We use Checkmarx to review the source code for the external applications that we expose to the cloud or other servers on the internet.
Director and Co-Founder at Ushiro-tec
The Best Fix Location & Payments Features Can Save Time Mitigating Network Configurations
Pros and Cons
- "The most valuable features of Checkmarx are the Best Fix Location and the Payments option because you can save a lot of time trying to mitigate the configuration. Using these tools can save you a lot of time."
- "If you really are worried about your business, i.e. about your development sites or development environments, Checkmarx is a great solution."
- "With Checkmarx, normally you need to use one tool for quality and you need to use another tool for security. I understand that Checkmarx is not in the parity space because it's totally different, but they could include some free features or recommendations too."
- "Checkmarx could probably do something to improve their license model."
What is our primary use case?
How has it helped my organization?
We received two main benefits from Checkmarx:
- Better Security
- Saving Time
I recommend Checkmarx to be sure that your development has robust security. For your team management, Checkmarx has a very nice feature to check out manual staff in the process.
What is most valuable?
The most valuable features of Checkmarx are the Best Fix Location and the Payments option because you can save a lot of time trying to mitigate the configuration. Using these tools can save you a lot of time.
What needs improvement?
Checkmarx could probably do something to improve their license model. If you have a small company, or if you have a small team with just one or two applications, the entry-level price is too high for such a company.
You can find all the solutions offered by Checkmarx through other solutions providers. That is why this type of company needs to be more flexible.
In this space, you have a security code and also you have a quality code. It is totally different in terms of investment. In terms of functionality, there are a lot of differences between the various competing products.
With Checkmarx, normally you need to use one tool for quality and you need to use another tool for security. I understand that Checkmarx is not in the parity space because it's totally different, but they could include some free features or recommendations too.
The problem with Checkmarx lies with the pricing and licensing, not the product itself. The product is very good.
Buyer's Guide
Checkmarx One
June 2026
Learn what your peers think about Checkmarx One. Get advice and tips from experienced pros sharing their opinions. Updated: June 2026.
900,747 professionals have used our research since 2012.
For how long have I used the solution?
One to three years.
What do I think about the stability of the solution?
Checkmarx is a good product, certainly stable.
What do I think about the scalability of the solution?
The scalability is good. We haven't had any problems with it.
How are customer service and support?
Our experience with technical support is good. They have a lot of expert staff on their customer service lines. We have had no problems with their technical support services.
Which solution did I use previously and why did I switch?
We used Veracode for some time and it's also a good solution. Veracode fits better for small companies. It's more automatic.
Checkmarx is more complete and they have more features to support our development team and security team requirements.
In general, Checkmarx is a better solution, but it's more complicated, especially in terms of the price for a small company.
How was the initial setup?
Our deployment of Checkmarx took a couple of days, at max, a week.
What about the implementation team?
The setup was a long time back, but I know that we did not use a reseller or consultant for the deployment.
Which other solutions did I evaluate?
We evaluated some products from a company in Spain. Checkmarx provided better functionality and options for us.
What other advice do I have?
We have a small team. It is about four people in total. We do not require that many staff for the deployment and maintenance of Checkmarx.
We are testing the solution in a small local company. Our idea is to expand the use of it to our clients in the West.
In this space, you can have different points of view and if only you are looking for a solution to do a check in your auditory report, then you can choose anyone.
If you really are worried about your business, i.e. about your development sites or development environments, Checkmarx is a great solution.
I would rate Checkmarx a nine out of ten because of the price, but technically for me, it is a 10.
I would rate Checkmarx with a nine because it would be perfect at a more functional level, and could be better at providing these features for parity.
If you research what Checkmarx is offering in their package distribution, you get exactly what they promise up front, so they are not lying.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Principal Software Engineer; Practice Lead at a comms service provider with 10,001+ employees
I like the code consistency feature, but it should have a dynamic testing feature to avoid false duplicates
Pros and Cons
- "The consistency of code showed our team where they are inconsistent or where they have made simple omissions."
- "Dynamic testing. If it had that feature I would have liked to see more consideration of framework validations that we don't have to duplicate. These flags are false positives."
What is our primary use case?
