We mainly use this solution for static comprehension testing.
Senior Software Engineering Manager at a financial services firm with 10,001+ employees
Used for static comprehension testing and helps us detect vulnerabilities early
Pros and Cons
- "The administration in Checkmarx is very good."
- "We want to have a holistic view of the portfolio-level dashboard and not just an individual technical project level."
What is our primary use case?
How has it helped my organization?
We use it for non-functional insight because it's a security vulnerability scanner. We can use Checkmarx for scanning anytime on our code base. We integrated that as part of our build-a-pipeline, and it helps us detect early. We have piloted in few applications for the shift of testing. From a metric perspective, I am unsure how we benefited from the quantifiable data, but we did benefit.
What is most valuable?
The administration in Checkmarx is very good. You can create specific teams which give you access to specific projects.
What needs improvement?
The benefits could be improved. We are a banking company, so we focus on security. We use Checkmarx for multiple applications, and IAST is an interactive application security testing that Checkmarx claims; however, we have not explored it yet.
We want to have a holistic view of the portfolio-level dashboard and not just an individual technical project level. We want an option to group several projects and view them at a business level. Additional features could include a comprehensive dashboard and secret scanning capabilities.
Buyer's Guide
Checkmarx One
June 2026
Learn what your peers think about Checkmarx One. Get advice and tips from experienced pros sharing their opinions. Updated: June 2026.
900,747 professionals have used our research since 2012.
For how long have I used the solution?
We have been using this solution for four years. It is deployed on-premises.
What do I think about the stability of the solution?
I rate the stability a six out of ten. We've had some stability issues, which may have been because of how we deployed the solution. When multiple scans are running in multiple applications, it closes down. This also happens where there is a large code base. After it runs for about 35 minutes, it abruptly closes. We have been discussing this issue with the Checkmarx team for it to be fixed.
What do I think about the scalability of the solution?
I rate the scalability a six out of ten, and we have 100 staff engineers using this solution.
How are customer service and support?
Our Checkmarx team interacts with their technical support.
Which solution did I use previously and why did I switch?
I've used Veracode, and there isn't a big difference between both solutions.
How was the initial setup?
I rate the initial setup a seven out of ten. When we integrated it, we built a pipeline, which was done by a separate DevOps team. Checkmarx is installed at the enterprise level, and we have a Checkmarx Dev team that runs the solution.
What other advice do I have?
I rate this solution an eight out of ten. I would recommend going for a piloting approach. With Checkmarx, you have different presets and can determine the security vulnerability standard. Also, check the stability before proceeding with the adoption.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Security Architect at a financial services firm with 5,001-10,000 employees
Easily scalable and finds more vulnerabilities than other tools
Pros and Cons
- "The best thing about Checkmarx is the amount of vulnerabilities that it can find compared to other free tools."
- "The statistics module has a function that allows you to show some statistics, but I think it's limited. Maybe it needs more information."
- "The default module that provides statistics is basic, and you need more elaborate information to do vulnerability management."
What is most valuable?
The best thing about Checkmarx is the amount of vulnerabilities that it can find compared to other free tools.
What needs improvement?
The statistics module has a function that allows you to show some statistics, but I think it's limited. Maybe it needs more information. There are some cases where you have to go directly to the Checkmarx database to get the information that you want. The default module that provides statistics is basic, and you need more elaborate information to do vulnerability management. The tool has a limited scope.
What do I think about the scalability of the solution?
It is easy to scale, you just have to pay. There are about 100 developers and security people using this solution in my company.
How are customer service and support?
The contract that we have is not directly with Checkmarx. It's with an intermediary company in Argentina, and they give us support. They are not very fast in answering our questions. They have a kind of first level support, but for more technical stuff they go directly to Checkmarx.
What's my experience with pricing, setup cost, and licensing?
As with other tools, if you want more, you have to pay more. You have to pay for additional modules or functionalities. For instance, if you want to do some scanning to external dependencies of the software, you have to buy another tool provided by Checkmarx.
You have to pay for licenses for the number of projects that you want to scan and the number of users. I think you have to pay licenses for three features: the number of users, the projects, and I don't remember the other one.
What other advice do I have?
We have two administrators who coordinate maintenance with the vendor.
My advice is that you need to estimate the right amount of licenses. That's very important because right now, our company needs more licenses, and that was not well estimated at the beginning. The other thing is to be clear about the features of this tool that you want or need.
