Listing Thumbnail

    Checkmarx One

     Info
    Sold by: Checkmarx 
    Deployed on AWS
    Checkmarx One helps you deliver secure software faster with an integrated Application Security Testing platform deployed as a service. A single event, like a code commit or build stage, can trigger scans of your source code, dependencies, and IaC templates, with results aggregated in one place.

    Overview

    Checkmarx One is an integrated Application Security Testing (AST) platform delivered by Checkmarx, an AWS Advanced Tier partner with Security and DevOps Competencies. We're a global leader in software security solutions, trusted by 1,700+ organizations and consistently recognized by Gartner as a Leader in AST. Checkmarx One delivers three essential AST services on a platform that's easy to integrate into your existing dev tools: Static application security testing: Checkmarx One is a flexible, accurate solution able to identify hundreds of vulnerabilities and weaknesses in custom code, with support for 25+ languages and frameworks. Software composition analysis: CxSCA enables you to mitigate risks in open source software and third-party libraries. Users can identify and prioritize open source vulnerabilities, take inventory of open source components and dependencies in use, and evaluate the risk of open source licenses. Infrastructure as code analysis: KICS detects security misconfigurations in IaC templates, helping prevent errors such as open storage buckets, insecure databases, and excessive privileges. Checkmarx One is easy to integrate: one event can trigger all scan types for your project, and scan results are aggregated, giving you fast triage of your project's security posture. Checkmarx One Developer Assist is an advanced security agent that delivers real-time context-aware prevention, remediation, and guidance to developers from the IDE. It empowers developers to identify risks in their code in realtime and harness the power of AI to remediate the risks on the spot. This feature is initially being released as part of the Checkmarx One plugin for VS Code, Cursor and Windsurf IDEs.

    CXONE ASSIST comprises two main elements: Realtime Scanning - Identify vulnerabilities in realtime during IDE development of both human-generated and AI-generated code. Our super-fast scanners run in the background whenever you edit a relevant file. Our scanners identify vulnerabilities and unmasked secrets in your code. We also identify vulnerable or malicious container images and open source packages used in your project. Results are marked as Problems which are highlighted in the code and annotated with identifying icons. Agentic-AI Remediation-Initiate an Agentic-AI session to receive remediation suggestions. Checkmarx feeds all relevant info to the AI agent which accesses our MCP server to gather data from our proprietary databases and customized AI models. The AI assistant then uses this data to generate remediated code for your project. You can accept the suggested changes or you can chat with the AI agent to learn more about the vulnerability and fine-tune the remediation suggestion.

    If you're an AWS customer interested in Checkmarx One and wish to purchase over AWS Marketplace in a different quantity or configuration, visit http://www.checkmarx.com/contact-us-aws  IMPORTANT INFORMATION ABOUT PRODUCTS AND SERVICES.

    1. Please note that add-ons be purchased only when the base product is purchased.
    2. Description of Base product: Checkmarx One Start with SAST. Description of available Add-ons: CxOne Start with SAST NG-API Security Addon, CxOne Start with SAST NG-IaC (KICS) Add on, Checkmarx One Start with SAST NG- AI Add on
    3. Description of Base product: Checkmarx One Essential Description of available Add-ons: CxOne Essential-Containers Add on, Cx One Essential-Malicious Packages Add on, Cx One Essential-IaC (KICS) Add on, CxOne Essential-AI Protection Add on
    4. Description of Base product: Checkmarx One Professional Description of available Add-ons: Checkmarx One Professional - IaC (KICS) Add on, Checkmarx One Professional - Enterprise Secrets Add on, Checkmarx One Professional - AI Protection Add on
    5. Checkmarx One Codebashing is available both as standalone and add-on with Base products mentioned above.
    6. CxOne Premium Service Package is available @ 20% of SaaS subscription fee. Checkmarx One Premium Service package fee shall be calculated as higher of: a) 20% of SaaS subscription fee OR b) USD 10,000 in case of 1 year term / USD 30,000 for 3 year term.
    7. Cx-SCS Threat API Malicious (per package) : Minimum quantity is 2 (two) and listed price is for 2 (two) units. SCS Threat API for Malicious OSS Packages Threat Information only (limited to 10,000 packages lookup per month). Each version/sub-version of the same package is considered a unique package.
    8. Minimum deal size shall be USD 30,000 for a one year term and USD 90,000 for three year term. Minimum deal size excludes Checkmarx One Premium Service Package and Checkmarx One PS days.
    9. Checkmarx reserves the right to revise prices periodically.
    10. Prices exclude applicable VAT/GST and WHT, if any.
    11. Refund Policy: no Refunds. Please reach out to aws-marketplace@checkmarx.com  for further information about the add-ons available under various base products.