Code scan. We performed periodic static code scans on copies of our Git repository to identify possible vulnerabilities.
How has it helped my organization?
Code consistency. It prompted our developers to fix code or document code they otherwise would not have done.
What is most valuable?
The consistency of code. Showed our team where they are inconsistent or where they have made simple omissions.
What needs improvement?
Dynamic testing. If it had that feature I would have liked to see more consideration of framework validations that we don't have to duplicate. These flags are false positives.
For how long have I used the solution?
One to three years.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Checkmarx One
June 2026
Learn what your peers think about Checkmarx One. Get advice and tips from experienced pros sharing their opinions. Updated: June 2026.
900,747 professionals have used our research since 2012.
Business Analyst at a tech services company with 201-500 employees
It made our organization more efficient with our whole code scan/deployment process for our software applications.
Pros and Cons
- "It is a stable product."
- "Most valuable features include: ease of use, dashboard. interface and the ability to report."
- "It has made our organization more efficient with our whole code scan/deployment process for our software applications."
- "It is an expensive solution."
What is our primary use case?
Our primary use case solution is for code scanning.
How has it helped my organization?
It has made our organization more efficient with our whole code scan/deployment process for our software applications.
What is most valuable?
The most valuable features are:
- Ease of use
- Dashboard
- Interface
- Report
For how long have I used the solution?
One to three years.
What do I think about the stability of the solution?
I have not had an issue with stability of the product.
What do I think about the scalability of the solution?
There have been no issues with scalability that I am aware of.
How are customer service and technical support?
I have not needed the use of technical support.
Which solution did I use previously and why did I switch?
Previously, we considered: Veracode, SonarQube, Fortify and IBM Security AppScan.
How was the initial setup?
I was not involved in the initial setup of the solution.
What was our ROI?
One should consider:
- Visual studio
- Report generation
- If the solution can be on-prem
- Pricing
What's my experience with pricing, setup cost, and licensing?
It is an expensive solution.
What other advice do I have?
Be cautious of the one-year subscription date. Once it expires, your price will go up.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Technical Architect at Photon Interactive
It gives the proper code flow of vulnerabilities and the number of occurrences
Pros and Cons
- "It gives the proper code flow of vulnerabilities and the number of occurrences."
- "After scanning, it shows in-depth code of where actual vulnerabilities are, which helps us to analyze them."
- "It provides us with quite a handful of false positive issues. If Checkmarx could reduce this number, it would be a great tool to use."
What is our primary use case?
I have used it for source code scanning of security vulnerabilities. It seems to be a good tool. It gives the proper code flow of vulnerabilities and the number of occurrences.
How has it helped my organization?
We have scanned various applications with it. It works fine, although we need to check manually for false positive issues.
What is most valuable?
After scanning, it shows in-depth code of where actual vulnerabilities are, which helps us to analyze them.
What needs improvement?
It provides us with quite a handful of false positive issues. If Checkmarx could reduce this number, it would be a great tool to use.
For how long have I used the solution?
One to three years.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Security Source Code Analyst at a tech services company with 10,001+ employees
Easy to insert in the SDLC, but the CxAudit tool has room for improvement
Pros and Cons
- "The most valuable feature for me is the Jenkins Plugin."
- "It is very easy to insert the tool in the SDLC because there are a wide variety of ways to access the source-code, initiate scans, and review the results."
- "I think the CxAudit tool has room for improvement. At the beginning you can choose a scan of a project, but in any event the project must be scanned again (wasting time)."
- "Updating and debugging of queries is not very convenient."
How has it helped my organization?
It is very easy to insert the tool in the SDLC because there are a wide variety of ways to access the source-code, initiate scans, and review the results. The projects need not care about getting a tool, accessing the tool, and it is cheaper using it.
What is most valuable?
The most valuable feature for me is the Jenkins Plugin. We usually take a copy of the normal build job for Checkmarx so that:
- we have all of the source code we need for the build, normal and generated source code;
- we need only one technical user for scanning the projects (SVN access and Git access need to change the passwords every 90 days).
What needs improvement?
I think the CxAudit tool has room for improvement. At the beginning you can choose a scan of a project, but in any event the project must be scanned again (wasting time).