I would rate this solution as a nine out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Checkmarx One
June 2026
Learn what your peers think about Checkmarx One. Get advice and tips from experienced pros sharing their opinions. Updated: June 2026.
900,747 professionals have used our research since 2012.
It's easy to initiate scans and triage defects.
Pros and Cons
- "The main thing we find valuable about Checkmarx is the ease of use, as it's easy to initiate scans and triage defects."
- "As the solution becomes more complex and feature rich, it takes more time to debug and resolve problems. Feature-wise, we have no complaints, but Checkmarx becomes harder to maintain as the product becomes more complex. When I talk to support, it takes them longer to fix the problem than it used to."
What is most valuable?
The main thing we find valuable about Checkmarx is the ease of use. It's easy to initiate scans and triage defects.
What needs improvement?
As the solution becomes more complex and feature rich, it takes more time to debug and resolve problems. Feature-wise, we have no complaints, but Checkmarx becomes harder to maintain as the product becomes more complex. When I talk to support, it takes them longer to fix the problem than it used to.
For how long have I used the solution?
We've been using Checkmarx for five years now.
What do I think about the stability of the solution?
Checkmarx is stable.
What do I think about the scalability of the solution?
Checkmarx is scalable. We can add more engines without a problem.
How was the initial setup?
Deploying Checkmarx isn't straightforward. It is a little complex, so it requires somebody well-versed in DevOps and Linux administration or Windows administration to do the setup.
What was our ROI?
We've seen a good return.
What's my experience with pricing, setup cost, and licensing?
Checkmarx costs us around $132,000 annually.
Which other solutions did I evaluate?
We evaluated CAST, Fortify, and HCL AppScan, but the deciding factor was Checkmarx's ease of use.
What other advice do I have?
I rate Checkmarx eight out of 10. It's secure, easy to use, and Checkmarx regularly updates their rule sets. I'm happy with the main features of the product, but some of the additional features didn't work for us in the beginning, like scanning at the source code repository level, reporting, etc. There was a lot of back and forth before it started working, so that's why I deducted two points.
My advice for future Checkmarx users is to plan the initial deployment well. You will have to choose the right system configuration: CPUs, RAM, disk space, and backup policy. If you plan ahead, you won't have any issues trying to debug or when the size increases.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Founder & Chairman at Endpoint-labs Cyber Security R&D
Enhanced security with robust feature set for comprehensive protection
Pros and Cons
- "Checkmarx offers many valuable features, including Static Application Security Testing (SAST), Software Composition Analysis (SCA), Infrastructure as Code (IAC), Supply Chain Security, and API Security."
- "The Dynamic Application Security Testing (DAST) feature should be better."
What is our primary use case?
I am representing Checkmarx as a reseller. I work with both the cloud and on-premises versions. I have been working with Checkmarx for more than twelve years.
How has it helped my organization?
Checkmarx is a must-use product due to the increasing number of cyber-attacks nowadays. The product's quality and performance justify its pricing, making it a worthwhile investment.
What is most valuable?
Checkmarx offers many valuable features, including Static Application Security Testing (SAST), Software Composition Analysis (SCA), Infrastructure as Code (IAC), Supply Chain Security, and API Security.
What needs improvement?
The Dynamic Application Security Testing (DAST) feature should be better. The technical support service could also improve in terms of their response time.
For how long have I used the solution?
I have been working with Checkmarx since the early days of Checkmarx, which is more than 12 years.
What do I think about the stability of the solution?
I would rate the stability of Checkmarx at nine out of ten.
What do I think about the scalability of the solution?
Checkmarx is scalable, and I would rate its scalability at nine out of ten.
How are customer service and support?
The customer service and support should be quicker from my point of view. I would rate them eight out of ten.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I have been working with Checkmarx for over 12 years without switching to a competitor due to Checkmarx being the best product in the market.
How was the initial setup?
The initial setup is straightforward, especially with the cloud version where no deployment is needed. The on-premises version requires some time and depends on the customer's environment.
What about the implementation team?
In typical circumstances, one senior engineer is enough for implementation, but in special cases, maybe two engineers are needed.
What was our ROI?
Checkmarx is cost-effective. It is a must-use product in today's cyber security environment.
What's my experience with pricing, setup cost, and licensing?
The pricing is relatively expensive due to the product's quality and performance, but it is worth it.
Which other solutions did I evaluate?
I chose Checkmarx over competitors due to ethical considerations and its superior functionality.
What other advice do I have?
Checkmarx is plug-and-play and the best product in the market at the moment, as evidenced by reports such as Gartner's.
