No more typing reviews! Try our Samantha, our new voice AI agent.
reviewer1711191 - PeerSpot reviewer
Cybersecurity at a transportation company with 1,001-5,000 employees
Real User
May 3, 2022
No need to compile the code to execute static code analysis, but should be more container-friendly and optimized for the CI pipeline
Pros and Cons
  • "I like that you don't have to compile the code in order to execute static code analysis. So, it's very handy."
  • "They should make it more container-friendly and optimized for the CI pipeline. They should make it a little less heavy. Right now, it requires a SQL database, and the way the tool works is that it has an engine and then it has an analysis database in which it stores the information. So, it is pretty heavy from that perspective because you have to have a full SQL Server. They're working on something called Checkmarx Light, which is a slim-down version. They haven't released it yet, but that's what we need. There should be something a little more slimmed down that can just run the analysis and output the results in a format that's readable as opposed to having a full, really big, and thick deployment with a full database server."
  • "They should make it more container-friendly and optimized for the CI pipeline. They should make it a little less heavy."

What is our primary use case?

I am using it for software assurance focused on security. I am using its latest version.

How has it helped my organization?

I use both the static code analysis and the open-source analysis engine. It gives visibility into weaknesses and the software that may be there in the source code and static analysis. It also gives some insights into the open source vulnerabilities that may be there in the codebase.

What is most valuable?

I like that you don't have to compile the code in order to execute static code analysis. So, it's very handy. Typically when using SCA tools on C/C++ and C# you must compile the software for SCA to work. CX doesn’t require any compilation due to the way the tool does synthetic compilation to help find errors in code. Many times 3rd party assurance providers don’t have all the files to compile so CX comes in handy. 

What needs improvement?

They should make it more container-friendly and optimized for the CI pipeline. They should make it a little less heavy. Right now, it requires a SQL database, and the way the tool works is that it has an engine and then it has an analysis database in which it stores the information. So, it is pretty heavy from that perspective because you have to have a full SQL Server. They're working on something called Checkmarx Light, which is a slim-down version. They haven't released it yet, but that's what we need. There should be something a little more slimmed down that can just run the analysis and output the results in a format that's readable as opposed to having a full, really big, and thick deployment with a full database server.

I had several issues with the installation. It should just work out of the box.

Buyer's Guide
Checkmarx One
August 2026
Learn what your peers think about Checkmarx One. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
908,834 professionals have used our research since 2012.

For how long have I used the solution?

I have been using it off and on for about a year.

What do I think about the stability of the solution?

I've run into a few bugs here and there but i would recommend installing on virtual machine and snapshoting a working install. 

What do I think about the scalability of the solution?

My setup is standalone. They do have a scalable version, but it's not something I need.

We're not using it a lot. Its usage is once a month. The way our organization works is that we don't do static code analysis every day. It's more on an as-needed basis. So, it's no fault of the Checkmarx tool. It's just not something that we've been working on.

How are customer service and support?

They were pretty good. I would rate them a four out of five, but I was using their salespeople. It wasn't their traditional tech support, so I can't really evaluate their traditional tech support. When they're selling something, they give you a lot more service instead of having to go through the support system.

Which solution did I use previously and why did I switch?

I still use other tools, so I just added it to the tool chest. I have Fortify, CodeSonar, etc  and I added Checkmarx as a different tool.

How was the initial setup?

I installed it. It's straightforward to install, but I had several issues with the installation. I don't know if it was with my environment or not. If it works properly, it's a simple install, but in my example, it did not work right off the bat. There was some troubleshooting that had to go on, which was a little frustrating.

It took weeks. It required back and forth communication with support for a couple of days, but I wasn't actively working on it for days. I would run into a bug, send the log file, and go back and forth. It wasn't anything crazy, but it was a little frustrating. It should just work out of the box. It should be pretty straightforward where you just click the installer and go, but it wasn't.

What about the implementation team?

It was implemented in-house, and then I had to call support when needed.

In terms of maintenance, it is pretty self-sustaining. You update it whenever it needs to be updated.

