We have been using this product extensively for a lot of applications to identify as well as employ proper remediation which makes the application secure including information issues which might get neglected with a manual code review process.
Innovation Consultant (Security Analyst) at a tech services company with 1,001-5,000 employees
It makes it easier to identify code vulnerabilities by presenting the flow of malicious input and fixing it.
Pros and Cons
- "Checkmarx pinpoints the vulnerability in the code and also presents the flow of malicious input across the application."
- "We have been using this product extensively for a lot of applications to identify as well as employ proper remediation which makes the application secure including information issues which might get neglected with a manual code review process."
- "Some of the descriptions were found to be missing or were not as elaborate as compared to other descriptions. Although, they could be found across various standard sources but it would save a lot of time for developers, if this was fixed."
- "Unfortunately, Checkmarx doesn't do any automated backups which is quite inconvenient."
How has it helped my organization?
What is most valuable?
Checkmarx pinpoints the vulnerability in the code and also presents the flow of malicious input across the application. It therefore makes it easier to identify these as well as fix them.
What needs improvement?
Checkmarx has the detailed description of all the vulnerabilities which it identifies after the source code scan. These descriptions are just a click away. Some of the descriptions were found to be missing or were not as elaborate as compared to other descriptions. Although, they could be found across various standard sources but it would save a lot of time for developers, if this was fixed.
What do I think about the stability of the solution?
We have not yet encountered any stability issues.
Buyer's Guide
Checkmarx One
June 2026
Learn what your peers think about Checkmarx One. Get advice and tips from experienced pros sharing their opinions. Updated: June 2026.
900,747 professionals have used our research since 2012.
What do I think about the scalability of the solution?
The solution provides high scalability. I am not sure about the limit of scans but it is sufficiently high. However, the issues which we faced were related to database backup. Unfortunately, Checkmarx doesn't do any automated backups which is quite inconvenient.
How are customer service and support?
I would rate the technical support as average. We never had to communicate much with the technical team but based on my knowledge the response from their end was delayed.
Which solution did I use previously and why did I switch?
I am not aware of any previous solutions.
How was the initial setup?
The setup was straightforward.
What's my experience with pricing, setup cost, and licensing?
It is a good product but a little overpriced.
Which other solutions did I evaluate?
I don't have much idea about other options since the organization had already purchased the product before I joined.
What other advice do I have?
Better to look out for other products available in the market as well.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Manager at a financial services firm
We felt like we were the extended quality organization as they frequently released poor quality patches that broke the existing functionality.
Pros and Cons
- "Scan reviews can occur during the development lifecycle."
- "It moved our organization towards being agile vs. waterfall."
- "C, C++, VB and T-SQL are not supported by this product. Although, C and C++ were advertised as being supported."
- "We felt like we were the extended quality organization for Checkmarx as they frequently released poor quality patches that broke the existing functionality."
How has it helped my organization?
It moved our organization towards being agile vs. waterfall.
What is most valuable?
Scan reviews can occur during the development lifecycle.
What needs improvement?
The areas in which this product needs to improve are:
- C, C++, VB and T-SQL are not supported by this product. Although, C and C++ were advertised as being supported.
- There were issues in regards to the JSP parsing.
- Defect report generation takes multiple hours for large projects.
- The Jenkins plugin does not work for projects that are larger than 4 million lines of code.
- The Eclipse plugin does not work.
- The hardware requirements for the tool add to the substantial cost of the solution and thus, increase the total cost of ownership.
- There seems to be a decline in the support team's responsiveness as our contract nears its end.
- We felt like we were the extended quality organization for Checkmarx as they frequently released poor quality patches that broke the existing functionality. A lot of the organizational hours, almost 1 FTE per year since Checkmarx was implemented, were spent to allow regression testing of the product. The Checkmarx SME team at my company had to do this testing to ensure that we do not expose product flaws to our user community.
What do I think about the stability of the solution?
We did encounter stability issues. The different versions of this product provide inconsistent results when the same piece of code is scanned.
What do I think about the scalability of the solution?
We did not encounter any scalability issues.
