

Checkmarx One and Tenable Vulnerability Management are key players in the vulnerability scanning and management market. Checkmarx One holds the advantage in advanced code scanning capabilities and remediation guidance, while Tenable's strength lies in its broader vulnerability management tools and integration capabilities.
Features: Checkmarx One offers advanced code scanning without code compilation, supporting various languages and providing comprehensive analysis tools. It identifies vulnerabilities and offers remediation guidance and syntax correction, which helps developers enhance secure coding skills. Tenable Vulnerability Management provides robust vulnerability scanning with strong integration capabilities with third-party solutions, making it competitive in managing a wide range of vulnerabilities.
Room for Improvement: Checkmarx One needs to address false positives, expand language support, and develop a more flexible and affordable licensing model. Tenable Vulnerability Management could benefit from better integration, intuitive dashboards, and expanded reporting capabilities.
Ease of Deployment and Customer Service: Checkmarx One supports multiple deployment options, including on-premises, hybrid, and public cloud, allowing flexibility for various infrastructures. While its technical support is positive, response times can be slow. Tenable Vulnerability Management offers diverse deployment options favoring public cloud availability, with customer service praised for promptness and knowledge, though improvements in response time and detailed support could enhance the experience.
Pricing and ROI: Checkmarx One is perceived as expensive due to its complex licensing model, but it promises a good ROI by reducing vulnerabilities early in development, minimizing troubleshooting costs. Tenable Vulnerability Management's pricing is seen as high, especially for SMBs, but offers reasonable ROI through comprehensive security coverage, with both needing more transparent and flexible pricing structures.
Overall, between the fast scanning, automation, automatic reporting, and easy detection, it has reduced manual effort enough that we did not need an extra reviewer, even as our codebase or team size grew.
Based on my interactions with the clients, I can tell that there is a return on investment because if something is not profitable and it's not helping to save costs or vulnerabilities, clients wouldn't come back to renew their license year after year.
If you raise a support case with Checkmarx, it is handled smoothly.
The customer support team is amazing and they provide on-phone call, email support, and on-website support.
I have relied on Checkmarx One customer support hundreds of times for several things, and Checkmarx One support is very proactive and very responsive.
It needs improvement in response time and addressing feature requests promptly.
The technical support of Tenable Vulnerability Management is available 24/7, and whenever we require support, we can get it within five minutes.
We had used Tenable's expert support services in order to make sure that we run Tenable Vulnerability Management on a continuous basis and are able to utilize their services.
Approximately four billion lines of code are being scanned monthly.
Since it is cloud-based, the infrastructure and PaaS, IaaS, and SaaS are taken care of by the cloud marketplace.
Checkmarx One's scalability has changed my organization because the strong collaboration between the development and security team helps us to do things much faster.
They can seamlessly scale the number of endpoints from 100 to 1,000,000 in a day.
Tenable Vulnerability Management is highly scalable.
With the growing needs of our company, Tenable Vulnerability Management is able to safely adapt.
I would rate the stability of this solution a nine on a scale of 1 to 10 where one is low stability and 10 is high.
Checkmarx One is often down when the cloud provider experiences issues.
I have faced no stability issues with Tenable.
The stability is commendable, and I would rate Tenable ten out of ten.
The stability of Tenable Vulnerability Management is highly reliable.
Integration into the IDE being used would be beneficial so that code does not need to be uploaded to the website and an IDE-friendly report could be generated.
It could suggest how the code base is written and automatically populate the source code with three different solution options to choose from.
If you can improve the speed optimization, it takes around 30 to 40 minutes for checking a build. If you can make it within five minutes or 10 minutes, that would be great.
They should also accelerate the process of implementing new features upon request.
I would suggest HP WebInspect as a better option than Tenable.io.
Tenable Vulnerability Management is not very effective for real-time risk prioritization for our organization's security strategy.
For a small team under 50 developers, normal expenses come under 30 to 60K.
Due to the number of years I've implemented Checkmarx One, there are rebates and discounts from the OEM which makes it a lot more profitable.
The pricing should be reasonable, matching what we are paying for.
Tenable charges around $40 per device, while Rapid7 costs $10 to $15 per device.
I would not say very expensive for Tenable Vulnerability Management; it is not prohibitive, but at the same time, there are some other tools in the marketplace which are offering the same kind of services that Tenable offers, the same kind of features that Tenable has offered at a lesser cost.
Since replacing the previous tool, SAST and SCA scans are conducted in a couple of minutes instead of hours or days.
The best features Checkmarx One offers, over the past years, include broad language and technical support that Checkmarx provides, covering most languages.
Checkmarx One has positively impacted our organization as we tend to find vulnerabilities very early in the development cycle.
Tenable enables vulnerability management through potential AI integration that consolidates efforts and resolves multiple vulnerabilities simultaneously.
The main benefit of integration with Tenable Vulnerability Management is that there will be no lack of missing vulnerabilities when it comes to the patching environment.
The best features of Tenable Vulnerability Management are flexibility, breadth and scope, and the fact that their current vulnerabilities come out, and they have tests for them within a day or two.
| Product | Mindshare (%) |
|---|---|
| Tenable Vulnerability Management | 2.9% |
| Checkmarx One | 1.6% |
| Other | 95.5% |


| Company Size | Count |
|---|---|
| Small Business | 32 |
| Midsize Enterprise | 9 |
| Large Enterprise | 46 |
| Company Size | Count |
|---|---|
| Small Business | 20 |
| Midsize Enterprise | 3 |
| Large Enterprise | 21 |
Checkmarx One delivers robust security through seamless integration with SCM and CI/CD tools, ensuring reliable SAST and SCA. Primarily used by organizations for vulnerability detection, it supports cloud and on-premises deployment to enhance secure coding practices.
Checkmarx One provides organizations with comprehensive tools for secure software development, integrating effectively with CI/CD pipelines to scan thousands of applications. Its capabilities extend to identifying vulnerabilities in both code bases and third-party software. Enhancing workflow by supporting SCM solutions, it assists in maintaining secure coding standards and compliance. While excelling in various areas, it requires improvements in scan speed, reduction of false positives, and broader platform integration, particularly for COBOL and Swift. Its pricing model is noted as high, and demand exists for better tutorials and documentation.
What are the key features of Checkmarx One?Industries implement Checkmarx One for secure coding compliance and vulnerability management across varying environments, choosing between cloud and on-premises deployment based on requirements. Its extensive language support and integration with DevSecOps practices make it a popular choice for organizations aiming to enhance software security.
Tenable Vulnerability Management offers efficient scanning, reporting, and integration capabilities. It supports extensive visibility and risk management for diverse environments while providing a user-friendly experience with strong cloud capabilities and container scanning.
Tenable Vulnerability Management is crucial for vulnerability assessment and managing security across network infrastructures. It effectively handles cloud and on-premises scans, identifying risks and enhancing cybersecurity measures with detailed reports. With features like automated scanning and risk prioritization, users manage vulnerabilities efficiently. Despite its strong points, improvements in pricing, navigation, and customization are desired, alongside better integration and AI-driven detection.
What are the most important features of Tenable Vulnerability Management?In industries like finance, healthcare, and education, Tenable Vulnerability Management supports robust cybersecurity measures. Organizations utilize it for scanning IT infrastructures, conducting cloud assessments, and performing endpoint analysis to mitigate threats in critical environments.
We monitor all Vulnerability Management reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.