I'd rate the solution nine out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer.
Penetration Tester & Information Security Expert at a comms service provider with 11-50 employees
Responsive support, useful code-checking module, and high availability
Pros and Cons
- "The most valuable features of Checkmarx are the SCA module and the code-checking module. Additionally, the solutions are explanatory and helpful."
- "Checkmarx could improve the solution reports and false positives. The false positives could be reduced. For example, we have alerts that are tagged as vulnerabilities but when you drill down they are not."
What is our primary use case?
Checkmarx is used to check the code from programmers and vulnerabilities in third-party software.
Checkmarx can be deployed on the cloud and on-premise. However, it depends on the version.
How has it helped my organization?
Checkmarx detected code sections that did not adhere to best practices. After being informed, the programmers were able to rectify some of the issues. Without Checkmarx, it is unlikely we would have identified these issues.
Utilizing the SCA module, I gained valuable insights into the vulnerabilities present in open-source Python libraries that individuals desire to use. As an information security consultant, I advise against employing Python libraries that contain known vulnerabilities. The SCA solution proved to be helpful in this regard.
What is most valuable?
The most valuable features of Checkmarx are the SCA module and the code-checking module. Additionally, the solutions are explanatory and helpful.
What needs improvement?
Checkmarx could improve the solution reports and false positives. The false positives could be reduced. For example, we have alerts that are tagged as vulnerabilities but when you drill down they are not.
In a future release, the SCA module could have better documentation. It was difficult to know how to check the names of all the modules. It took me a lot of time and I needed help to be able to write the requirements file. More clarification would be helpful in the documentation, such as examples.
For how long have I used the solution?
I have been using Checkmarx for approximately six months.
What do I think about the stability of the solution?
The stability is great.
I rate the stability of Checkmarx a ten out of ten.
What do I think about the scalability of the solution?
The scalability of the solution is great. Everything I send to the solution is processed quickly.
We have five information security analysts and programmers using this solution.
We plan to increase our usage. We will install it on more networks.
I rate the scalability of Checkmarx a ten out of ten.
How are customer service and support?
I found someone in the evening that logged in and answered my issues. They are responsive.
I rate the support of Checkmarx a ten out of ten.
How would you rate customer service and support?
Positive
What other advice do I have?
We have one person for the maintenance of the solution but it is minimal and is not a full-time job.
I would advise others to ask for a demo of the solution and if it works well for their use case then purchase it.
I rate Checkmarx a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. consultant
Head of DevOps at Tpconnects technologies
A highly recommended tool for delivering secure products
Pros and Cons
- "Checkmarx has helped us deliver more secure products. We are able to do static code analysis with the tool before shipping our code to production. When the integration is in the pipeline, this tool gives us early notifications on code fixes."
- "I would like to see the tool’s pricing improved."
What is our primary use case?
We use the solution for SAST and DAST testing.
How has it helped my organization?
Checkmarx has helped us deliver more secure products. We are able to do static code analysis with the tool before shipping our code to production. When the integration is in the pipeline, this tool gives us early notifications on code fixes.
What is most valuable?
Checkmarx gives you an overview of all security aspects of the codes and shows what code aspects you need to be looking into.
What needs improvement?
I would like to see the tool’s pricing improved.
For how long have I used the solution?
I have been working with the solution for three years. At present, I am using the latest version.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
The solution is scalable. Around 50 developers in our organization are using it.
How was the initial setup?
The solution was easy to setup since it had proper documentation.
What about the implementation team?
The solution’s deployment was done by in-house members.
What was our ROI?
We got good ROI with the use of the solution. We have seen returns on PCI and other security aspects.
What's my experience with pricing, setup cost, and licensing?
I would rate the solution’s pricing an eight out of ten. The tool’s pricing is higher than others and it is for the license alone.
What other advice do I have?
I would rate the solution an eight out of ten since it fulfills most of the requirements. I recommend this tool to anyone who is willing to give it a try.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Practice Lead - Cyber Security at a tech vendor with 10,001+ employees
It has fewer false positives than other products, giving you better results
Pros and Cons
- "What I like best about Checkmarx is that it has fewer false positives than other products, giving you better results."
- "One area for improvement in Checkmarx is pricing, as it's more expensive than other products."
What is our primary use case?
We primarily use Checkmarx for assessing vulnerabilities in applications.
What is most valuable?
What I like best about Checkmarx is that it has fewer false positives than other products, giving you better results.