What was our ROI?

There hasn't been much return yet because we haven't used it much, but I have enough faith in it that I committed to it for multiple years. We are starting to use it more but not enough to state ROI yet

What other advice do I have?

I would rate it a seven out of ten. It's not the best tool on the market, but it provides some good capability for what it is.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Evgen Gulak - PeerSpot reviewer
Head of IT Security Department at a energy/utilities company with 5,001-10,000 employees
Real User
Jan 16, 2022
Many false positives and inaccurate information, but scalable
Pros and Cons
  • "The solution is scalable, but other solutions are better."
  • "We are using Checkmarx for analyzing threats."
  • "Checkmarx needs to improve the false positives and provide more accuracy in identifying vulnerabilities. It misses important vulnerabilities."
  • "The purchase of this solution was a mistake. I would advise others to deploy the solution and to test all of the functionality before buying and do not trust the marketing from Checkmarx."

What is our primary use case?

We are using Checkmarx for analyzing threats.

We are not using the latest version of Checkmarx because we faced some issues.

What needs improvement?

Checkmarx needs to improve the false positives and provide more accuracy in identifying vulnerabilities. It misses important vulnerabilities.

SonarCube functions better in these areas.

For how long have I used the solution?

I have used Checkmarx within the last 24 months.

What do I think about the stability of the solution?

The stability of Checkmarx could improve.

I would rate the stability of Checkmarx a six out of ten.

What do I think about the scalability of the solution?

The solution is scalable, but other solutions are better.

We have 20 developers using this solution. We have a few projects left to use this solution and then we will move to something else next year.

How are customer service and support?

The support could improve, it takes a long time for a response. The service we received was poor.

Which solution did I use previously and why did I switch?

I am using Checkmarx in parallel with SonarQube.

How was the initial setup?

We didn't like how long they took to implement the product. The installation was not intuitive. We were constantly having meetings and installation additional things.

The implementation process should improve.

What about the implementation team?

We were helped by both the local partner and the vendor for the implementation.

We have two developers for the maintenance and support of Checkmarx.

What's my experience with pricing, setup cost, and licensing?

We're using a commercial version of Checkmarx, and we paid for the solution for two years. The price is high and could be reduced.

The local distributor charges two times higher than in other countries.

What other advice do I have?

The purchase of this solution was a mistake.

I would advise others to deploy the solution and to test all of the functionality before buying and do not trust the marketing from Checkmarx.

I rate Checkmarx a four out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Checkmarx One
August 2026
Learn what your peers think about Checkmarx One. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
908,834 professionals have used our research since 2012.
Oscar Cardozo - PeerSpot reviewer
Arquitecto de soluciones at Tsoft
Real User
Jun 10, 2024
Has GPT and Copilot integration, and UI is easy to navigate
Pros and Cons
  • "The tool's valuable features include integrating GPT and Copilot. Additionally, the UI web representation is very user-friendly, making navigation easy. GPT has made several improvements to my security code."
  • "I can't create a business case with multiple-factor authentication."

What is our primary use case?

I use the tool for testing purposes. 

What is most valuable?

The tool's valuable features include integrating GPT and Copilot. Additionally, the UI web representation is very user-friendly, making navigation easy. GPT has made several improvements to my security code.

What needs improvement?

I can't create a business case with multiple-factor authentication.

For how long have I used the solution?

I have been working with the product for two years. 

How are customer service and support?

While support handles tickets and resolves specific issues, such as business cases, it can be frustrating waiting for responses. They often take a lot of time to address cases or provide resolutions.

How would you rate customer service and support?

Neutral

How was the initial setup?

Checkmarx One's deployment is easy. When we deployed it for a new client, it took around a month to complete. This involved setting up all parameters and sub-administrators. Additionally, finalizing the project involved several tasks, such as scanning with all security gates.

What was our ROI?

We can get a return in six months. 

What's my experience with pricing, setup cost, and licensing?

The tool's pricing is fine. 

What other advice do I have?

