We use Checkmarx for security vulnerability identification. We are using its latest version. We have a license to upgrade to the latest version. Whenever there is a new version, we update it to the latest version.
Senior Manager at a manufacturing company with 10,001+ employees
A stable solution for identifying security vulnerabilities but needs functionalities for identifying the run-time null values and doing static and dynamic code validation
Pros and Cons
- "The identification of verification-related security vulnerabilities is really important and one of the key things. It also identifies vulnerabilities for any kind of third-party tool coming into the system or any third-party tools that you are using, which is very useful for avoiding random hacking."
- "We are trying to find out if there is a way to identify the run-time null values. I am analyzing different tools to check if there is any tool that supports run-time null value identification, but I don't think any of the tools in the market currently supports this feature. It would be helpful if Checkmarx can identify and throw an exception for a null value at the run time. It would make things a lot easier if there is a way for Checkmarx to identify nullable fields or hard-coded values in the code. The accessibility for customized Checkmarx rules is currently limited and should be improved. In addition, it would be great if Checkmarx can do static code and dynamic code validation. It does a lot of security-related scanning, and it should also do static code and dynamic code validation. Currently, for security-related validation, we are using Checkmarx, and for static code and dynamic code validation, we are using some other tools. We are spending money on different tools. We can pay a little extra money and use Checkmarx for everything."
What is our primary use case?
What is most valuable?
The identification of verification-related security vulnerabilities is really important and one of the key things. It also identifies vulnerabilities for any kind of third-party tool coming into the system or any third-party tools that you are using, which is very useful for avoiding random hacking.
What needs improvement?
We are trying to find out if there is a way to identify the run-time null values. I am analyzing different tools to check if there is any tool that supports run-time null value identification, but I don't think any of the tools in the market currently supports this feature. It would be helpful if Checkmarx can identify and throw an exception for a null value at the run time. It would make things a lot easier if there is a way for Checkmarx to identify nullable fields or hard-coded values in the code.
The accessibility for customized Checkmarx rules is currently limited and should be improved. In addition, it would be great if Checkmarx can do static code and dynamic code validation. It does a lot of security-related scanning, and it should also do static code and dynamic code validation. Currently, for security-related validation, we are using Checkmarx, and for static code and dynamic code validation, we are using some other tools. We are spending money on different tools. We can pay a little extra money and use Checkmarx for everything.
For how long have I used the solution?
I have been using this solution for two years.
Buyer's Guide
Checkmarx One
May 2025

Learn what your peers think about Checkmarx One. Get advice and tips from experienced pros sharing their opinions. Updated: May 2025.
851,823 professionals have used our research since 2012.
What do I think about the stability of the solution?
Its stability is okay.
How are customer service and support?
We don't directly deal with the Checkmarx technical team. There is a support group available for that, and they work with the Checkmarx team. When we have any issues, we directly call our internal team, and they call the Checkmarx team. They get back to us pretty quickly. The response is very quick. There is no problem.
How was the initial setup?
The initial setup was easy. Our project was quite big, and it took a bit longer. It took almost six hours. We could not do it as CI/CD pipeline because the pipeline expects a response in a short span of time, which was a challenge for us. We are now doing the Checkmarx review manually. We first run the code analysis, and, after the code analysis is over, we go for the pipeline. This is an overhead for us.
It would be helpful if they can improve the speed of the analysis rate. We also need to find out from our side if there is a way to increase the wait time of the CI/CD pipeline and modify the timeout limit. It would then take 30 minutes to one hour rather than five or six hours. We should be able to adjust the timeout time, change the CI/CD settings, and go ahead with the integrated process. Currently, we cannot have an integrated system, and we also have to move from one script to the next script manually.
What other advice do I have?
Even though we run it manually, it captures most of the things. We decided to go with Checkmarx two years ago, and we are continuing with it.