How are customer service and technical support?
The support team is knowledgeable. However, we still have tickets open from 2014. There is a lot of follow up required to get closure on issues.
Which solution did I use previously and why did I switch?
Previously, we were using a different solution. We were leveraging multiple tools since we have code in multiple languages. Checkmarx advertised that they provide support for C, C+++, Java, etc. It turned out that they aren’t able to scan C and C++ for us. Our reason to switch to Checkmarx didn’t work out for us.
How was the initial setup?
The initial setup was straightforward.
What's my experience with pricing, setup cost, and licensing?
The license has a vague language around P1 issues and the associated support. Make sure to review these in order to align them with your organizational policies.
I suggest using a trial term to run a gamut of scenarios that need to be leveraged before settling in with the Checkmarx solution.
Which other solutions did I evaluate?
We evaluated the Veracode option.
What other advice do I have?
The product is not mature and ready for the enterprise usage yet. It is okay to use it when the support expectations are low and the code is in languages that require support only in Java and .NET.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Checkmarx One
June 2026
Learn what your peers think about Checkmarx One. Get advice and tips from experienced pros sharing their opinions. Updated: June 2026.
900,747 professionals have used our research since 2012.
Founder at a tech company with 51-200 employees
It can scan precompiled (source) code, as well as compiled (binary) code.
Pros and Cons
- "The process of remediating software security vulnerabilities can now be performed (ongoing) as portions of the application are being built in advance of being compiled."
- "The product can be improved by continuing to expand the application languages and frameworks that can be scanned for vulnerabilities. This includes expanded coverage for mobile applications as well as open-source development tools."
How has it helped my organization?
The process of remediating software security vulnerabilities can now be performed (ongoing) as portions of the application are being built in advance of being compiled. Among other benefits, this reduces the cost to fix the problem(s) as the fix can occur earlier in the SDLC.
What is most valuable?
The ability to identify a vulnerability, the optimal place for remediation and the correct syntax is very valuable. This feature helps ensure that the software fix is comprehensive and effective. The CxSuite is easy to use and because it provides the correct coding syntax to address a vulnerability, it helps improve the secure coding skill set among developers. The product can scan precompiled (source) code, as well as compiled (binary) code, delivering effectiveness and efficiency throughout the SDLC.
What needs improvement?
The product can be improved by continuing to expand the application languages and frameworks that can be scanned for vulnerabilities. This includes expanded coverage for mobile applications as well as open-source development tools.
The Checkmarx CxSuite covers a wide range of programming languages including many of the most popular languages used by developers today. As matter of general improvement, expanding coverage to languages (emerging, legacy) and open source frameworks will increase the overall effectiveness of product.
*2017 Update. A number of leading Open Source Frameworks are now supported.
What do I think about the stability of the solution?
The product is stable.
What do I think about the scalability of the solution?
The product scales well.
How are customer service and technical support?
The technical support is high quality. The support team is well versed in how best to configure, implement and operate the product.
Which solution did I use previously and why did I switch?
I did not previously use a different solution.
How was the initial setup?
The initial set up is straightforward. The product requires a fairly simple computing environment for operation.
What's my experience with pricing, setup cost, and licensing?
The product licensing offers the flexibility to cover a wide range of environments. The pricing is competitive and provides a lower TCO (total cost of ownership) for achieving application security.
Which other solutions did I evaluate?
We considered several other commercial-grade application security solutions. The Checkmarx solution offers an ideal combination of code coverage, functionality, usability and TCO.
What other advice do I have?
The Checkmarx CxSuite product works well, delivers efficiency to the SDLC, and most important of all, it effectively improves application security.
It works!
Disclosure: My company has a business relationship with this vendor other than being a customer. My company is a Checkmarx Certified Partner.
SRE Vice Group Manager at a tech services company with 10,001+ employees
We can create custom rules for code checks. You have to do a lot of customization.
Pros and Cons
- "The solution allows us to create custom rules for code checks."
- "This product requires you to create your own rulesets. You have to do a lot of customization."
How has it helped my organization?