Updating and debugging of queries is not very convenient.
For how long have I used the solution?
One to three years.
What do I think about the stability of the solution?
In our last update to version 8.5.0, we had a problem with DB migration but, overall, I must say it has been stable.
What do I think about the scalability of the solution?
Regarding scalability, we have only one scan engine and our licence allows only two scans at the same time.
How are customer service and technical support?
I would rate the technical support seven out of 10. When you first create a ticket you sometimes get questions that you wouldn't expect from first-level support.
Which solution did I use previously and why did I switch?
None. I started with this product.
How was the initial setup?
The initial setup was decribed very well and it was straightforward. We had only two small problems: implementing the SSL certificate, and getting access for LDAP users.
What's my experience with pricing, setup cost, and licensing?
We got a special offer for a 30% reduction for three years, after our first year.
I think for a real source-code scanning tool, you have to add a lot of money for Open Source Analysis, and AppSec Coach (160 Euro per user per year).
Which other solutions did I evaluate?
I didn’t evaluate this or other solutions, but my team leader had experience with HPE Fortify and he said it is much more expensive, and the service even worse.
What other advice do I have?
Before implementing the product I would evaluate if it is really necessary to scan so many different languages and frameworks. If not, I think there must be a cheaper solution for scanning Java-only applications (which are 90% of our applications).
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Sr. Security Engineer at SugarCRM
Security testing solution with vulnerability details and planned blackout times.
Pros and Cons
- "Vulnerability details is valuable."
- "The initial setup was very easy."
- "Implementing a blackout time for any user or teams: Needs improvement."
- "Vulnerability details: Reduce false positive results and improve it by providing more details how I can resolve the vulnerability."
How has it helped my organization?
- Put the vulnerability details area on the right side of the application or it may be changeable
- Save and reset screen configuration
What is most valuable?
Vulnerability details part.
What needs improvement?
- Vulnerability details: Reduce false positive results and improve it by providing more details how I can resolve the vulnerability.
- Implementing a blackout time for any user or teams: Needs improvement. I need to place limits for some users or teams within a specific time frame. For example, between 02:00 to 06:00. They can't start any scanning during that time, even if they have scanner privileges.
What do I think about the stability of the solution?
In the latest version, the session logout doesn't work properly.
What do I think about the scalability of the solution?
We have two engine licenses, but we can't scan two projects at the same time.
How are customer service and technical support?
I would give technical support a rating of 9/10.
Which solution did I use previously and why did I switch?
We were using Fortify. Its software capability was limited in terms of mobile code scanning.
How was the initial setup?
The initial setup was very easy.
What's my experience with pricing, setup cost, and licensing?
We don't have any specific advice about these issues.
Which other solutions did I evaluate?
We evaluated Fortify and AppScan.
What other advice do I have?
I don't like the latest license update. I can't set a limit for the reviewer account.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Responsable du Pôle Sécurité des Applications at a tech company with 51-200 employees
Both automatic and manual code review are possible. We can set up proper reports of code vulnerability.
Pros and Cons
- "Both automatic and manual code review (CxQL) are valuable."
- "Security can be part of the SDLC and reduce the cost of vulnerability remediation."
- "Integration into the SDLC (i.e. support for last version of SonarQube) could be added."
- "We had to lock the number of CPUs used to not crash the Checkmarx Audit."
How has it helped my organization?
After a proper on-boarding, we can set up proper reports of code vulnerability and/or misconfiguration to developers.
Security can be part of the SDLC and reduce the cost of vulnerability remediation. Also, we got faster remediation time for high and critical vulnerability.
What is most valuable?
Valuable features include:
- Both automatic and manual code review (CxQL).
- The languages covered by the solution.
What needs improvement?
Integration into the SDLC (i.e. support for last version of SonarQube) could be added.
What do I think about the stability of the solution?
We had to lock the number of CPUs used to not crash the Checkmarx Audit.
What do I think about the scalability of the solution?
We haven’t had scalability issues yet.
How are customer service and technical support?
Professional service is really good. Support is too formal. Quickly answering it is not supported instead of developing a hot fix.
Which solution did I use previously and why did I switch?