    Highlights

    • FIND THREATS AND SAVE TIME : Identify open source risks. Get severity metrics and remediation guidance. Identify potential license and compliance issues. See which libraries are adding to maintenance burdens. Get risk reports or extract data via API.
    • SPOT INSECURE CODE EARLIER: Our industry-leading source code analysis covers a wide range of languages. Checkmarx One finds vulnerabilities faster by scanning uncompiled code and only re-scanning new or modified code.
    • Prevent misconfigurations from reaching production: Scan your IaC templates for valid but insecure configurations before deployment to prevent catastrophic security misconfigurations.

    Details

    Delivery method

    Deployed on AWS

    Unlock automation with AI agent solutions

    Fast-track AI initiatives with agents, tools, and solutions from AWS Partners.
    AI Agents

    Features and programs

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Checkmarx One

     Info
    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (17)

     Info
    Dimension
    Description
    Cost/12 months
    CxOne Start with SAST NG
    Checkmarx One Start with SAST-price per license per year
    $1,035.00
    CxOne API Security
    CxOne Start with SAST NG-API Security Addon-price per license per year
    $276.00
    CxOne IaC (KICS)
    CxOne Start with SAST NG-IaC (KICS) Add on-price per license per year
    $240.00
    CxOne DevAssist
    Checkmarx One Start with SAST NG- DevAssist Add on-price per license per year
    $300.00
    Checkmarx One Codebashing
    Checkmarx One Codebashing
    $345.00
    CxOne Essential
    Checkmarx One Essential - price per license per year
    $1,564.00
    CxAST-CONTAINERS
    CxOne Essential-Containers Add on-price per license per year
    $240.00
    CxOne Malicious Packages
    Cx One Essential-Malicious Packages Add on-price per license per year
    $276.00
    CxAST-IAC-KICS
    Cx One Essential-IaC (KICS) Add on-price per license per year
    $240.00
    CxOne DevAssist
    CxOne Essential-DevAssist Add on-price per license per year
    $120.00

    Vendor refund policy

    1. Minimum Deal size shall be USD 30,000 for 1 year term & USD 90,000 for 3 year term, excluding Checkmarx One Premium Service Package and Checkmarx one PS days.
    2. Checkmarx One Premium Service package fee shall be calculated as higher of: a) 20% of SaaS subscription fee OR b) USD 10,000 in case of 1 year term / USD 30,000 for 3 year term.
    1. Checkmarx reserves the right to revise prices, without advance notice.
    2. Prices quoted are exclusive of VAT/GST and WHT, if applicable.
    3. No refunds.

    How can we make this page better?

    We'd like to hear your feedback and ideas on how to improve this page.
    We'd like to hear your feedback and ideas on how to improve this page.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    Vendor support

    Checkmarx technical support, online support https://support.checkmarx.com  Checkmarx One Standard Support is Included within the price of software subscription and Checkmarx One Premium Service Package available by paying 20% SaaS subscription fee.