I rate the overall product an eight out of ten. 

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Java Developer at a security firm with 51-200 employees
Real User
Nov 3, 2023
Has a valuable static code analysis feature and a simple setup process
Pros and Cons
  • "The product's most valuable feature is static code and supply chain effect analysis. It provides a lot of visibility."
  • "The product's reporting feature could be better. The feature works well for developers, but reports generated to be shared with external parties are poor, it lacks the details one gets when viewing the results directly from the Checkmarx One platform."

What is our primary use case?

We use the product for static code analysis, supply chain, and container security.

What is most valuable?

The product's most valuable feature is static code and supply chain effect analysis. It provides a lot of visibility.

What needs improvement?

The product's reporting feature could be better. The feature works well for developers, but reports generated to be shared with external parties are poor, it lacks the details one gets when viewing the results directly from the Checkmarx One platform.

For how long have I used the solution?

We have been using Checkmarx's on-premise version for four years. We switched to the cloud version recently.

What do I think about the stability of the solution?

I rate the product's stability a nine or ten out of ten.

What do I think about the scalability of the solution?

We have 40 Checkmarx users in our organization. I rate its scalability a nine out of ten.

How are customer service and support?

The technical support team promptly addresses the issues.

How was the initial setup?

The initial setup process is easy.

What other advice do I have?

I rate Checkmarx an eight out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
reviewer1534434 - PeerSpot reviewer
System Engineer at a tech vendor with 10,001+ employees
Real User
Apr 26, 2023
Easy to use, configurable, and has all the features we need
Pros and Cons
  • "It has all the features we need."
  • "The validation process needs to be sped up."

What is our primary use case?

We use the solution on a developing project. Before we bring the code to production, we have to ensure its quality, and we use this solution. 

What is most valuable?

It's easy to use. The configuration is easy. 

It has all the features we need. 

What needs improvement?

We haven't had any issues with the solution so far. It is not missing any features. 

It takes too much time to check the code. The validation process needs to be sped up. 

There have been some configuration issues. We sometimes have failures. 

For how long have I used the solution?

I've been using the solution for two and a half years at this point. 

What do I think about the stability of the solution?

We've had to deal with errors. When we blacklist or whitelist, we do have some issues. There are a few configuration issues. I'd rate the stability seven out of ten. It could be improved. 

What do I think about the scalability of the solution?

I can't speak to the scalability. I don't deal with scaling. The usage is limited. We aren't attempting to expand it. We only do two to three processes at the same time. 

How are customer service and support?

Technical support is okay. We are mostly happy with the help we get. We can directly connect with them.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

I'm also using SonarQube.

How was the initial setup?

I did not handle the deployment directly. We have a team that manages the tool. I'm not aware of how many people are needed to maintain and deploy the solution. 

What's my experience with pricing, setup cost, and licensing?

I don't deal with the pricing directly. I don't know the exact cost. 

What other advice do I have?

I'm a customer and end-user.

I would recommend the solution to other users. I'd rate the solution eight out of ten. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Peter Ejiofor - PeerSpot reviewer
Chief Executive Officer at Ethnos ITSolutions
Reseller
Jun 20, 2022
Integrates well, overall good functionality, and highly reliable
Pros and Cons
  • "The most valuable features of Checkmarx are difficult to pinpoint because of the way the functionalities and the features are intertwined, it's difficult to say which part of them I prefer most. You initiate the scan, you have a scan, you have the review set, and reporting, they all work together as one whole process. It's not like accounting software, where you have the different features, et cetera."
  • "Providing the scanning ability that shows the errors at the source code level is critical to have effective development of any critical application."
  • "Checkmarx could improve by reducing the price."

What is our primary use case?

Checkmarx is a source code application for development, which means from the source code level, you can use Checkmarx to detect your coding errors, and to detect vulnerabilities that could have come from the different tools that you were using to develop your application. At the source code level, you can prevent the weaknesses that the application can carry on the journey of its development and use.  

Checkmarx helps the users to have a secure coding environment and experience, and a secure source code level of application. That main application can leverage or improve the service delivery to customers.

