Try our new research platform with insights from 80,000+ expert users
reviewer932058 - PeerSpot reviewer
AVP, aPaaS Engineer at a financial services firm with 10,001+ employees
Real User
Reasonably price, high performance, and simple installation
Pros and Cons
  • "The solution has good performance, it is able to compute in 10 to 15 minutes."
  • "Checkmarx could improve the REST APIs by including automation."

What is our primary use case?

We are using Checkmarx for application code scanning, such as scanning for different leverages in the application code.

What is most valuable?

The solution has good performance, it is able to compute in 10 to 15 minutes. 

What needs improvement?

Checkmarx could improve the REST APIs by including automation.

For how long have I used the solution?

I have been using Checkmarx for approximately one year.

Buyer's Guide
Checkmarx One
August 2025
Learn what your peers think about Checkmarx One. Get advice and tips from experienced pros sharing their opinions. Updated: August 2025.
865,295 professionals have used our research since 2012.

What do I think about the stability of the solution?

Checkmarx is stable.

What do I think about the scalability of the solution?

The scalability of Checkmarx is good, we can onboard easily.

We have approximately 200 people in my organization using this solution.

How are customer service and support?

I have not contacted technical support. We have not required it.

Which solution did I use previously and why did I switch?

I have used SonarQube previously.

How was the initial setup?

The installation is straightforward and takes approximately 40 minutes.

What about the implementation team?

I am able to do the implementation myself.

We have administrators and engineers that support and maintain the solution.

What's my experience with pricing, setup cost, and licensing?

We have purchased an annual license to use this solution. The price is reasonable.

What other advice do I have?

I rate Checkmarx a nine out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1646475 - PeerSpot reviewer
Senior Cybersecurity Solution Architect at a computer software company with 51-200 employees
Real User
Integrates well with other security solutions
Pros and Cons
  • "It can integrate very well with DAST solutions. So both of them are combined into an integrated solution for customers running application security."
  • "I expect application security vendors to cover all aspects of application security, including SAST, DAST, and even mobile application security testing. And it would be much better if they provided an on-premises and cloud option for all these main application security features."

What is our primary use case?

Checkmarx is used only for static application security testing (SAST), and it can integrate very well with DAST solutions. So both of them are combined into an integrated solution for customers running application security.

What needs improvement?

I expect application security vendors to cover all aspects of application security, including SAST, DAST, and even mobile application security testing. And it would be much better if they provided an on-premises and cloud option for all these main application security features. So most of my customers would love to have consolidated vendors who cover all application security to lower operational overhead.

For how long have I used the solution?

I'm a solution architect, not an end-user. I'm selling Checkmarx. This is the first year I've done business with Checkmarx. In the past five years, I worked a lot with Fortify and Micro Focus. I currently have two customers running Checkmarx, and one more is evaluating the product.

How was the initial setup?

Setting up Checkmarx should be relatively straightforward. It takes a little more time for the DevOps team to enable everything, but overall deployment should take less than a week, including preparation and implementation. 

What's my experience with pricing, setup cost, and licensing?

Most of my customers opted for a perpetual license. They prefer to pay the highest amount upfront for the perpetual license and then pay for additional support annually.

What other advice do I have?

I rate Checkmarx eight out of 10. Until I get more extensive feedback from clients, I would rate it an eight.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Buyer's Guide
Checkmarx One
August 2025
Learn what your peers think about Checkmarx One. Get advice and tips from experienced pros sharing their opinions. Updated: August 2025.
865,295 professionals have used our research since 2012.
reviewer1672218 - PeerSpot reviewer
Director and Co-Founder at a tech services company with 1-10 employees
Real User
Fits our requirements, scales easily, and is easy to use
Pros and Cons
  • "It is very useful because it fits our requirements. It is also easy to use. It is not complex, and we are satisfied with the results."
  • "Its pricing model can be improved. Sometimes, it is a little complex to understand its pricing model."

What is most valuable?

It is very useful because it fits our requirements. It is also easy to use. It is not complex, and we are satisfied with the results.

What needs improvement?

Its pricing model can be improved. Sometimes, it is a little complex to understand its pricing model.

For how long have I used the solution?

I have been using this solution for a couple of years.

What do I think about the stability of the solution?

It is pretty stable.

What do I think about the scalability of the solution?

It has the capability to scale very easily. It is not a problem.

How are customer service and technical support?

Their support is good. It has a good webpage with a lot of details.

How was the initial setup?

It is very easy to set up. It takes a couple of days. It is not an issue.

What's my experience with pricing, setup cost, and licensing?

It is not expensive, but sometimes, their pricing model or licensing model is not very clear. There are similar variables, such as projects or developers, and sometimes, it is a little bit confusing. 

What other advice do I have?

I would absolutely recommend this solution. I would rate Checkmarx a nine out of 10.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
reviewer1398084 - PeerSpot reviewer
Procurement Analyst at a pharma/biotech company with 10,001+ employees
Real User
Flexible features, stable, but more supported languages needed
Pros and Cons
  • "One of the most valuable features is it is flexible."
  • "The integration could improve by including, for example, DevSecOps."