We didn’t really have a previous solution but Checkmarx was the best match for .NET support and scan without resolving the dependencies.
How was the initial setup?
Setup was straightforward, but quickly you need complex fine tuning.
What's my experience with pricing, setup cost, and licensing?
Include PS or deployment assistance in order not to miss true positive vulnerabilities. Really powerful tool, but it must be configured to match your application.
What other advice do I have?
Ask to meet another customer with the same needs or the same kind of organization, to learn from their experience.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Security test engineer at a tech vendor with 10,001+ employees
Communicates where to fix the issue for less iterations. Resolutions should be provided for installation issues due to internal security policies.
Pros and Cons
- "The solution communicates where to fix the issue for the purpose of less iterations."
- "The resolutions should also be provided. For example, if the user faces any problem regarding an installation due to the internal security policies of their company, there should be a resolution offered."
How has it helped my organization?
Now we have information about which specific sections have to be fixed. We can now remove the issue from most of the sections.
What is most valuable?
The solution communicates where to fix the issue for the purpose of less iterations.
What needs improvement?
The resolutions should also be provided. For example, if the user faces any problem regarding an installation due to the internal security policies of their company, there should be a resolution offered.
What do I think about the stability of the solution?
There were no stability issues.
What do I think about the scalability of the solution?
There were no scalability issues.
How are customer service and technical support?
I would give technical support a rating of 8/10.
Which solution did I use previously and why did I switch?
We switched solutions due to the client's requirements.
What's my experience with pricing, setup cost, and licensing?
I faced a few issues in the installation due to my local policies. The customer support was very helpful.
Which other solutions did I evaluate?
We looked at other tools, such as HPE Security and ZAP solutions.
What other advice do I have?
Go for it, if you want testing on the code level.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
SAP FIORI / HCP Consultant at Silveo
Helps us check vulnerabilities in our applications. I would like to integrate it as a service along with the cloud platform.
Pros and Cons
- "Helps us check vulnerabilities in our SAP Fiori application."
- "One of the most important tools in our building process."
- "I really would like to integrate it as a service along with the SAP HANA Cloud Platform. It will then be easy to use it directly as a service."
- "When we have many applications to check, I need to wait a long time in the queue."
How has it helped my organization?
This product helps us to deliver good quality software.
What is most valuable?
- Performs security checks for SAP Fiori applications
- Helps us check vulnerabilities in our SAP Fiori application
- Easy to use and master
- One of the most important tools in our building process
What needs improvement?
I really would like to integrate it as a service along with the SAP HANA Cloud Platform. It will then be easy to use it directly as a service.
This improvement is needed in order to follow up the growth and of SAP cloud platform, it is a Platform as a service created by SAP, many services have been added to SAP HANA Cloud Platform, like GIT repository, Jenkins, Translation etc.
So, if it is possible to add the Checkmarx as a service in this platform, it will be easy to perform security check directly without using a dedicated server.
What do I think about the stability of the solution?
Maybe this issue is related to our configuration. When we have many applications to check, I need to wait a long time in the queue.
What do I think about the scalability of the solution?
We did encounter scalability issues. Maybe this is related to the stability issue mentioned above.
Which solution did I use previously and why did I switch?
We haven't used anything else. This is our first solution.
How was the initial setup?
I don’t know how to set up the product.
Which other solutions did I evaluate?
We did not look at any other options.
What other advice do I have?
It is a good tool. I recommend it in order to ensure software quality.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Technical Program Manager at a engineering company with 10,001+ employees
Acts as the first check point during our consulting for apps that are looking for a security assessment or Penetration Testing.
Pros and Cons
- "The ability to track the vulnerabilities inside the code (origin and destination of weak variables or functions)."
- "Checkmarx is a powerful scanning tool, and it’s essential to have one of these products to build a safe and stable application when it comes to inviting customers to use your online services."
- "The lack of ability to review compiled source code. It would then be able to compete with other scanning tools, such as Veracode."
How has it helped my organization?
For manual code testing, Checkmarx has been very helpful discarding false positives, filtering and removing a lot of files that are not presenting any threat, as well as indicating the files or functions that should be focused upon.