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    10
    In Testing
    Top
    25
    In Continuous Integration and Continuous Delivery
    Top
    25
    In Cloud Governance

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    0 reviews
    Insufficient data
    Insufficient data
    Insufficient data
    Insufficient data
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Static Application Security Testing
    Comprehensive vulnerability scanning for custom code across 25+ programming languages and frameworks
    Software Composition Analysis
    Automated identification and prioritization of vulnerabilities in open source software and third-party library dependencies
    Infrastructure as Code Analysis
    Detection of security misconfigurations in infrastructure template deployments to prevent potential security risks
    Real-time IDE Security Scanning
    Background vulnerability scanning during code development with immediate identification of risks in human and AI-generated code
    AI-Powered Remediation
    Context-aware AI agent that generates code remediation suggestions using proprietary databases and customized AI models
    Application Security Scanning
    Continuous end-to-end security scanning across source control, CI/CD, registry, and cloud environments with real-time monitoring
    Vulnerability Prioritization
    Advanced threat assessment using contextual analysis of vulnerability exploitability, reachability, and business impact
    Pipeline Security Tracking
    Proprietary Pipeline Bill of Materials (PBOM) framework for tracking complete software lineage and ensuring build integrity
    Automated Remediation
    No-code workflow capabilities for automatically blocking vulnerabilities, risky code, and configuration changes
    Software Supply Chain Protection
    Comprehensive security coverage across software development lifecycle with integrated risk prevention mechanisms
    Code Security
    Integrated code security with Software Composition Analysis (SCA), Static Application Security Testing (SAST), and Infrastructure as Code (IaC) security with continuous runtime application behavior monitoring
    Cloud Security Posture Management
    Robust Cloud Service Posture Management (CSPM) and Kubernetes Security Posture Management (KSPM) with attack path analysis and visualization of interconnected infrastructure risks
    Cloud Infrastructure Entitlement Management
    Comprehensive visibility and assessment of AWS IAM users, groups, roles, policies, and machine entitlements with automatic discovery and excessive permission identification
    Behavioral Analytics
    Continuous monitoring of AWS workloads using advanced anomaly detection techniques with comparison of past and present states to identify unusual behaviors
    Threat Correlation
    Automated correlation of multiple security alerts into high-confidence composite alerts using behavioral analytics, anomaly detection, and threat intelligence from AWS CloudTrail and GuardDuty

    Contract

     Info
    Standard contract
    No
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4.5
    1 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    0%
    100%
    0%
    0%
    0%
    1 AWS reviews
    |
    47 external reviews
    Star ratings include only reviews from verified AWS customers. External reviews can also include a star rating, but star ratings from external reviews are not averaged in with the AWS customer star ratings.
    Rohit Kaushish

    Automated code validation has saved our team over 16 hours weekly and improved security checks

    Reviewed on Nov 18, 2025
    Review provided by PeerSpot

    What is our primary use case?

    My main case to use Checkmarx One  was to streamline validation and quality check across our code, and we are quickly verifying our PCI compliances, identifying inconsistencies, and ensuring that our output meets the required standard before we move on to the next stage.
    The platform is integrated into our CI/CD pipelines (Bitbucket /Jenkins ), allowing scans to run automatically on every commit or pull request. This ensures vulnerabilities are detected early and fixes are incorporated before code reaches production.

    How has it helped my organization?

    Checkmarx One has significantly improved our organization’s security posture. We now catch vulnerabilities much earlier in the development cycle, which has reduced remediation time and lowered the number of issues reaching production. This has also improved developer efficiency and given us greater confidence in our releases.
    Checkmarx One has improved visibility across our codebases. We now have centralized dashboards and consistent scanning across projects, which makes governance and compliance much easier to manage.

    What is most valuable?

    Checkmarx One  has become an essential part of our current project because in every process of code it checks what type of errors are there, what type of code quality is there, these types of checks and visibility to developers really help and make our project easy to work.

    I appreciate most features of Checkmarx One including automated checks, code quality checks, checking the rule-based validation, what type of code coverage is there, whether it's covering or not, whether it's applied or not, these types of issues and triage, what type of triage we will get before merging the code in our production. Logging functionality is also very good, as it will tell if this code is flexible for your current scenario or not. Alert and notification to each customer and each developer is also a big task here. These are the good features, audit and traceability we can say.

    Checkmarx One has had a positive impact on our organization, especially in terms of productivity. When we went with manual checks, we spent a lot of time, but automated checks by using Checkmarx One make fixing our issues easier, faster and save our team's time. We save a lot of time here.