I would rate Checkmarx a seven out of ten. There are a few things that can be improved in this solution.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Sr. Security Engineer at SugarCRM
Security testing solution with vulnerability details and planned blackout times.
Pros and Cons
- "Vulnerability details is valuable."
- "Implementing a blackout time for any user or teams: Needs improvement."
How has it helped my organization?
- Put the vulnerability details area on the right side of the application or it may be changeable
- Save and reset screen configuration
What is most valuable?
Vulnerability details part.
What needs improvement?
- Vulnerability details: Reduce false positive results and improve it by providing more details how I can resolve the vulnerability.
- Implementing a blackout time for any user or teams: Needs improvement. I need to place limits for some users or teams within a specific time frame. For example, between 02:00 to 06:00. They can't start any scanning during that time, even if they have scanner privileges.
What do I think about the stability of the solution?
In the latest version, the session logout doesn't work properly.
What do I think about the scalability of the solution?
We have two engine licenses, but we can't scan two projects at the same time.
How are customer service and technical support?
I would give technical support a rating of 9/10.
Which solution did I use previously and why did I switch?
We were using Fortify. Its software capability was limited in terms of mobile code scanning.
How was the initial setup?
The initial setup was very easy.
What's my experience with pricing, setup cost, and licensing?
We don't have any specific advice about these issues.
Which other solutions did I evaluate?
We evaluated Fortify and AppScan.
What other advice do I have?
I don't like the latest license update. I can't set a limit for the reviewer account.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Checkmarx One
May 2025

Learn what your peers think about Checkmarx One. Get advice and tips from experienced pros sharing their opinions. Updated: May 2025.
851,823 professionals have used our research since 2012.
Arquitecto de soluciones at Tsoft
Has GPT and Copilot integration, and UI is easy to navigate
Pros and Cons
- "The tool's valuable features include integrating GPT and Copilot. Additionally, the UI web representation is very user-friendly, making navigation easy. GPT has made several improvements to my security code."
- "I can't create a business case with multiple-factor authentication."
What is our primary use case?
I use the tool for testing purposes.
What is most valuable?
The tool's valuable features include integrating GPT and Copilot. Additionally, the UI web representation is very user-friendly, making navigation easy. GPT has made several improvements to my security code.
What needs improvement?
I can't create a business case with multiple-factor authentication.
For how long have I used the solution?
I have been working with the product for two years.
How are customer service and support?
While support handles tickets and resolves specific issues, such as business cases, it can be frustrating waiting for responses. They often take a lot of time to address cases or provide resolutions.
How would you rate customer service and support?
Neutral
How was the initial setup?
Checkmarx One's deployment is easy. When we deployed it for a new client, it took around a month to complete. This involved setting up all parameters and sub-administrators. Additionally, finalizing the project involved several tasks, such as scanning with all security gates.
What was our ROI?
We can get a return in six months.
What's my experience with pricing, setup cost, and licensing?
The tool's pricing is fine.
What other advice do I have?
I rate the overall product an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Vice President Of Technology at a computer software company with 5,001-10,000 employees
Good reporting, performance, and coverage for different languages
Pros and Cons
- "The most valuable feature is the application tracking reporting."
- "The cost per user is high and should be reduced."
What is our primary use case?
We primarily use Checkmarx for application security and tracking.
What is most valuable?
The most valuable feature is the application tracking reporting.
From the user's perspective, the interface is pretty good. It will point out the exact line of code when an issue is found.
It is good in terms of coverage for different languages.
It is updated automatically so there is less maintenance.
What needs improvement?
The cost per user is high and should be reduced. Five years ago, it was a user-based model, which was significantly better. It would be great if we could distribute the cost equally between projects.
For how long have I used the solution?
I have been working with Checkmarx for about two years.
What do I think about the stability of the solution?
This is a stable product.
What do I think about the scalability of the solution?
It is scalable in terms of being able to run multiple instances for different products. We have approximately 10 users, which is the size of our application security team.