Checkmarx acts as the first checkpoint during our consulting for apps that are looking for a security assessment or Penetration Testing. It is also a game changer, giving the customer's results from each finding in the Checkmarx results.
What is most valuable?
- The export feature and presentation of the results.
- The ability to track the vulnerabilities inside the code (origin and destination of weak variables or functions).
- A wide variety of modern programming languages are supported, including mobile languages).
What needs improvement?
The lack of ability to review compiled source code. It would then be able to compete with other scanning tools, such as Veracode.
Compiled code means that the code written is stored in binaries, for machine reading only. Tools like Veracode read only those binaries (compiled code).
Another way to have the code is “Source Code written only”, which is the only code format that Checkmarx accepts, a process where you don’t compile and everyone is able to read line by line the code.
What do I think about the stability of the solution?
When the workload contains so many source codes being scanned, and none of them present any progress, sometimes they seem to get stuck. There are also a considerable number of false positives (vulnerabilities that do not present a danger against the application or the user).
What do I think about the scalability of the solution?
We have not encountered any scalability issues.
How are customer service and support?
From both customer support and technical support, the response is very swift (less than a day) and the technical people are very skilled on the common issues concerning the management of the scanning tool, even with issues of server saturation and scanners stuck at a percentage.
Which solution did I use previously and why did I switch?
I used to work mostly on checking the source code manually, and estimated the time of completion counting the lines of code to review. With Checkmarx that time was hugely reduced.
I also worked with Veracode, which I use for compiled code, but most of the customer’s applications have uncompiled code, so that is why I use Checkmarx more frequently.
How was the initial setup?
The initial setup was complex. There is a curve of learning, and you also need technical knowledge on reviewing the results of Checkmarx’s work.
What's my experience with pricing, setup cost, and licensing?
Checkmarx is not a cheap scanning tool, but none of the security tools are cheap. Checkmarx is a powerful scanning tool, and it’s essential to have one of these products to build a safe and stable application when it comes to inviting customers to use your online services.
Which other solutions did I evaluate?
We evaluated AppScan and Veracode. Neither covers the needs of my clients, the way I work, and the programming languages that Checkmarx covers.
What other advice do I have?
I recommend to have a live session with the marketing team, to have a demo and to track all your doubts before purchasing. Checkmarx is a powerful tool but you need to be sure what you are using, and what it is for. You could use just 20% of what the tool can do, and therefore waste your money. So either fully learn how to use it and evaluate if it’s the right scanning tool to have, or go for a better and cheaper option.
Disclosure: My company has a business relationship with this vendor other than being a customer. We support together a huge list of clients, we have credentials and provide support to each
business and division. So, we have the capacity to escalate any trouble or problem in case it is
necessary. We have our own community and are able to provide and remove access to users.
Buyer's Guide
Download our free Checkmarx One Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2026
Product Categories
Application Security Tools Static Application Security Testing (SAST) Vulnerability Management Container Security Static Code Analysis API Security Dynamic Application Security Testing (DAST) DevSecOps Risk-Based Vulnerability Management Application Security Posture Management (ASPM) AI SecurityPopular Comparisons
SonarQube
SentinelOne Singularity Cloud Security
Microsoft Defender for Cloud
Prisma Cloud by Palo Alto Networks
GitLab
Veracode
Tanium
Qualys VMDR
Imperva Application Security Platform
TrendAI Vision One – Cloud Security
Orca Security
CrowdStrike Falcon Cloud Security
Tenable Nessus
Buyer's Guide
Download our free Checkmarx One Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What is the biggest difference between Veracode and Checkmarx?
- Checkmarx or Veracode. Which should we choose?
- What is the Biggest Difference Between Checkmarx and Fortify?
- What is the biggest difference between Checkmarx and SonarQube?
- Checkmarx vs SonarQube; SonarQube interoperability with Checkmarx or Veracode
- If you had to both encrypt and compress data during transmission, which would you do first and why?
- When evaluating Application Security, what aspect do you think is the most important to look for?
- What are the threats associated with using ‘bogus’ cybersecurity tools?
- What are the Top 5 cybersecurity trends in 2022?
- Which application security solutions include both vulnerability scans and quality checks?
