During the trial period, we tried to build automated security development lifecycles with this product and with other products. We have achieved partial success with this.
What is most valuable?
The solution allows us to create custom rules for code checks. Without custom rules, the system couldn’t find anything serious in the custom code and libraries.
What needs improvement?
The main issue was the supported Windows OS for the installation. Windows is not appropriate for a big internet company’s infrastructure. Supporting a Windows machine, especially for this software, is inconvenient.
This product requires you to create your own rulesets. You have to do a lot of customization. The default rules do not work very well. In addition, it is impossible to analyze code with dynamic dependencies.
What do I think about the stability of the solution?
There were no problems with stability. The application was stable in our test cases.
What do I think about the scalability of the solution?
There were no scalability issues, but keep in mind that our version can only scale on one server.
How are customer service and technical support?
There is very good technical support. We have the support of two onsite engineers.
Which solution did I use previously and why did I switch?
We are using other tools along with this solution.
How was the initial setup?
The setup was simple. It mostly involved clicking the “Next” button in the Windows installer.
What's my experience with pricing, setup cost, and licensing?
The pricing was not very good. This is just a framework which shouldn’t cost so much.
The product comes with very strange licensing options. They don’t let you exclude workplace licenses, which are useless for building automated systems.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Software Security Analyst at a financial services firm with 1,001-5,000 employees
It scans code for security vulnerabilities without needing to compile first. It reports many false positives.
Pros and Cons
- "We were using HPE Security Fortify to scan code for security vulnerabilities, but it can scan only after a successful compile, and if the code has dependencies or build errors the scan fails, while with Checkmarx pre-compile scanning is seamless and allows us to scan more code."
- "Checkmarx reports many false positives that we need to manually segregate and mark “Not exploitable”."
How has it helped my organization?
Checkmarx saves us a lot of time. We were using HPE Security Fortify to scan code for security vulnerabilities, but it can scan only after a successful compile. If the code has dependencies or build errors, the scan fails. With Checkmarx, pre-compile scanning is seamless. This allows us to scan more code.
What is most valuable?
The most valuable feature is that Checkmarx scans code for security vulnerabilities without needing to compile first.
What needs improvement?
Checkmarx reports many false positives that we need to manually segregate and mark “Not exploitable”.
What do I think about the stability of the solution?
We encountered stability issues when scanning large code blocks. It consumes a lot of memory, and at times, Checkmarx services freeze and don’t work properly.
What do I think about the scalability of the solution?
I don’t know of any scalability issues.
How are customer service and technical support?
Just four words for the technical support team: “Checkmarx team is awesome”.
Which solution did I use previously and why did I switch?
Before Checkmarx, we used HPE Security Fortify and IBM AppScan. We also tried several open-source scanning tools.
How was the initial setup?
Overall, the initial setup is easy. Checkmarx provides an installer binary and we just need go through the wizard for an express installation. If we need an advanced configuration, we contact the Checkmarx support team.
What's my experience with pricing, setup cost, and licensing?
I believe pricing is better compared to other commercial tools.
Which other solutions did I evaluate?
Yes, we compared Checkmarx features and benefits with IBM AppScan and HPE Security Fortify.
What other advice do I have?
Personally, I recommend Checkmarx for static analysis.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Assistant Manager Business Development at a tech services company with 501-1,000 employees
It offers comprehensive and incremental scanning, and supports all major languages.
Pros and Cons
- "Less false positive errors as compared to any other solution."
- "As an InfoSec consulting company, we come across major challenging projects, and Checkmarx has made life easy by reducing manual efforts in using test cases against any vulnerability found during source code reviews while intelligently finding the latest vulnerabilities beyond the OWASP Top Ten."
- "Licensing models and Swift language support are the aspects in which this product needs to improve. Swift is a new language, in which major customers require support for lower prices."
How has it helped my organization?
As an InfoSec consulting company, we come across major challenging projects. Checkmarx has made life easy and my team is best at using it. It reduces manual efforts in using test cases against any vulnerability found during source code reviews. Apart from OWASP Top Ten, Checkmarx is quite intelligent to find the latest vulnerability and report it.