I would like to increase our usage of this product, but it will ultimately depend on the company's strategy.
How are customer service and technical support?
Given the stability of Checmarx, it doesn't require a lot of communication with technical support. That said, we have been in touch with them for non-technical issues and they have a good team with a lot of Russian speakers.
Which solution did I use previously and why did I switch?
Prior to using Checkmarx, I used AppScan but the concept is completely different. With Checkmarx, you are working with source code, whereas as with AppScan, you are working with binaries. You can say that AppScan is more like a dynamic security scan and Checkmarx is more static.
These products are quite different in terms of how you do the testing. Checkmarx is better from both a performance perspective and reporting a lower number of false positives.
How was the initial setup?
We did not have any trouble with the initial setup. Our deployment was done within a couple of hours. The easiest thing to do is create a virtual machine and deploy it.
What about the implementation team?
Our in-house IT staff was responsible for the implementation.
What's my experience with pricing, setup cost, and licensing?
The number of users and coverage for languages will have an impact on the cost of the license. We would like to deploy it for the whole company but it's a question of spending thousands of dollars. Investing $200,000 or $300,000 would be an upper management decision.
The educational component is additional and costs approximately $100 per month for each user. This is too high so we did not agree to the service.
What other advice do I have?
Overall, we are very satisfied with Checkmarx and it is a product that I recommend.
I would rate this solution an eight out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Founder at a tech company with 51-200 employees
It can scan precompiled (source) code, as well as compiled (binary) code.
Pros and Cons
- "The process of remediating software security vulnerabilities can now be performed (ongoing) as portions of the application are being built in advance of being compiled."
- "The product can be improved by continuing to expand the application languages and frameworks that can be scanned for vulnerabilities. This includes expanded coverage for mobile applications as well as open-source development tools."
How has it helped my organization?
The process of remediating software security vulnerabilities can now be performed (ongoing) as portions of the application are being built in advance of being compiled. Among other benefits, this reduces the cost to fix the problem(s) as the fix can occur earlier in the SDLC.
What is most valuable?
The ability to identify a vulnerability, the optimal place for remediation and the correct syntax is very valuable. This feature helps ensure that the software fix is comprehensive and effective. The CxSuite is easy to use and because it provides the correct coding syntax to address a vulnerability, it helps improve the secure coding skill set among developers. The product can scan precompiled (source) code, as well as compiled (binary) code, delivering effectiveness and efficiency throughout the SDLC.
What needs improvement?
The product can be improved by continuing to expand the application languages and frameworks that can be scanned for vulnerabilities. This includes expanded coverage for mobile applications as well as open-source development tools.
The Checkmarx CxSuite covers a wide range of programming languages including many of the most popular languages used by developers today. As matter of general improvement, expanding coverage to languages (emerging, legacy) and open source frameworks will increase the overall effectiveness of product.
*2017 Update. A number of leading Open Source Frameworks are now supported.
What do I think about the stability of the solution?
The product is stable.
What do I think about the scalability of the solution?
The product scales well.
How are customer service and technical support?
The technical support is high quality. The support team is well versed in how best to configure, implement and operate the product.
Which solution did I use previously and why did I switch?
I did not previously use a different solution.
How was the initial setup?
The initial set up is straightforward. The product requires a fairly simple computing environment for operation.
What's my experience with pricing, setup cost, and licensing?
The product licensing offers the flexibility to cover a wide range of environments. The pricing is competitive and provides a lower TCO (total cost of ownership) for achieving application security.
Which other solutions did I evaluate?
We considered several other commercial-grade application security solutions. The Checkmarx solution offers an ideal combination of code coverage, functionality, usability and TCO.
What other advice do I have?
The Checkmarx CxSuite product works well, delivers efficiency to the SDLC, and most important of all, it effectively improves application security.
It works!
Disclosure: My company has a business relationship with this vendor other than being a customer: My company is a Checkmarx Certified Partner.
