Early detection with custom queries has improved secure coding practices and continuously prevents critical vulnerabilities from reaching deployment
What is our primary use case?
My main use case for Checkmarx One is as a SAST product. In the Jenkins pipeline, we use it to build or confirm the Checkmarx result. Whenever we find any high or critical severity vulnerability, we break the pipeline and the product does not go to deployment. I use Checkmarx audit a lot. Whenever I find a zero-day vulnerability, we go to Checkmarx audit and write some custom query so that we can find the particular vulnerability in a particular library. Checkmarx One can give us the exact code where that library is deployed and we replace the server version and the library version.
What is most valuable?
The best features Checkmarx One offers are Checkmarx audit and the ability to write custom queries.
Checkmarx One has positively impacted our organization as we tend to find vulnerabilities very early in the development cycle. The initial scans allowed the teams to catch the vulnerabilities early. But after some time, they got used to it and started writing more secure code. In a way, it has saved a lot of time.
What needs improvement?
For Checkmarx One, I think that adding repositories and scanning impromptu code could improve it. Suppose an impromptu team comes and provides the code in a GitLab repo, there should be a quick scan button. You just link the repo and can get a result instantly.
For how long have I used the solution?
I have been using it for five years.
What do I think about the stability of the solution?
What do I think about the scalability of the solution?
Checkmarx One's scalability is good.
How are customer service and support?
We had Checkmarx office hours for customer support, and that helps a lot.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
We did not previously use a different solution. We were using the free version of Semgrep.
What was our ROI?
I'm not in a position to provide a return on investment because I'm at a lower level, such as Product Security Engineer. I don't deal with these details.
What other advice do I have?
My advice to others looking into using Checkmarx One is to go for the demo version first and see. If it fits into your pipeline, then go for it.
Checkmarx One is a great tool. SAST-wise, I love it. It's integrating into the pipeline, Checkmarx audit, and manually marking the results as false positive. After the rescan, it does not appear. So that works great.
I found this interview to be good, but I think there should be a pause button. Anyone can take a break and doesn't have to continue for the whole length. You can hit pause and continue whenever you come back.
I would rate this review an 8.
Which deployment model are you using for this solution?
On-premises
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Reselling has delivered fast secure-code training and streamlined code review for development teams
What is our primary use case?
My main use case for
Checkmarx One is that I am a reseller, and the company I work for is a reseller. What I typically do with
Checkmarx One is implementation, helping our clients or customers to meet their use cases, support, and setting up, and also using it to show the customer how to use the product.
A very recent implementation I can think of is that we had a client that wanted to do SAST, and we sold Checkmarx One to them for their SAST implementation. I was able to walk the clients through how to use the platform, how to review the source code with Checkmarx One, and most especially how to use the one-fix remediation features of Checkmarx whereby you can use the recommendation from Checkmarx One to fix the issues found in the source code.
What is most valuable?
The best features that Checkmarx One offers in my experience include its reliability in managing false positives, the integration to the CI/CD pipeline, and most importantly, the
Codebashing feature that Checkmarx One has where developers can learn how to code better and securely.
In terms of usability, Checkmarx One is one of those solutions where implementation is very straightforward and within the next few minutes after implementing Checkmarx One, you can actually start getting results almost instantly. The ease of use is there, and the usability shows that the time to generate returns on your investment is very quick.
From my point of view as a professional service or support engineer, Checkmarx One has positively impacted my organization and clients. The fact that clients come back to renew their Checkmarx One subscription means that it is valuable to them, and winning new deals means that the solution is actually meeting the need in the market. I have deployed Checkmarx One for different clients and resold Checkmarx One to different clients, and that can only be because the solution does exactly what it says it does.
After implementing Checkmarx One, the time it takes for clients to come up with secure code has been a lot faster. Once you implement Checkmarx One, you can be sure that you're getting value from the solution almost immediately because Checkmarx One also handles false positives very effectively, saving you time and saving your developers time. This has really improved the client's experience.
Additionally, Checkmarx One also has the Codebashing feature that helps to provide further knowledge to the customer on how to write secure codes, and that's a very outstanding feature of Checkmarx One.
What needs improvement?
Checkmarx One is doing a lot already, and what I would just ask is for Checkmarx One, as a company, to look into investing in RASP because being a very good SAST to DAST solution, RASP is becoming increasingly needed, especially from the reseller vendor side. If Checkmarx One could start development of a RASP platform, that would do us a lot of good.
RASP is the key one for me.
For how long have I used the solution?
I have been working in my current field for about over eight years.
What do I think about the stability of the solution?
Checkmarx One is very stable in my experience.
What do I think about the scalability of the solution?
Checkmarx One's scalability is good; it can handle growing needs or larger environments easily.