What is most valuable?
Some valuable features of this product are:
- Very comprehensive scanning
- Less false positive errors as compared to any other solution
- Incremental scanning
- Supports all major languages
What needs improvement?
Licensing models and Swift language support are the aspects in which this product needs to improve. Swift is a new language, in which major customers require support for lower prices.
What do I think about the stability of the solution?
I have not encountered any stability issues.
What do I think about the scalability of the solution?
I have not encountered any scalability issues.
How are customer service and technical support?
I have never used technical support, so can't comment. We ourselves are expert at it.
Which solution did I use previously and why did I switch?
We have used no other product.
How was the initial setup?
The setup process was simple.
What's my experience with pricing, setup cost, and licensing?
It is the right price for quality delivery.
Which other solutions did I evaluate?
We did not evaluate other options, before choosing this product.
What other advice do I have?
Go for it.
Disclosure: My company has a business relationship with this vendor other than being a customer. We're the primary resellers of the product in India and Middle East region.
Senior Software Security Analyst at a financial services firm with 1,001-5,000 employees
It allows for SAST scanning of uncompiled code. More API functionality should be added.
Pros and Cons
- "It allows for SAST scanning of uncompiled code. Further, it natively integrates with all key repos formats (Git, TFS, SVN, Perforce, etc)."
- "Initial setup couldn't be any easier; Checkmarx has good documentation on environment requirements, and as long as you meet those, the installation process takes maybe 30 minutes for an initial setup, perhaps a bit longer if you're adding multiple engines."
- "Meta data is always needed."
Improvements to My Organization
Cx gives you the ability to push SAST down much lower in the SDLC process. With the use of multiple IDE plugins and the ability to do "incremental" scanning, a scan of your latest code does not bog down your machine as it is offloaded.
Valuable Features
It allows for SAST scanning of uncompiled code. Further, it natively integrates with all key repos formats (Git, TFS, SVN, Perforce, etc).
Room for Improvement
Meta data is always needed. More tutorials/videos for developers to fix their vulnerabilities is nice. Although the API is useful, I would like to see more functionality added.
Stability Issues
I've had to restart services/bounce the VM on two rare occasions.
Scalability Issues
It scales very easy.
Customer Service and Technical Support
Customer Service:
Customer service is good. Engineers have been quick to get back to me regarding issues and custom work that I have performed.
Technical Support:
Technical support is very knowledgeable.
Initial Setup
Initial setup couldn't be any easier. Cx has good documentation on environment requirements. As long as you meet those, the installation process takes maybe 30 minutes for an initial setup; perhaps a bit longer if you're adding multiple engines.
Implementation Team
An in-house team implemented it.
Pricing, Setup Cost and Licensing
Everything is negotiable. Checkmarx approached our dealings in good faith and clearly wanted to be around for awhile. It is much more inexpensive than some alternatives.
Other Solutions Considered
Before choosing, we also evaluated Fortify, IBM Appscan, Veracode, etc.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Hi Joe,
Given that you've continued to successfully use Checkmarx for an extended period of time since you contributed to our discussion that compares the solution to Veracode,
How does your experience compare one year later?
(See the discussion thread here:
www.itcentralstation.com/questions/checkmarx-or-veracode-which-should-we-choose)
Looking forward to your feedback
Full Stack Developer at a tech services company with 51-200 employees
It helps with vulnerability scanning of codes to prevent vulnerability of our applications.
Pros and Cons
- "The license is fairly costly but worth the investment."
What is most valuable?
It provides us with code analysis.
How has it helped my organization?
It helps with vulnerability scanning of codes to prevent vulnerability of our applications.
For how long have I used the solution?
I've used it for one year.
What was my experience with deployment of the solution?
No issues encountered.
Which solution did I use previously and why did I switch?
Straight forward. Easy to follow steps.
I worked for an IT security firm and it was quite easy to setup the product for demo purposes virtually and even physically on the client premises
How was the initial setup?
It was straightforward, as it has easy to follow steps.
I worked for an IT security firm and it was quite easy to setup the product for demo purposes virtually and even physically on the client premises.