What needs improvement?
One area for improvement in Checkmarx is pricing, as it's more expensive than other products.
For how long have I used the solution?
I've used Checkmarx for four to five years.
What do I think about the stability of the solution?
Regarding Checkmarx stability, it's an eight out of ten.
What do I think about the scalability of the solution?
Checkmarx is a scalable tool and much better scalability-wise than other products I used. I'm rating its scalability as eight out of ten.
How are customer service and support?
We never had to contact the Checkmarx technical support team.
How was the initial setup?
I was not involved in the initial setup for Checkmarx.
What's my experience with pricing, setup cost, and licensing?
Checkmarx is comparatively costlier than other products, which is why some of the customers feel reluctant to go for it, though performance-wise, Checkmarx can compete with other products.
What other advice do I have?
My company is in the service business, so it provides services to customers. For example, the customer uses SonarQube, so my company uses the same tool to execute vulnerability assessments.
I've worked on Checkmarx, NetSuite, Acunetix, and other application security tools used by customers.
My rating for Checkmarx is eight out of ten because it's a good product, and its only con is the cost, which is high for some customers.
I recommend Checkmarx to others because of its performance. The tool has better intelligent outcomes, and Checkmarx has better automation internally.
My company is a Checkmarx customer.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Engineer at a tech vendor with 10,001+ employees
Useful automation , detailed reports, but scalability could improve
Pros and Cons
- "The most valuable features of Checkmarx are the automation and information that it provides in the reports."
- "Checkmarx needs to be more scalable for large enterprise companies."
- "The stability of Checkmarx could improve. We're having issues with it, and the scan reliability is sometimes impacted so we sometimes have to restart the services to allow scans out of the queue."
What is our primary use case?
We use Checkmarx as a code analysis tool.
How has it helped my organization?
We have always used some kind of code analysis tool and Checkmarx has been working for us at this time. We like the tool.
What is most valuable?
The most valuable feature of Checkmarx are the automation and information that it provides in the reports.
For how long have I used the solution?
I am using Checkmarx for approximately two years.
What do I think about the stability of the solution?
The stability of Checkmarx could improve. We're having issues with it, but we don't want to upgrade to the newest version until we make sure that the issues we're having now aren't present in the newer version.
The scan reliability sometimes is impacted and we sometimes have to restart the services to allow scans out of the queue.
What do I think about the scalability of the solution?
Checkmarx needs to be more scalable for large enterprise companies.
How are customer service and support?
I have used the support from Checkmarx.
I rate the support from Checkmarx a seven out of ten.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
I was previously using Fortify but they were antiquated. They were not updating the solution on a regular basis.
How was the initial setup?
The initial setup of Checkmarx is straightforward. The implementation of Checkmarx does not take long because we have a process for it.
What about the implementation team?
We have four people that maintain Checkmarx in our company. We have professional services but I did most of the deployment myself.
What other advice do I have?
My advice to others is that Checkmarx is good compared to the other tools. However, they are all comparable, it depends on what languages they want to scan. Overall, Checkmarx is a decent solution. It would be a good idea to test other solutions.
I rate Checkmarx
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Chief Executive Officer at Ethnos ITSolutions
Integrates well, overall good functionality, and highly reliable
Pros and Cons
- "The most valuable features of Checkmarx are difficult to pinpoint because of the way the functionalities and the features are intertwined, it's difficult to say which part of them I prefer most. You initiate the scan, you have a scan, you have the review set, and reporting, they all work together as one whole process. It's not like accounting software, where you have the different features, et cetera."
- "Providing the scanning ability that shows the errors at the source code level is critical to have effective development of any critical application."
- "Checkmarx could improve by reducing the price."
What is our primary use case?
Checkmarx is a source code application for development, which means from the source code level, you can use Checkmarx to detect your coding errors, and to detect vulnerabilities that could have come from the different tools that you were using to develop your application. At the source code level, you can prevent the weaknesses that the application can carry on the journey of its development and use.
Checkmarx helps the users to have a secure coding environment and experience, and a secure source code level of application. That main application can leverage or improve the service delivery to customers.
What is most valuable?
The most valuable features of Checkmarx are difficult to pinpoint because of the way the functionalities and the features are intertwined, it's difficult to say which part of them I prefer most. You initiate the scan, you have a scan, you have the review set, and reporting, they all work together as one whole process. It's not like accounting software, where you have the different features, et cetera.
The software languages that they support are one of the largest in the market.
What needs improvement?
