

Fortify Software Security Center and Checkmarx One are two prominent solutions competing in application security. Checkmarx One appears to have the upper hand due to its comprehensive features and ease of use.
Features: Fortify offers comprehensive vulnerability coverage, numerous integration options, and strong support. Checkmarx One is known for its intuitive functionality, robust scanning capabilities, and support for multiple programming languages.
Room for Improvement: Fortify users point out the need for improved reporting, faster scanning speeds, and enhanced analytics. Checkmarx One could benefit from better scan accuracy, a more user-friendly installation, and further optimization of its accuracy.
Ease of Deployment and Customer Service: Fortify's deployment is stable but has a steep learning curve. Customer service is proactive yet needs faster response times. Checkmarx One offers a smoother deployment and consistent customer support.
Pricing and ROI: Fortify has a manageable initial setup cost, though its ROI is questioned due to optimization time. Checkmarx One is more expensive but justifies its ROI with streamlined processes and faster integration.
| Product | Mindshare (%) |
|---|---|
| Checkmarx One | 9.7% |
| Fortify Software Security Center | 1.5% |
| Other | 88.8% |


| Company Size | Count |
|---|---|
| Small Business | 32 |
| Midsize Enterprise | 9 |
| Large Enterprise | 46 |
| Company Size | Count |
|---|---|
| Small Business | 4 |
| Midsize Enterprise | 1 |
| Large Enterprise | 3 |
Checkmarx One delivers robust security through seamless integration with SCM and CI/CD tools, ensuring reliable SAST and SCA. Primarily used by organizations for vulnerability detection, it supports cloud and on-premises deployment to enhance secure coding practices.
Checkmarx One provides organizations with comprehensive tools for secure software development, integrating effectively with CI/CD pipelines to scan thousands of applications. Its capabilities extend to identifying vulnerabilities in both code bases and third-party software. Enhancing workflow by supporting SCM solutions, it assists in maintaining secure coding standards and compliance. While excelling in various areas, it requires improvements in scan speed, reduction of false positives, and broader platform integration, particularly for COBOL and Swift. Its pricing model is noted as high, and demand exists for better tutorials and documentation.
What are the key features of Checkmarx One?Industries implement Checkmarx One for secure coding compliance and vulnerability management across varying environments, choosing between cloud and on-premises deployment based on requirements. Its extensive language support and integration with DevSecOps practices make it a popular choice for organizations aiming to enhance software security.
Fortify Software Security Center offers comprehensive application security through a centralized console that integrates static and dynamic analysis, making it essential for organizations focused on robust security operations.
Fortify Software Security Center delivers extensive capabilities that facilitate application security testing, code audits, and bug fixes. Its centralized console enhances governance and control, while its interoperability with tools like Kiuwan and Azure strengthens its functionality. The dashboard's intuitive data customization, along with the ability to store and report data on-premises, further complements its integration capabilities. Although improvements in dataset aggregation, integration with tools like Jira, and resolution of false positives are required, its ability to scan and analyze source code to identify security violations is acknowledged.
What are the key features of Fortify Software Security Center?Fortify Software Security Center is adopted in software-driven industries for its robust application security capabilities. Users in technology sectors rely on its static code analysis for auditing and security testing. Its on-premises deployment model and integration with platforms like Azure make it ideal for storing and reporting data, providing customization that aligns with industry standards.
We monitor all Static Application Security Testing (SAST) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.