Checkmarx saves us a lot of time. We were using HPE Security Fortify to scan code for security vulnerabilities, but it can scan only after a successful compile. If the code has dependencies or build errors, the scan fails. With Checkmarx, pre-compile scanning is seamless. This allows us to scan more code.
Senior Software Security Analyst at a financial services firm with 1,001-5,000 employees
It scans code for security vulnerabilities without needing to compile first. It reports many false positives.
Pros and Cons
- "We were using HPE Security Fortify to scan code for security vulnerabilities, but it can scan only after a successful compile. If the code has dependencies or build errors, the scan fails. With Checkmarx, pre-compile scanning is seamless. This allows us to scan more code."
- "Checkmarx reports many false positives that we need to manually segregate and mark “Not exploitable”."
How has it helped my organization?
What is most valuable?
The most valuable feature is that Checkmarx scans code for security vulnerabilities without needing to compile first.
What needs improvement?
Checkmarx reports many false positives that we need to manually segregate and mark “Not exploitable”.
What do I think about the stability of the solution?
We encountered stability issues when scanning large code blocks. It consumes a lot of memory, and at times, Checkmarx services freeze and don’t work properly.
Buyer's Guide
Checkmarx One
February 2026
Learn what your peers think about Checkmarx One. Get advice and tips from experienced pros sharing their opinions. Updated: February 2026.
881,757 professionals have used our research since 2012.
What do I think about the scalability of the solution?
I don’t know of any scalability issues.
How are customer service and support?
Just four words for the technical support team: “Checkmarx team is awesome”.
Which solution did I use previously and why did I switch?
Before Checkmarx, we used HPE Security Fortify and IBM AppScan. We also tried several open-source scanning tools.
How was the initial setup?
Overall, the initial setup is easy. Checkmarx provides an installer binary and we just need go through the wizard for an express installation. If we need an advanced configuration, we contact the Checkmarx support team.
What's my experience with pricing, setup cost, and licensing?
I believe pricing is better compared to other commercial tools.
Which other solutions did I evaluate?
Yes, we compared Checkmarx features and benefits with IBM AppScan and HPE Security Fortify.
What other advice do I have?
Personally, I recommend Checkmarx for static analysis.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Assistant Manager Business Development at a tech services company with 501-1,000 employees
It offers comprehensive and incremental scanning, and supports all major languages.
Pros and Cons
- "Less false positive errors as compared to any other solution."
- "Licensing models and Swift language support are the aspects in which this product needs to improve. Swift is a new language, in which major customers require support for lower prices."
How has it helped my organization?
As an InfoSec consulting company, we come across major challenging projects. Checkmarx has made life easy and my team is best at using it. It reduces manual efforts in using test cases against any vulnerability found during source code reviews. Apart from OWASP Top Ten, Checkmarx is quite intelligent to find the latest vulnerability and report it.
What is most valuable?
Some valuable features of this product are:
- Very comprehensive scanning
- Less false positive errors as compared to any other solution
- Incremental scanning
- Supports all major languages
What needs improvement?
Licensing models and Swift language support are the aspects in which this product needs to improve. Swift is a new language, in which major customers require support for lower prices.
What do I think about the stability of the solution?
I have not encountered any stability issues.
What do I think about the scalability of the solution?
I have not encountered any scalability issues.
How are customer service and technical support?
I have never used technical support, so can't comment. We ourselves are expert at it.
Which solution did I use previously and why did I switch?
We have used no other product.
How was the initial setup?
The setup process was simple.
What's my experience with pricing, setup cost, and licensing?
It is the right price for quality delivery.
Which other solutions did I evaluate?
We did not evaluate other options, before choosing this product.
What other advice do I have?
Go for it.
Disclosure: My company has a business relationship with this vendor other than being a customer. We're the primary resellers of the product in India and Middle East region.
Buyer's Guide
Checkmarx One
February 2026
Learn what your peers think about Checkmarx One. Get advice and tips from experienced pros sharing their opinions. Updated: February 2026.
881,757 professionals have used our research since 2012.
Senior Software Security Analyst at a financial services firm with 1,001-5,000 employees
It allows for SAST scanning of uncompiled code. More API functionality should be added.
Pros and Cons
- "It allows for SAST scanning of uncompiled code. Further, it natively integrates with all key repos formats (Git, TFS, SVN, Perforce, etc)."