What is most valuable?

The most valuable features of Checkmarx are difficult to pinpoint because of the way the functionalities and the features are intertwined, it's difficult to say which part of them I prefer most. You initiate the scan, you have a scan, you have the review set, and reporting, they all work together as one whole process. It's not like accounting software, where you have the different features, et cetera. 

The software languages that they support are one of the largest in the market.

What needs improvement?

Checkmarx could improve by reducing the price.

For how long have I used the solution?

I have been using Checkmarx within the past 12 months.

What do I think about the stability of the solution?

Checkmarx has been stable in my usage and I'm confident to recommend it to anybody.

What do I think about the scalability of the solution?

Checkmarx is very scalable. It can run for a small and large organizations.

How are customer service and support?

The technical support is good.

I rate the support from Checkmarx a four out of five.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup of Checkmarx is easy.

I rate the initial setup of Checkmarx a four out of five.

What about the implementation team?

We use one engineer with the help of Checkmarx for support and deployment.

What's my experience with pricing, setup cost, and licensing?

The price of Checkmarx could be reduced to match their competitors, it is expensive.

What other advice do I have?

I strongly recommend Checkmarx to others. I have sold the solution for nearly eight years, and I'm not aware of any major complaints that the users have that could not be resolved.

I rate Checkmarx an eight out of ten.

The Checkmarx application is a live wire of technology delivery, and if your application is vulnerable, then the asset that your acquisition will run will also suffer vulnerability. Providing the scanning ability that shows the errors at the source code level is critical to have effective development of any critical application.

I would recommend Checkmarx eight because it's very critical and integral to the improvement of technology and cyber security today. It's a critical tool in protecting cyberspace, your asset in cyberspace, and an application that runs nearly all human life today. Everything is driven by technology and application.

Disclosure: My company has a business relationship with this vendor other than being a customer.
PeerSpot user
Le Viet - PeerSpot reviewer
Security Consultant at VNCS
Real User
Jun 2, 2022
Minimal configuration, simple setup, and useful user interface
Pros and Cons
  • "The most valuable feature of Checkmarx is the user interface, it is very easy to use, and we do not need to configure anything, we only have to scan to see the results."
  • "Checkmarx could improve the speed of the scans."

What is our primary use case?

Checkmarx is used for application security, we can detect the stability and other details on how to fix issues.

What is most valuable?

The most valuable feature of Checkmarx is the user interface, it is very easy to use. We do not need to configure anything, we only have to scan to see the results.

What needs improvement?

Checkmarx could improve the speed of the scans.

For how long have I used the solution?

I have been using Checkmarx for approximately half a year.

What do I think about the scalability of the solution?

We have five people in our company that uses Checkmarx, we do not plan to increase usage.

How are customer service and support?

I have used the support from Checkmarx.

Which solution did I use previously and why did I switch?

I have not used another before Checkmarx.

How was the initial setup?

The initial setup of Checkmarx was very easy. The process took approximately one hour. We only need to provide information.

What about the implementation team?

We have five people that are supporting Checkmarx in our company.

What other advice do I have?

This solution is one of the easiest solutions I have used. We have professional services set it up for us but the scans are not enough for us.

I rate Checkmarx an eight out of ten.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1108275 - PeerSpot reviewer
Security at a tech services company with 51-200 employees
Real User
Feb 11, 2022
Gives good results, but can be more user-friendly
Pros and Cons
  • "Apart from software scanning, software composition scanning is valuable."
  • "In my opinion, Checkmarx gives better results, and its protection is better than SonarQube."
  • "Its user interface could be improved and made more friendly."

What is our primary use case?

We use it for code scanning and security testing for our in-house application development. We are using its latest version.

What is most valuable?

Apart from software scanning, software composition scanning is valuable.

What needs improvement?

Its user interface could be improved and made more friendly. 

When we change a window, the session times out, and we have to log in again. It can be improved from this aspect.

For how long have I used the solution?

I have been using this solution for about one year.