What is our primary use case?

We use the solution for scanning the code for security.

What is most valuable?

One of the most valuable features is it is flexible. 

What needs improvement?

The integration could improve by including, for example, DevSecOps.

In an upcoming release, they could improve by adding support for more languages.

For how long have I used the solution?

I have been using the solution for two years.

What do I think about the stability of the solution?

I have found the solution to be stable.

What do I think about the scalability of the solution?

The scalability of the solution is good. We have approximately 4000 using the solution in my organization and they are mostly engineers.

How are customer service and technical support?

The technical support we have experience was good but they could be faster.

What other advice do I have?

I would recommend this solution to others.

I rate Checkmarx a six out of ten.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1355637 - PeerSpot reviewer
Director at a tech services company with 11-50 employees
Reseller
Good features, good support, fair price, and good ability to deliver what customers require
Pros and Cons
  • "The features and technologies are very good. The flexibility and the roadmap have also been very good. They're at the forefront of delivering the additional capabilities that are required with cloud delivery, etc. Their ability to deliver what customers require and when they require is very important."
  • "There is nothing particular that I don't like in this solution. It can have more integrations, but the integrations that we would like are in the roadmap anyway, and they just need to deliver the roadmap. What I like about the roadmap is that it is going where it needs to go. If I were to look at the roadmap, there is nothing that is jumping out there that says to me, "Yeah. I'd like something else on the roadmap." What they're looking to deliver is what I would expect and forecast them to deliver."

What is our primary use case?

We're selling their licenses and their technologies. We have on-premises and cloud deployments. Its deployment depends on the customer requirements. 

It is used for a range of requirements for DevSecOps. It has been deployed to ensure that the development cycle delivers clean and secure code that is vulnerability-free. It is there as a part of the whole compliance and security process.

What is most valuable?

The features and technologies are very good. The flexibility and the roadmap have also been very good. They're at the forefront of delivering the additional capabilities that are required with cloud delivery, etc. Their ability to deliver what customers require and when they require is very important. 

What needs improvement?

There is nothing particular that I don't like in this solution. It can have more integrations, but the integrations that we would like are in the roadmap anyway, and they just need to deliver the roadmap. What I like about the roadmap is that it is going where it needs to go. If I were to look at the roadmap, there is nothing that is jumping out there that says to me, "Yeah. I'd like something else on the roadmap." What they're looking to deliver is what I would expect and forecast them to deliver.

For how long have I used the solution?

I have been using this solution for two years.

What do I think about the scalability of the solution?

Our customers are completely comfortable with the scalability of the technologies. They can deploy them initially in a relatively straightforward manner and then grow them into their organization quite successfully. We primarily have large customers.

How are customer service and technical support?

Our team works with them. Their sales engineering team as well as their pre-sales capabilities are very good. They're clear. They work, and they're available, which is good. It is somewhat unusual in this business.

How was the initial setup?

It depends on different technologies, but it is reasonably quite straightforward.

What's my experience with pricing, setup cost, and licensing?

Its price is fair. It is in or around the right spot. Ultimately, if the price is wrong, customers won't commit, but they do tend to commit. It is neither too cheap nor too expensive.

What other advice do I have?

They're a very good company to work with, and that's a very important aspect of any technology these days. You could find very nice technologies, but if the company is not good to work with, it could be of no use. You'll not be able to get it deployed, and you'll not get assistance. You will get bad value for good technology. Checkmarx is a nice, pleasant, and relatively easy company to work with. You will get a good return, and you will get a good partnership and relationship working with them.

I would rate Checkmarx an eight out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
reviewer1521882 - PeerSpot reviewer
Information Security Architect at a tech services company with 1,001-5,000 employees
Real User
Gives less number of false positives and supports most of the languages, but need to support remaining languages and create a model to identify zero-day attacks
Pros and Cons
  • "The feature that I have found most valuable is that its number of false positives is less than the other security application platforms. Its ease of use is another good feature. It also supports most of the languages."
  • "They can support the remaining languages that are currently not supported. They can also create a different model that can identify zero-day attacks. They can work on different patterns to identify and detect zero-day vulnerability attacks."

What is our primary use case?

We are using multiple solutions for application security, and Checkmarx is one of them. We are a client-centric organization, and we are also providing support to clients for application security. Sometimes, we have our own production, and then we scan the customer information and provide application security. For a few clients, it is deployed on the cloud, and for a few customers, it is on-premises.

What is most valuable?

The feature that I have found most valuable is that its number of false positives is less than the other security application platforms. Its ease of use is another good feature. It also supports most of the languages.

What needs improvement?

They can support the remaining languages that are currently not supported. They can also
create a different model that can identify zero-day attacks. They can work on different patterns to identify and detect zero-day vulnerability attacks.

What do I think about the stability of the solution?

It is stable, and it works.

What do I think about the scalability of the solution?

It is scalable. Our clients are small, medium, and big enterprises. It is for all the categories.