Checkmarx could improve by reducing the price.
For how long have I used the solution?
I have been using Checkmarx within the past 12 months.
What do I think about the stability of the solution?
Checkmarx has been stable in my usage and I'm confident to recommend it to anybody.
What do I think about the scalability of the solution?
Checkmarx is very scalable. It can run for a small and large organizations.
How are customer service and support?
The technical support is good.
I rate the support from Checkmarx a four out of five.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup of Checkmarx is easy.
I rate the initial setup of Checkmarx a four out of five.
What about the implementation team?
We use one engineer with the help of Checkmarx for support and deployment.
What's my experience with pricing, setup cost, and licensing?
The price of Checkmarx could be reduced to match their competitors, it is expensive.
What other advice do I have?
I strongly recommend Checkmarx to others. I have sold the solution for nearly eight years, and I'm not aware of any major complaints that the users have that could not be resolved.
I rate Checkmarx an eight out of ten.
The Checkmarx application is a live wire of technology delivery, and if your application is vulnerable, then the asset that your acquisition will run will also suffer vulnerability. Providing the scanning ability that shows the errors at the source code level is critical to have effective development of any critical application.
I would recommend Checkmarx eight because it's very critical and integral to the improvement of technology and cyber security today. It's a critical tool in protecting cyberspace, your asset in cyberspace, and an application that runs nearly all human life today. Everything is driven by technology and application.
Disclosure: My company has a business relationship with this vendor other than being a customer.
Techincal Lead of Developers at a government with 10,001+ employees
Intuitive, with good dashboards and metrics but needs more third-party integration
Pros and Cons
- "The most valuable feature is that it actually identifies the different criteria you can set to meet whatever standards you're trying to get your system accredited for."
- "Checkmarx could be improved with more integration with third-party software."
- "Checkmarx isn't accredited by the US government for DOD networks, so we've been forced to remove it from the network."
What is our primary use case?
We mainly use Checkmarx for accreditation, checking for vulnerabilities, and identifying areas in the code to fix some of the NIST 800 security controls.
What is most valuable?
The most valuable feature is that it actually identifies the different criteria you can set to meet whatever standards you're trying to get your system accredited for. It's also pretty intuitive and has a lot of good dashboards and metrics.
What needs improvement?
Checkmarx could be improved with more integration with third-party software.
For how long have I used the solution?
I've been using Checkmarx for about six months.
What do I think about the stability of the solution?
We've had no issues with Checkmarx's stability.
What do I think about the scalability of the solution?
I thought Checkmarx was pretty scalable.
How are customer service and support?
My experience with Checkmarx's technical support has been very positive.
How would you rate customer service and support?
Positive
How was the initial setup?
I found the setup pretty straightforward, though it took several days because the system engineers had to go through some different configuration settings to get it done.
What about the implementation team?
We worked with Checkmarx when we ran into issues, and they were pretty responsive.
What other advice do I have?
Checkmarx isn't accredited by the US government for DOD networks, so we've been forced to remove it from the network. I'd rate Checkmarx as seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Checkmarx One Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2026
Product Categories
Application Security Tools Static Application Security Testing (SAST) Vulnerability Management Container Security Static Code Analysis API Security Dynamic Application Security Testing (DAST) DevSecOps Risk-Based Vulnerability Management Application Security Posture Management (ASPM) AI SecurityPopular Comparisons
SonarQube
SentinelOne Singularity Cloud Security
Microsoft Defender for Cloud
Prisma Cloud by Palo Alto Networks
GitLab
Veracode
Tanium
Qualys VMDR
Imperva Application Security Platform
TrendAI Vision One – Cloud Security
Orca Security
CrowdStrike Falcon Cloud Security
Tenable Nessus
Buyer's Guide
Download our free Checkmarx One Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What is the biggest difference between Veracode and Checkmarx?
- Checkmarx or Veracode. Which should we choose?
- What is the Biggest Difference Between Checkmarx and Fortify?
- What is the biggest difference between Checkmarx and SonarQube?
- Checkmarx vs SonarQube; SonarQube interoperability with Checkmarx or Veracode
- If you had to both encrypt and compress data during transmission, which would you do first and why?
- When evaluating Application Security, what aspect do you think is the most important to look for?
- What are the threats associated with using ‘bogus’ cybersecurity tools?
- What are the Top 5 cybersecurity trends in 2022?
- Which application security solutions include both vulnerability scans and quality checks?