What do I think about the stability of the solution?

It has been stable during our work.

What do I think about the scalability of the solution?

We don't have so many applications. So, I have no idea about its scalability. It is enough for our work at the moment, and we have not had any problem with its scalability.

In our team, we have about 10 users.

How are customer service and support?

We are just users of this solution. There is another team that interacts with them. They get technical support from the vendor on this. 

Which solution did I use previously and why did I switch?

In my previous company, I used SonarQube. In my opinion, Checkmarx gives better results, and its protection is better than SonarQube.

How was the initial setup?

Another team takes care of its deployment. We are just users. We just log into the server and use it for scanning.

What other advice do I have?

It has been working well. I would rate it a seven out of 10.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer932058 - PeerSpot reviewer
A VP, A Paa S Engineer at a tech vendor with 10,001+ employees
Real User
Jan 10, 2022
Reasonably price, high performance, and simple installation
Pros and Cons
  • "The solution has good performance, it is able to compute in 10 to 15 minutes."
  • "Checkmarx could improve the REST APIs by including automation."

What is our primary use case?

We are using Checkmarx for application code scanning, such as scanning for different leverages in the application code.

What is most valuable?

The solution has good performance, it is able to compute in 10 to 15 minutes. 

What needs improvement?

Checkmarx could improve the REST APIs by including automation.

For how long have I used the solution?

I have been using Checkmarx for approximately one year.

What do I think about the stability of the solution?

Checkmarx is stable.

What do I think about the scalability of the solution?

The scalability of Checkmarx is good, we can onboard easily.

We have approximately 200 people in my organization using this solution.

How are customer service and support?

I have not contacted technical support. We have not required it.

Which solution did I use previously and why did I switch?

I have used SonarQube previously.

How was the initial setup?

The installation is straightforward and takes approximately 40 minutes.

What about the implementation team?

I am able to do the implementation myself.

We have administrators and engineers that support and maintain the solution.

What's my experience with pricing, setup cost, and licensing?

We have purchased an annual license to use this solution. The price is reasonable.

What other advice do I have?

I rate Checkmarx a nine out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1646475 - PeerSpot reviewer
Senior Cybersecurity Solution Architect at a computer software company with 51-200 employees
Real User
Oct 17, 2021
Integrates well with other security solutions
Pros and Cons
  • "It can integrate very well with DAST solutions. So both of them are combined into an integrated solution for customers running application security."
  • "I expect application security vendors to cover all aspects of application security, including SAST, DAST, and even mobile application security testing. And it would be much better if they provided an on-premises and cloud option for all these main application security features."

What is our primary use case?

Checkmarx is used only for static application security testing (SAST), and it can integrate very well with DAST solutions. So both of them are combined into an integrated solution for customers running application security.

What needs improvement?

I expect application security vendors to cover all aspects of application security, including SAST, DAST, and even mobile application security testing. And it would be much better if they provided an on-premises and cloud option for all these main application security features. So most of my customers would love to have consolidated vendors who cover all application security to lower operational overhead.

For how long have I used the solution?

I'm a solution architect, not an end-user. I'm selling Checkmarx. This is the first year I've done business with Checkmarx. In the past five years, I worked a lot with Fortify and Micro Focus. I currently have two customers running Checkmarx, and one more is evaluating the product.

How was the initial setup?

Setting up Checkmarx should be relatively straightforward. It takes a little more time for the DevOps team to enable everything, but overall deployment should take less than a week, including preparation and implementation. 

What's my experience with pricing, setup cost, and licensing?

Most of my customers opted for a perpetual license. They prefer to pay the highest amount upfront for the perpetual license and then pay for additional support annually.

What other advice do I have?

I rate Checkmarx eight out of 10. Until I get more extensive feedback from clients, I would rate it an eight.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Buyer's Guide
Download our free Checkmarx One Report and get advice and tips from experienced pros sharing their opinions.
Updated: August 2026
Buyer's Guide
Download our free Checkmarx One Report and get advice and tips from experienced pros sharing their opinions.