What's my experience with pricing, setup cost, and licensing?
The license is fairly costly but worth the investment.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partners
Co-Founder, CTO at a tech services company with 51-200 employees
It allows us to verify the dev department's code in order to minimize security holes, but it needs better role management.
Pros and Cons
- "We have used this product to verify the dev department's code in order to minimize security holes."
- "It needs better role management."
What is most valuable?
They're all as valuable as each other.
How has it helped my organization?
We have used this product to verify the dev department's code in order to minimize security holes.
What needs improvement?
It needs better role management.
For how long have I used the solution?
I've used it for three years.
What was my experience with deployment of the solution?
No issues encountered.
What do I think about the stability of the solution?
No issues encountered.
What do I think about the scalability of the solution?
No issues encountered.
How are customer service and technical support?
Customer Service:
It's very good.
Technical Support:It's very good.
Which solution did I use previously and why did I switch?
This is the only solution I have used.
How was the initial setup?
Very straightforward.
What about the implementation team?
I implemented it myself.
What's my experience with pricing, setup cost, and licensing?
Licensing is expensive per X amount of lines in the code.
Which other solutions did I evaluate?
No other options were evaluated.
Disclosure: My company has a business relationship with this vendor other than being a customer. We are providing leads to Checkmarx.
Going for another POC with Checkmarx... This time implementing it with Jira, to open an automatic flow for better mitigation SLA and for Infosec visibility
Cyber-Ark Consultant at a tech services company with 51-200 employees
It is a very good product, but it needs a better understanding of file references.
Pros and Cons
- "It provides a graphical view of any vulnerabilities."
- "It could be improved with more reporting of false positives and the understanding of file references."
What is most valuable?
It provides a graphical view of any vulnerabilities.
How has it helped my organization?
I have used it as a consultant.
What needs improvement?
It could be improved with more reporting of false positives and the understanding of file references.
For how long have I used the solution?
I've used it for one year.
What was my experience with deployment of the solution?
No issues encountered.
What do I think about the stability of the solution?
No issues encountered.
What do I think about the scalability of the solution?
One needs to be sure on the number of LOC that will be run and also the size of the code.
How are customer service and technical support?
Customer Service:
8/10.
Technical Support:8/10.
Which solution did I use previously and why did I switch?
I have used Armorize codesecure.
How was the initial setup?
It's a straightforward deployment, and it learns with time.
What about the implementation team?
I implement it.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Checkmarx One Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2026
Product Categories
Application Security Tools Static Application Security Testing (SAST) Vulnerability Management Container Security Static Code Analysis API Security Dynamic Application Security Testing (DAST) DevSecOps Risk-Based Vulnerability Management Application Security Posture Management (ASPM) AI SecurityPopular Comparisons
SonarQube
SentinelOne Singularity Cloud Security
Microsoft Defender for Cloud
Prisma Cloud by Palo Alto Networks
GitLab
Veracode
Tanium
Qualys VMDR
Imperva Application Security Platform
TrendAI Vision One – Cloud Security
Orca Security
CrowdStrike Falcon Cloud Security
Tenable Nessus
Buyer's Guide
Download our free Checkmarx One Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What is the biggest difference between Veracode and Checkmarx?
- Checkmarx or Veracode. Which should we choose?
- What is the Biggest Difference Between Checkmarx and Fortify?
- What is the biggest difference between Checkmarx and SonarQube?
- Checkmarx vs SonarQube; SonarQube interoperability with Checkmarx or Veracode
- If you had to both encrypt and compress data during transmission, which would you do first and why?
- When evaluating Application Security, what aspect do you think is the most important to look for?
- What are the threats associated with using ‘bogus’ cybersecurity tools?
- What are the Top 5 cybersecurity trends in 2022?
- Which application security solutions include both vulnerability scans and quality checks?

















The software and application security should be the mandatory thing because most of the applications crash because of virus or harmful attacks. I was also getting the virus issue in my application then avastsupportnumber.co.uk/avast-customer-support avast customer service helped me a lot.