- "Meta data is always needed."
Improvements to My Organization
Cx gives you the ability to push SAST down much lower in the SDLC process. With the use of multiple IDE plugins and the ability to do "incremental" scanning, a scan of your latest code does not bog down your machine as it is offloaded.
Valuable Features
It allows for SAST scanning of uncompiled code. Further, it natively integrates with all key repos formats (Git, TFS, SVN, Perforce, etc).
Room for Improvement
Meta data is always needed. More tutorials/videos for developers to fix their vulnerabilities is nice. Although the API is useful, I would like to see more functionality added.
Stability Issues
I've had to restart services/bounce the VM on two rare occasions.
Scalability Issues
It scales very easy.
Customer Service and Technical Support
Customer Service:
Customer service is good. Engineers have been quick to get back to me regarding issues and custom work that I have performed.
Technical Support:
Technical support is very knowledgeable.
Initial Setup
Initial setup couldn't be any easier. Cx has good documentation on environment requirements. As long as you meet those, the installation process takes maybe 30 minutes for an initial setup; perhaps a bit longer if you're adding multiple engines.
Implementation Team
An in-house team implemented it.
Pricing, Setup Cost and Licensing
Everything is negotiable. Checkmarx approached our dealings in good faith and clearly wanted to be around for awhile. It is much more inexpensive than some alternatives.
Other Solutions Considered
Before choosing, we also evaluated Fortify, IBM Appscan, Veracode, etc.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Full Stack Developer at a tech services company with 51-200 employees
It helps with vulnerability scanning of codes to prevent vulnerability of our applications.
What is most valuable?
It provides us with code analysis.
How has it helped my organization?
It helps with vulnerability scanning of codes to prevent vulnerability of our applications.
For how long have I used the solution?
I've used it for one year.
What was my experience with deployment of the solution?
No issues encountered.
Which solution did I use previously and why did I switch?
Straight forward. Easy to follow steps.
I worked for an IT security firm and it was quite easy to setup the product for demo purposes virtually and even physically on the client premises
How was the initial setup?
It was straightforward, as it has easy to follow steps.
I worked for an IT security firm and it was quite easy to setup the product for demo purposes virtually and even physically on the client premises.
What's my experience with pricing, setup cost, and licensing?
The license is fairly costly but worth the investment.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partners
Co-Founder, CTO at a tech services company with 51-200 employees
It allows us to verify the dev department's code in order to minimize security holes, but it needs better role management.
What is most valuable?
They're all as valuable as each other.
How has it helped my organization?
We have used this product to verify the dev department's code in order to minimize security holes.
What needs improvement?
It needs better role management.
For how long have I used the solution?
I've used it for three years.
What was my experience with deployment of the solution?
No issues encountered.
What do I think about the stability of the solution?
No issues encountered.
What do I think about the scalability of the solution?
No issues encountered.
How are customer service and technical support?
Customer Service:
It's very good.
Technical Support:It's very good.
Which solution did I use previously and why did I switch?
This is the only solution I have used.
How was the initial setup?
Very straightforward.
What about the implementation team?
I implemented it myself.
What's my experience with pricing, setup cost, and licensing?
Licensing is expensive per X amount of lines in the code.
Which other solutions did I evaluate?
No other options were evaluated.
Disclosure: My company has a business relationship with this vendor other than being a customer. We are providing leads to Checkmarx.
Going for another POC with Checkmarx... This time implementing it with Jira, to open an automatic flow for better mitigation SLA and for Infosec visibility
Cyber-Ark Consultant at a tech services company with 51-200 employees
It is a very good product, but it needs a better understanding of file references.
What is most valuable?
It provides a graphical view of any vulnerabilities.
How has it helped my organization?
I have used it as a consultant.
What needs improvement?
It could be improved with more reporting of false positives and the understanding of file references.
For how long have I used the solution?
I've used it for one year.
What was my experience with deployment of the solution?
No issues encountered.
What do I think about the stability of the solution?
No issues encountered.
What do I think about the scalability of the solution?
One needs to be sure on the number of LOC that will be run and also the size of the code.
How are customer service and technical support?
Customer Service:
8/10.
Technical Support:8/10.
Which solution did I use previously and why did I switch?
I have used Armorize codesecure.
How was the initial setup?
It's a straightforward deployment, and it learns with time.
What about the implementation team?
