No more typing reviews! Try our Samantha, our new voice AI agent.

Checkmarx One vs Ixia BreakingPoint comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive SummaryUpdated on Oct 8, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Checkmarx One
Ranking in Static Application Security Testing (SAST)
2nd
Average Rating
7.8
Reviews Sentiment
6.6
Number of Reviews
81
Ranking in other categories
Application Security Tools (2nd), Vulnerability Management (12th), Container Security (15th), Static Code Analysis (2nd), API Security (5th), Dynamic Application Security Testing (DAST) (2nd), DevSecOps (3rd), Risk-Based Vulnerability Management (10th), Application Security Posture Management (ASPM) (3rd), AI Security (3rd)
Ixia BreakingPoint
Ranking in Static Application Security Testing (SAST)
33rd
Average Rating
8.4
Reviews Sentiment
7.3
Number of Reviews
8
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of September 2026, in the Static Application Security Testing (SAST) category, the mindshare of Checkmarx One is 8.3%, down from 10.3% compared to the previous year. The mindshare of Ixia BreakingPoint is 0.7%, up from 0.4% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Static Application Security Testing (SAST) Mindshare Distribution
ProductMindshare (%)
Checkmarx One8.3%
Ixia BreakingPoint0.7%
Other91.0%
Static Application Security Testing (SAST)
 

Featured Reviews

Shahzad Shahzad - PeerSpot reviewer
Senior Solution Architect | L3+ Systems & Cloud Engineer | SRE Specialist at Canada Cloud Solution
Enable secure development workflows while identifying opportunities for faster scans and improved AI guidance
Checkmarx One is a very strong platform, but there are several areas where it can improve to support modern DevSecOps workflows even better. For example, better real-time developer guidance is needed. The IDE plugin should offer richer AI-powered auto-fixes similar to SNYK Code or GitHub Copilot Security, as current guidance is good but not deeply contextual for large-scale enterprise codebases. This matters because it reduces developer friction and accelerates shift-left adoption. More transparency control over the correlation engines is another need. The correlation engine is powerful but not fully transparent. Users want to understand why vulnerabilities were correlated or de-prioritized, which helps AppSec teams trust the prioritization logic. Faster SAST scan and more language coverage is needed since SAST scan can still be slow for very large mono-repos and there is limited deep support for new language frameworks like Rust and Go, along with advanced coverage for serverless-specific frameworks. This matters because large organizations want sub-minute scans in CI/CD as cloud-native ecosystems evolve fast. A strong API security module is another area for enhancement. API security scanning could be improved with active testing, API discovery, full Swagger, OpenAPI, drift detection, and schema-based fuzzing. This is important as API attacks are one of the biggest AppSec risks in 2025. Checkmarx One is strong, but I see a few areas for improvement including faster SAST scanning for large mono-repos, deeper language framework support, more transparent correlation logic, and stronger API security that includes discovery and runtime context. The IDE plugin could offer more AI-assisted fixes, and the SBOM lifecycle tracking can evolve further. Enhancing integration with SIEM and SOAR would also make enterprise adoption smoother, and these improvements would help developers and AppSec teams move faster with more accuracy.
Sai Prasad - PeerSpot reviewer
Staff QA Engineer at Virsec
Works better for testing traffic, mix profile, and enrollment scenarios than other solutions
Once, when I raised a ticket regarding a hardware or software issue, the solution's support team visited our company to discuss and find out ways to solve the problem. Sometimes, they asked us to send several photos from the back and front end to identify the issue. It was time-consuming as we were occupied with some other testing simultaneously. Instead, it would have been great if they could have visited our company and rectified the problem.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Vulnerability details is valuable."
"The SAST component was absolutely 100% stable."
"Checkmarx One has positively impacted our organization as we tend to find vulnerabilities very early in the development cycle."
"Initial setup couldn't be any easier; Checkmarx has good documentation on environment requirements, and as long as you meet those, the installation process takes maybe 30 minutes for an initial setup, perhaps a bit longer if you're adding multiple engines."
"The most valuable features are the easy to understand interface, and it 's very user-friendly."
"The main benefit to using this solution is that we find vulnerabilities in our software before the development cycle is complete."
"The administration in Checkmarx is very good."
"Most valuable features include: ease of use, dashboard. interface and the ability to report."
"It is a scalable solution."
"We use Ixia BreakingPoint for Layer 7 traffic generation. That's what we like."
"I like that we can test cloud applications."
"There is a virtual version of the product which is scaled to 100s of virtual testing blades."
"The most valuable feature of Ixia BreakingPoint is the ransomware and malware database for simulated attacks."
"The solution has many protocols and options, making it very flexible."
"What Ixia BreakingPoint brings to the end customer is the use case."
"The DDoS testing module is useful and quick to use."
 