Head of DevOps at Tpconnects technologies
A highly recommended tool for delivering secure products
Pros and Cons
- "Checkmarx has helped us deliver more secure products. We are able to do static code analysis with the tool before shipping our code to production. When the integration is in the pipeline, this tool gives us early notifications on code fixes."
- "I would like to see the tool’s pricing improved."
What is our primary use case?
We use the solution for SAST and DAST testing.
How has it helped my organization?
Checkmarx has helped us deliver more secure products. We are able to do static code analysis with the tool before shipping our code to production. When the integration is in the pipeline, this tool gives us early notifications on code fixes.
What is most valuable?
Checkmarx gives you an overview of all security aspects of the codes and shows what code aspects you need to be looking into.
What needs improvement?
I would like to see the tool’s pricing improved.
For how long have I used the solution?
I have been working with the solution for three years. At present, I am using the latest version.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
The solution is scalable. Around 50 developers in our organization are using it.
How was the initial setup?
The solution was easy to setup since it had proper documentation.
What about the implementation team?
The solution’s deployment was done by in-house members.
What was our ROI?
We got good ROI with the use of the solution. We have seen returns on PCI and other security aspects.
What's my experience with pricing, setup cost, and licensing?
I would rate the solution’s pricing an eight out of ten. The tool’s pricing is higher than others and it is for the license alone.
What other advice do I have?
I would rate the solution an eight out of ten since it fulfills most of the requirements. I recommend this tool to anyone who is willing to give it a try.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Chief Executive Officer at Ethnos ITSolutions
Integrates well, overall good functionality, and highly reliable
Pros and Cons
- "The most valuable features of Checkmarx are difficult to pinpoint because of the way the functionalities and the features are intertwined, it's difficult to say which part of them I prefer most. You initiate the scan, you have a scan, you have the review set, and reporting, they all work together as one whole process. It's not like accounting software, where you have the different features, et cetera."
- "Checkmarx could improve by reducing the price."
What is our primary use case?
Checkmarx is a source code application for development, which means from the source code level, you can use Checkmarx to detect your coding errors, and to detect vulnerabilities that could have come from the different tools that you were using to develop your application. At the source code level, you can prevent the weaknesses that the application can carry on the journey of its development and use.
Checkmarx helps the users to have a secure coding environment and experience, and a secure source code level of application. That main application can leverage or improve the service delivery to customers.
What is most valuable?
The most valuable features of Checkmarx are difficult to pinpoint because of the way the functionalities and the features are intertwined, it's difficult to say which part of them I prefer most. You initiate the scan, you have a scan, you have the review set, and reporting, they all work together as one whole process. It's not like accounting software, where you have the different features, et cetera.
The software languages that they support are one of the largest in the market.
What needs improvement?
Checkmarx could improve by reducing the price.
For how long have I used the solution?
I have been using Checkmarx within the past 12 months.
What do I think about the stability of the solution?
Checkmarx has been stable in my usage and I'm confident to recommend it to anybody.
What do I think about the scalability of the solution?
Checkmarx is very scalable. It can run for a small and large organizations.
How are customer service and support?
The technical support is good.
I rate the support from Checkmarx a four out of five.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup of Checkmarx is easy.
I rate the initial setup of Checkmarx a four out of five.
What about the implementation team?
We use one engineer with the help of Checkmarx for support and deployment.
What's my experience with pricing, setup cost, and licensing?
The price of Checkmarx could be reduced to match their competitors, it is expensive.
What other advice do I have?
I strongly recommend Checkmarx to others. I have sold the solution for nearly eight years, and I'm not aware of any major complaints that the users have that could not be resolved.
I rate Checkmarx an eight out of ten.
The Checkmarx application is a live wire of technology delivery, and if your application is vulnerable, then the asset that your acquisition will run will also suffer vulnerability. Providing the scanning ability that shows the errors at the source code level is critical to have effective development of any critical application.