    By using the automated testing in Checkmarx One, we have saved around one or two days in a full week of our team because we have a lot of code to do with seven markets. In this market, we have to daily push around 20 to 30 tickets per day. This saves us a lot of time, mostly around 16 hours a week.

    What needs improvement?

    Checkmarx One is doing great, but there is a need for UI improvement so we can get the exact error over there on our Bitbucket  itself. Additionally, if you can improve the speed optimization, it takes around 30 to 40 minutes for checking a build. If you can make it within five minutes or 10 minutes, that would be great. This feature is something I want from your side.

    Integration with Checkmarx One is easy, so it is not complicated. However, reporting is complicated because it takes a lot of time to report the errors and it makes around 40 to 50 minutes for a build. After we push the code, it will give around 40 to 50 minutes. Therefore, you need to work on the reporting part and apart from that, it is doing a great job here.

    You are doing a great job in checking the code quality, bug fixing, vulnerabilities, and security aspects. However, one thing you have to improve is your reporting time should be less. It takes around 40 to 50 minutes, so you need to reduce it to within 10 to 20 minutes.

    For how long have I used the solution?

    In my current project, I am using Checkmarx One and from the last four years, we have been working with Checkmarx.

    What do I think about the stability of the solution?

    The solution has been very stable. Scans run reliably, the platform is consistently available, and we haven’t experienced unexpected downtime. It’s dependable enough to integrate directly into our CI/CD workflow.

    What do I think about the scalability of the solution?

    Overall, scalability has been solid. The platform supports our growing workloads and additional applications without requiring major configuration changes. A bit of tuning was needed in the beginning, but after that it has been smooth.

    How are customer service and support?

    Customer support has been excellent. The team is responsive, knowledgeable, and quick to assist when issues arise. Whether it’s configuration questions or troubleshooting, they consistently provide clear and actionable guidance.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    Before Checkmarx One, we relied on a mix of manual code reviews and basic scanning tools. As our codebase grew, this approach wasn’t scalable or consistent. We switched to Checkmarx One because it offered deeper coverage, automation, and a unified platform for SAST , SCA , and other security scans

    How was the initial setup?

    Setup was generally easy, but it required coordination between development and security teams to ensure SAST , SCA , and pipeline integrations were properly configured. Once aligned, the rollout was smooth.

    What about the implementation team?

    We implemented Checkmarx One using our in-house team. The setup was manageable with the documentation provided, and we were able to configure the platform without needing external assistance.

    What was our ROI?

    Our ROI has been strong. We’ve reduced manual code review time by around 25–30%, allowing developers to focus more on feature delivery. The automation and early detection of vulnerabilities have noticeably lowered rework costs.

    What's my experience with pricing, setup cost, and licensing?

    Checkmarx One is a premium solution, so budget accordingly. Make  sure you understand how licensing scales with additional applications and users. I advise negotiating multi-year contracts or bundles, as these can reduce costs and simplify licensing.

    Which other solutions did I evaluate?

    Yes, we evaluated a few other application security platforms, but Checkmarx One provided the best combination of accuracy, ease of integration, and centralized scanning capabilities

    What other advice do I have?

    I find this interview great, and there is nothing that I think should change for the future. You are doing a great job here.

    If someone is looking for code quality, then my advice is to use Checkmarx One. This is the best solution to provide efficiency in your work, code compliance, security, and scalability in your code. You can also save a lot of time by using Checkmarx One to scan your code. I would recommend you, if you are looking to save time checking the code, then Checkmarx One is the best solution for you. I would rate this product a 9 out of 10.

    Syed Hasan

    Partner experiences excellent technical support and seamless initial setup

    Reviewed on Jun 02, 2025
    Review provided by PeerSpot

    What is our primary use case?

    I am a partner of the vendor, and I can say that one of the clients with whom I am working has bought the licenses for Checkmarx One , and we are actually doing the security scans of their whole application base, code base, and everything.