Cons

"Meta data is always needed."
"The stability of Checkmarx could improve. We're having issues with it, and the scan reliability is sometimes impacted so we sometimes have to restart the services to allow scans out of the queue."
"Checkmarx One can be improved on the side of faster scans, especially when our CI pipelines are scanning for vulnerabilities."
"We want to have a holistic view of the portfolio-level dashboard and not just an individual technical project level."
"For Checkmarx One, I think that adding repositories and scanning impromptu code could improve it."
"As the solution becomes more complex and feature rich, it takes more time to debug and resolve problems. Feature-wise, we have no complaints, but Checkmarx becomes harder to maintain as the product becomes more complex. When I talk to support, it takes them longer to fix the problem than it used to."
"This product requires you to create your own rulesets. You have to do a lot of customization."
"The integration could improve by including, for example, DevSecOps."
"The flash GUI has room for improvement."
"Currently BPS VE's REST API was just developed (some specific functionalities are implemented) and can be improved for better control over the tool using scripts, which help in test automation."
"The production traffic simulations are not realistic enough for some types of DDoS attacks."
"The solution originally was hard to configure; I'm not sure if they've updated this to make it simpler, but if not, it's something that could be streamlined."
"The quality of the traffic generation could be improved with Ixia BreakingPoint, i.e. to get closer to being accurate in what a real user will do."
"They should improve UI mode packages for the users."
"The price could be better."
"The SSL simulation is realistic but some kinds of tests work imperfectly."
 

Pricing and Cost Advice

"The pricing is competitive and provides a lower TCO (total cost of ownership) for achieving application security."
"The solution is costly."
"The price of Checkmarx could be reduced to match their competitors, it is expensive."
"If you want more, you have to pay more. You have to pay for additional modules or functionalities."
"Be cautious of the one-year subscription date. Once it expires, your price will go up."
"It's relatively expensive."
"​Checkmarx is not a cheap scanning tool, but none of the security tools are cheap. Checkmarx is a powerful scanning tool, and it’s essential to have one of these products."
"We're using a commercial version of Checkmarx, and we paid for the solution for one year. The price is high and could be reduced."
"There is no differentiation in licenses for Breaking Point. For one license, you will get all the features. There is no complexity in that."
"The solution is expensive."
"or us, the pricing is somewhere around $12,000 a year. I'm unsure as to what new licenses now cost."
"The price of the solution is expensive."
"We have a one year subscription license for $25,000 US Dollars."
"The price is high. We pay for the license monthly."
report
Use our free recommendation engine to learn which Static Application Security Testing (SAST) solutions are best for your needs.
913,654 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
15%
Manufacturing Company
9%
Computer Software Company
7%
Outsourcing Company
7%
Manufacturing Company
14%
Outsourcing Company
13%
Comms Service Provider
12%
Construction Company
9%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business32
Midsize Enterprise9
Large Enterprise46
By reviewers
Company SizeCount
Small Business7
Large Enterprise3
 

Questions from the Community

What alternatives are there for Fortify WebInspect and Fortify SCA?
I would like to recommend Checkmarx. With Checkmarx, you are able to have an all in one solution for SAST and SCA as well. Veracode is only a cloud solution. Hope this helps.
What is the biggest difference between Veracode and Checkmarx?
According to my experience of using both the tools in different organizations Veracode is a Cloud-native, managed AppSec platform with strong focus on ease of use, it is SaaS delivery, and provide...
What is your experience regarding pricing and costs for Checkmarx?
Checkmarx One is a premium solution, so budget accordingly. Make sure you understand how licensing scales with additional applications and users. I advise negotiating multi-year contracts or bundle...
Ask a question
Earn 20 points
 

Overview

 

Sample Customers

YIT, Salesforce, Coca-Cola, SAP, U.S. Army, Liveperson, Playtech Case Study: Liveperson Implements Innovative Secure SDLC
Corsa Technology
Find out what your peers are saying about Checkmarx One vs. Ixia BreakingPoint and other solutions. Updated: September 2026.
913,654 professionals have used our research since 2012.