I would recommend Checkmarx eight because it's very critical and integral to the improvement of technology and cyber security today. It's a critical tool in protecting cyberspace, your asset in cyberspace, and an application that runs nearly all human life today. Everything is driven by technology and application.
Disclosure: My company has a business relationship with this vendor other than being a customer:
Senior Software Security Analyst at a financial services firm with 1,001-5,000 employees
It scans code for security vulnerabilities without needing to compile first. It reports many false positives.
Pros and Cons
- "We were using HPE Security Fortify to scan code for security vulnerabilities, but it can scan only after a successful compile. If the code has dependencies or build errors, the scan fails. With Checkmarx, pre-compile scanning is seamless. This allows us to scan more code."
- "Checkmarx reports many false positives that we need to manually segregate and mark “Not exploitable”."
How has it helped my organization?
Checkmarx saves us a lot of time. We were using HPE Security Fortify to scan code for security vulnerabilities, but it can scan only after a successful compile. If the code has dependencies or build errors, the scan fails. With Checkmarx, pre-compile scanning is seamless. This allows us to scan more code.
What is most valuable?
The most valuable feature is that Checkmarx scans code for security vulnerabilities without needing to compile first.
What needs improvement?
Checkmarx reports many false positives that we need to manually segregate and mark “Not exploitable”.
What do I think about the stability of the solution?
We encountered stability issues when scanning large code blocks. It consumes a lot of memory, and at times, Checkmarx services freeze and don’t work properly.
What do I think about the scalability of the solution?
I don’t know of any scalability issues.
How are customer service and technical support?
Just four words for the technical support team: “Checkmarx team is awesome”.
Which solution did I use previously and why did I switch?
Before Checkmarx, we used HPE Security Fortify and IBM AppScan. We also tried several open-source scanning tools.
How was the initial setup?
Overall, the initial setup is easy. Checkmarx provides an installer binary and we just need go through the wizard for an express installation. If we need an advanced configuration, we contact the Checkmarx support team.
What's my experience with pricing, setup cost, and licensing?
I believe pricing is better compared to other commercial tools.
Which other solutions did I evaluate?
Yes, we compared Checkmarx features and benefits with IBM AppScan and HPE Security Fortify.
What other advice do I have?
Personally, I recommend Checkmarx for static analysis.
Disclosure: I am a real user, and this review is based on my own experience and opinions.

Buyer's Guide
Download our free Checkmarx One Report and get advice and tips from experienced pros
sharing their opinions.
Updated: May 2025
Product Categories
Application Security Tools Static Application Security Testing (SAST) Vulnerability Management Static Code Analysis API Security DevSecOps Risk-Based Vulnerability ManagementPopular Comparisons
SonarQube Server (formerly SonarQube)
GitLab
SentinelOne Singularity Cloud Security
Veracode
Coverity
Mend.io
OWASP Zap
CrowdStrike Falcon Cloud Security
SonarQube Cloud (formerly SonarCloud)
Fortify on Demand
Orca Security
GitHub Advanced Security
JFrog Xray
Sonatype Lifecycle
Buyer's Guide
Download our free Checkmarx One Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What is the biggest difference between Veracode and Checkmarx?
- Checkmarx or Veracode. Which should we choose?
- What is the Biggest Difference Between Checkmarx and Fortify?
- What is the biggest difference between Checkmarx and SonarQube?
- Checkmarx vs SonarQube; SonarQube interoperability with Checkmarx or Veracode
- If you had to both encrypt and compress data during transmission, which would you do first and why?
- When evaluating Application Security, what aspect do you think is the most important to look for?
- What are the Top 5 cybersecurity trends in 2022?
- What are the threats associated with using ‘bogus’ cybersecurity tools?
- We're evaluating Tripwire, what else should we consider?
The software and application security should be the mandatory thing because most of the applications crash because of virus or harmful attacks. I was also getting the virus issue in my application then avastsupportnumber.co.uk avast customer service helped me a lot.