How are customer service and technical support?

Their support is good. I had discussions with them multiple times. We are getting proper support.

How was the initial setup?

It is straightforward. It is not a big challenge. It doesn't take long.

What's my experience with pricing, setup cost, and licensing?

I would rate Checkmarx a seven out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
reviewer1192836 - PeerSpot reviewer
Director of consultory at a non-tech company with 1,001-5,000 employees
Reseller
Includes features to easily secure code, multiple language support and excellent customer support
Pros and Cons
  • "The setup is very easy. There is a lot of information in the documents which makes the install not difficult at all."
  • "I would like to see the DAST solution in the future."

What is our primary use case?

We onboard clients with the solution. We install the product and do the first scan with them. We help developers with security and the best practices with their applications with this solution.

What is most valuable?

The most valued feature comes within the platform called Codebashing, it allows scanning code for security flaws. Our clients are able to learn from these scans and develop more secure code. The solution is easy to configure and user friendly as well. They also have support for a large variety of languages compared to other solutions and the product updates continuously.

What needs improvement?

I would like to see the DAST solution in the future. 

For how long have I used the solution?

We have been using the solution for one year.

What do I think about the stability of the solution?

We had no issues and it has always worked at a top level of performance.

What do I think about the scalability of the solution?

The solution is easy to intergate. It is plug and play and intergrates well with the pipeline and DevSecOps. Our main client is a big company and the solution works well.

How are customer service and technical support?

The support is excellent.

How was the initial setup?

The setup is very easy. There is a lot of information in the documents which makes the install not difficult at all.

What was our ROI?

The product saves you money by minimizing the time needed to figure out how to mitigate the problems by using such features such as The Best Fixed Location and the flow charts.

Which other solutions did I evaluate?

We evaluated Veracode before choosing Checkmarx.

What other advice do I have?

Depending on the client, we could deploy the solution on the cloud or on-premise. I would recommend Checkmarx because you can learn from the scanning done. They have some of the best features which make the product wonderful. 

I rate Checkmarx a ten out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
PeerSpot user
reviewer1415661 - PeerSpot reviewer
General Manager at a consultancy with 51-200 employees
Real User
Intuitive interface, easy to set up, and saves us money by finding problems at an early stage
Pros and Cons
  • "The UI is very intuitive and simple to use."
  • "Creating and editing custom rules in Checkmarx is difficult because the license for the editor comes at an additional cost, and there is a steep learning curve."

What is our primary use case?

We use Checkmarx for static analysis as part of our software development lifecycle. It is very important because it helps us identify the security flaws in the code at a very early stage. Ultimately, this helps in reducing costs.

What is most valuable?

The UI is very intuitive and simple to use. You don't need to know anything about the product before you being working with it.

The interface used to audit issues is also simple to use.

Compared to similar products, the code scanning time is fast.

What needs improvement?

Most the the static analysers come with pre-loaded rulesets. However, many times developers have to write their own custom rules. Writing custom rules in Checkmark is difficult because you need a different editor which is licensed separately. Besides not much training material is available on how to write the rules. 

For how long have I used the solution?

We have been using Checkmarx for almost four years.

What do I think about the stability of the solution?

It is pretty stable and we have not had any issues. We have a monitoring team that monitors the health of our infrastructure and we are alerted to any problems.

What do I think about the scalability of the solution?

We were able to scale easily and did not have any issues in doing so. At this team, we have between 70 and 80 applications that we are scanning with it.

How are customer service and technical support?

We have contacted technical support a couple of times and the issues were addressed in a timely manner.

Which solution did I use previously and why did I switch?

We have used other products and found that you have to spend considerable time fine-tuning the scanning engine. With Checkmarx, it is a lot less and I would say that this is one of the significant differences with this solution.

The maintenance in terms of running the scans and fine-tuning the scans is very low.

On the other hand, we have used other tools where writing custom rules is not so difficult to do.

How was the initial setup?

Checkmarx is pretty straightforward and very easy to set up.

What about the implementation team?

Our in-house team deployed and manages this product. I have one person who handles all of it, and the deployment can be completed within a day or two. As long as the infrastructure is ready, it can be done within a day.

What was our ROI?

Checkmarx helps us to find problems with source code at an early stage in the development, which saves us in terms of troubleshooting costs.

What's my experience with pricing, setup cost, and licensing?

The interface used to create custom rules comes at an additional cost.

What other advice do I have?

Checkmarx is probably one of the best static code analyzers available in the market at this point. It is very easy to deploy, use, and maintain. The amount of maintenance required is pretty low. It is absolutely a good tool that I can recommend.

Checkmarx has added a lot of functionality since we began using it. This includes OSA, the open-source scan, a training module, and run-time protection.

For static code analysis, we are only using Checkmarx and we plan to continue. 

I would rate this solution a nine out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Checkmarx One Report and get advice and tips from experienced pros sharing their opinions.
Updated: August 2025
Buyer's Guide
Download our free Checkmarx One Report and get advice and tips from experienced pros sharing their opinions.