependency risk governance, and cryptographic integrity assurance for open-source software ecosystems and community-led engineering environments.

Prove your software is trustworthy — cryptographically, continuously

We baseline your code trust posture across all 6 domains and deliver a roadmap from assumed confidence to verifiable, board-reportable software trust.