    Whatever solutions were provided by, or suggested by, Checkmarx One , we are going through them and implementing them. Some were valid and some were not applicable for us based on the scenario. That is the work experience I have working on Checkmarx One.

    What is most valuable?

    My experience with the initial setup of Checkmarx One is straightforward; it is not complex compared to other tools that I have tried.

    Checkmarx One was deployed in a hybrid manner because they were scanning their production-based systems and then fixing the code base. It was hybrid, maybe on-premises with them, not completely on cloud.

    My clients for Checkmarx One are usually enterprise-sized businesses. I have seen a return on investment from Checkmarx One.

    What needs improvement?

    In my opinion, if we are able to extract or show the report, and because everything is going towards agent tech and GenAI, it would be beneficial if it could get integrated with our code base and do the fix automatically.

    It could suggest how the code base is written and automatically populate the source code with three different solution options to choose from. This would be really helpful.

    What do I think about the stability of the solution?

    I would rate the stability of this solution a nine on a scale of 1 to 10 where one is low stability and 10 is high.

    What do I think about the scalability of the solution?

    I would rate the scalability of this solution an eight on a scale of 1 to 10, where one is low scalability and 10 is high scalability.

    How are customer service and support?

    I would rate technical support a nine from 1 to 10, where one is low quality of their technical support and 10 is high quality.

    What was our ROI?

    I have seen a return on investment from Checkmarx One.

    What other advice do I have?

    The price of Checkmarx One should be fine as of now.

    I would rate this solution a nine overall, from 1 to 10, where one is the worst solution and 10 is the best solution.

    Retail

    Brilliant Code to Cloud Application

    Reviewed on Dec 16, 2024
    Review provided by G2
    What do you like best about the product?
    Is so user friendly and it is very easy to become familiar with all the numerous features. Although I wasn't around for the implementation, I've found that it is relatively straightforward to integrate further functionality. The Scanning tools (IaC, SAST, SCA, API etc.) are all excellent and provide us with all the staus and visibility that we require. If we ever have issues that can't be resolved the Customer Support team at Checkmarx always are there to help us out.
    What do you dislike about the product?
    The dahsboards layour and display could be improved.
    What problems is the product solving and how is that benefiting you?
    Checkmarx is being used mainly for the scanning and checking of code before it makes the journey to the Cloud (AWS). We are using it to look at all the languages and frameworks that we have in our Tech/Data Stack that are incorporated into our IT Landscape. One of the main benefits is that it allows our developers to identify, detect and remediate vulnerabilities at source. It also allows them to edit queries easily and quickly.
    Cuneyt KALPAKOGLU Phd.

    Enhanced security with robust feature set for comprehensive protection

    Reviewed on Oct 07, 2024
    Review from a verified AWS customer

    What is our primary use case?

    I am representing Checkmarx as a reseller. I work with both the cloud and on-premises versions. I have been working with Checkmarx for more than twelve years.

    How has it helped my organization?

    Checkmarx is a must-use product due to the increasing number of cyber-attacks nowadays. The product's quality and performance justify its pricing, making it a worthwhile investment.

    What is most valuable?

    Checkmarx offers many valuable features, including Static Application Security Testing (SAST ), Software Composition Analysis (SCA) , Infrastructure as Code  (IAC), Supply Chain Security, and API Security .

    What needs improvement?

    The Dynamic Application Security Testing (DAST)  feature should be better. The technical support service could also improve in terms of their response time.

    For how long have I used the solution?

    I have been working with Checkmarx since the early days of Checkmarx, which is more than 12 years.

    What do I think about the stability of the solution?

    I would rate the stability of Checkmarx at nine out of ten.

    What do I think about the scalability of the solution?

    Checkmarx is scalable, and I would rate its scalability at nine out of ten.

    How are customer service and support?

    The customer service and support should be quicker from my point of view. I would rate them eight out of ten.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    I have been working with Checkmarx for over 12 years without switching to a competitor due to Checkmarx being the best product in the market.

    How was the initial setup?

    The initial setup is straightforward, especially with the cloud version where no deployment is needed. The on-premises version requires some time and depends on the customer's environment.