I implement it.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Arquitecto de soluciones at a tech services company with 1,001-5,000 employees
Has GPT and Copilot integration, and UI is easy to navigate
Pros and Cons
- "The tool's valuable features include integrating GPT and Copilot. Additionally, the UI web representation is very user-friendly, making navigation easy. GPT has made several improvements to my security code."
- "I can't create a business case with multiple-factor authentication."
What is our primary use case?
I use the tool for testing purposes.
What is most valuable?
The tool's valuable features include integrating GPT and Copilot. Additionally, the UI web representation is very user-friendly, making navigation easy. GPT has made several improvements to my security code.
What needs improvement?
I can't create a business case with multiple-factor authentication.
For how long have I used the solution?
I have been working with the product for two years.
How are customer service and support?
While support handles tickets and resolves specific issues, such as business cases, it can be frustrating waiting for responses. They often take a lot of time to address cases or provide resolutions.
How would you rate customer service and support?
Neutral
How was the initial setup?
Checkmarx One's deployment is easy. When we deployed it for a new client, it took around a month to complete. This involved setting up all parameters and sub-administrators. Additionally, finalizing the project involved several tasks, such as scanning with all security gates.
What was our ROI?
We can get a return in six months.
What's my experience with pricing, setup cost, and licensing?
The tool's pricing is fine.
What other advice do I have?
I rate the overall product an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Cyber Security Engineer at a tech services company with 1-10 employees
A stable solution that helps with dynamic application testing
Pros and Cons
- "We use the solution for dynamic application testing."
- "I would like the product to include more debugging and developed tools. It needs to also add enhancements on the coding side."
What is our primary use case?
We use the solution for dynamic application testing.
What needs improvement?
I would like the product to include more debugging and developed tools. It needs to also add enhancements on the coding side.
For how long have I used the solution?
I have been working with the product for seven months.
What do I think about the stability of the solution?
I would rate the product's stability a ten out of ten.
What do I think about the scalability of the solution?
I would rate the product's scalability a ten out of ten. My company has 15 users for the produc.
How are customer service and support?
The solution's technical support is good.
How would you rate customer service and support?
Positive
How was the initial setup?
The tool's setup is very straightforward and I would rate it a ten out of ten. The product's deployment took one to two months to complete. We required the technical and development team which consisted of four to five people to handle the deployment.
What's my experience with pricing, setup cost, and licensing?
The solution's price is high and you pay based on the number of users.
What other advice do I have?
I would rate the product a ten out of ten. The solution is the best tool for developers and organizations.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Checkmarx One Report and get advice and tips from experienced pros
sharing their opinions.
Updated: February 2026
Product Categories
Application Security Tools Static Application Security Testing (SAST) Vulnerability Management Container Security Static Code Analysis API Security Dynamic Application Security Testing (DAST) DevSecOps Risk-Based Vulnerability Management Application Security Posture Management (ASPM) AI SecurityPopular Comparisons
SonarQube
SentinelOne Singularity Cloud Security
Microsoft Defender for Cloud
Prisma Cloud by Palo Alto Networks
GitLab
Veracode
Imperva Application Security Platform
Coverity Static
CrowdStrike Falcon Cloud Security
JFrog Xray
Orca Security
Tenable Security Center
GitHub Advanced Security
Buyer's Guide
Download our free Checkmarx One Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What is the biggest difference between Veracode and Checkmarx?
- Checkmarx or Veracode. Which should we choose?
- What is the Biggest Difference Between Checkmarx and Fortify?
- What is the biggest difference between Checkmarx and SonarQube?
- Checkmarx vs SonarQube; SonarQube interoperability with Checkmarx or Veracode
- If you had to both encrypt and compress data during transmission, which would you do first and why?
- When evaluating Application Security, what aspect do you think is the most important to look for?
- What are the Top 5 cybersecurity trends in 2022?
- What are the threats associated with using ‘bogus’ cybersecurity tools?
- We're evaluating Tripwire, what else should we consider?



















Hi Joe,
Given that you've continued to successfully use Checkmarx for an extended period of time since you contributed to our discussion that compares the solution to Veracode,
How does your experience compare one year later?
(See the discussion thread here:
www.itcentralstation.com/questions/checkmarx-or-veracode-which-should-we-choose)
Looking forward to your feedback