    What about the implementation team?

    In typical circumstances, one senior engineer is enough for implementation, but in special cases, maybe two engineers are needed.

    What was our ROI?

    Checkmarx is cost-effective. It is a must-use product in today's cyber security environment.

    What's my experience with pricing, setup cost, and licensing?

    The pricing is relatively expensive due to the product's quality and performance, but it is worth it.

    Which other solutions did I evaluate?

    I chose Checkmarx over competitors due to ethical considerations and its superior functionality.

    What other advice do I have?

    Checkmarx is plug-and-play and the best product in the market at the moment, as evidenced by reports such as Gartner's.

    I'd rate the solution nine out of ten.

    FernandoCarlos

    Integrated security for streamlined code scanning with scope for dynamic and API improvements

    Reviewed on Sep 13, 2024
    Review provided by PeerSpot

    What is our primary use case?

    We have integrated Checkmarx into all the company's development pipelines. We use it to scan more than 4,000 repositories and around 25,000 pipelines.

    The integration is particularly useful as it works directly with several common SCM solutions in the market, such as GitHub  and Bitbucket , and with CI/CD tools like Jenkins  and GoCD . This allows us to register repositories quickly and scan code efficiently in our development process.

    How has it helped my organization?

    Checkmarx helps developers improve the maturity of their coding practices and brings a security mindset to development teams, product managers, and business areas.

    It aids in identifying and mitigating vulnerabilities early in the development cycle, enhancing the overall security posture of the organization.

    What is most valuable?

    The most valuable features of Checkmarx are its integration with multiple SCM solutions and CICD tools, its ability to scale according to user licenses, and the quick scanning process. Specifically, the Static Application Security Test (SAST ) and Software Composition Analysis (SCA)  are highly established and useful in identifying numerous vulnerabilities.

    What needs improvement?

    Checkmarx needs improvement in its Dynamic Application Security Testing (DAST)  and API security features. The DAST solution uses the OWASP Zap  engine, which is less powerful compared to other market solutions like Fortify's WebInspect .

    Additionally, the API security solution does not provide comprehensive results, and the secret scanning feature also needs enhancement. Furthermore, the container security and infrastructure as code scanning features are not mature enough and require significant improvements.

    For how long have I used the solution?

    I have been working with Checkmarx for about two years.

    What do I think about the scalability of the solution?

    Checkmarx scales very well according to the user licenses. The solution supports concurrent scans based on the number of committers, which is a significant improvement over the previous CXSAST solution that only supported a limited number of simultaneous scans.

    The scans are quick, but the time taken can vary based on the amount of code and the frequency of scans.

    How are customer service and support?

    The technical support from the vendor is generally good, rated at about 8.5 out of ten. Checkmarx utilizes partners as integrators who offer enterprise support, including a dedicated technical account manager. The support from Checkmarx's team has improved, offering a four-hour SLA and 24/7 availability.

    How would you rate customer service and support?

    Positive

    How was the initial setup?

    The initial setup is simple and quick due to its SaaS nature. It involves setting up the tenant, registering applications, and integrating with the company's SSO . The integration with CI/CD tools takes a bit more time and effort.

    What about the implementation team?

    The implementation is typically done with the help of a partner who acts as an integrator and offers enterprise support. This includes the allocation of a dedicated professional as a technical account manager or customer success manager.

    What was our ROI?

    Checkmarx provides a good return on investment by preventing breaches and vulnerabilities that could be much more costly. It adds significant value by improving the security practices and mindset across the development lifecycle.

    What's my experience with pricing, setup cost, and licensing?

    Checkmarx is not a cheap solution. For around 250 users or committers, the cost is approximately $500,000. However, the investment is justified considering the potential costs of security breaches and the benefits of improved security practices.

    What other advice do I have?

    To achieve better results, consider performing both native integration in the SCM tool and integration using the CI/CD solution. This helps gain visibility into the deployment stages and ensures comprehensive code scanning. I'd rate the solution eight out of ten.

    View all reviews