How are customer service and support?
I have relied on Checkmarx One customer support hundreds of times for several things, and Checkmarx One support is very proactive and very responsive. You can rely on them.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
I have not previously used a different solution for my clients; it has most times always been Checkmarx One.
How was the initial setup?
The ease of use is there, and the usability shows that the time to generate returns on your investment is very quick. That is something that is outstanding about Checkmarx One.
What about the implementation team?
Due to the number of years I've implemented Checkmarx One, there are rebates and discounts from the OEM which makes it a lot more profitable, and in terms of setup costs, it's already factored into the cost of the solution. The clients we are deploying for usually manage that cost. We have a good relationship with generating a license and all of that, so the experience is seamless and really good.
What was our ROI?
I have to mention again that I am not a direct user of Checkmarx One, as I implement Checkmarx One for clients and use it in clients' environments. The person who has the most accurate answer around return on investment would be the client. However, based on my interactions with the clients, I can tell that there is a return on investment because if something is not profitable and it's not helping to save costs or vulnerabilities, clients wouldn't come back to renew their license year after year. I would say that while I may not have direct metrics, I can affirm that there is a good return on investment for our clients' environments.
What's my experience with pricing, setup cost, and licensing?
Due to the number of years I've implemented Checkmarx One, there are rebates and discounts from the OEM which makes it a lot more profitable, and in terms of setup costs, it's already factored into the cost of the solution. The clients we are deploying for usually manage that cost.
Which other solutions did I evaluate?
Before choosing Checkmarx One, we did not evaluate other options for clients; in most cases, clients really wanted Checkmarx One themselves, so we just implement Checkmarx One for them.
What other advice do I have?
I would rate Checkmarx One an eight out of ten.
I choose eight out of ten because Checkmarx One is outstanding; truthfully, Checkmarx One is really, really good.
My advice for others looking into using Checkmarx One is to come to me; let me sell Checkmarx One to you. I have good experience using Checkmarx One, and I can help you set up your Checkmarx One to ensure that you're getting your return on value quickly. If you're looking for a SAST solution that would provide a return on investment and assist with source code scanning to improve your entire SDLC cycle, Checkmarx One is a tool that you can rely on. My overall rating for Checkmarx One is eight out of ten.
Which deployment model are you using for this solution?
Private Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Improves collaboration between teams and embeds security directly into development workflows
What is our primary use case?
Checkmarx One is my main tool for vulnerability detection and smooth integration over the things to be scanned. It helps me to perform smooth vulnerability detection. The primary use case that fits into my workflow is to see the vulnerabilities in
Checkmarx One dashboard, and then we can fix them. It depends on the vulnerability that we have in our code, and then we do the same until we achieve the desired latency.Checkmarx One dashboard is helpful for scanning, integration, and vulnerability detection.
What is most valuable?
I have been using Checkmarx One for three years.Checkmarx One positively impacts my organization by detecting vulnerabilities. This is a significant impact when we are going into the coding part. It helps us to do proper coding and deploy with improved performance.The features that help me in my work include CI/CD pipeline integration and code repository integration that are automated with triggering. I can also get scanning results as feedback and testing integration. It supports board security coverage. Checkmarx One is basically embedding security into the developer workflow, which means
IDE, plus source code management, plus CI/CD.Checkmarx One has significantly reduced the time we spend identifying vulnerabilities because the scan runs automatically in our CI/CD pipeline. The results are centralized in a single dashboard. This eliminates manual checking and gives us faster visibility into high-risk problems and issues. In terms of collaboration, it helps us improve coordination between development and security teams. We use a shared dashboard. The clear remediation guidelines and automated ticket creation make communication smoother and ensure both teams are aligned on priorities and timelines. Overall, the tool has helped streamline our
DevSecOps workflow.
What needs improvement?
Scanning speed optimization is an area where improvements can be made, and we can reduce false positives. The tool still requires manual verification in some cases, which could be improved. I recommend stronger integration with modern development tools. Other tools might include
GitHub Actions,
GitLab Runner, and
Azure DevOps pipelines.The improvements needed are in scan speed, reducing false positives, and more detailed remediation guidelines. These are the areas where improvements can be made.
For how long have I used the solution?
I have been using Checkmarx One for three years.
What do I think about the stability of the solution?
Checkmarx One is very stable, so we switched to it.
What do I think about the scalability of the solution?
Checkmarx One's scalability has changed my organization because the strong collaboration between the development and security team helps us to do things much faster.
How are customer service and support?
I have reached out to customer support for Checkmarx One, and they are very helpful when needed.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
We were using a combination of open scanners before Checkmarx One. We might have used
SonarQube for code quality and basic security checks, and a tool for dependency checking for vulnerability scanning. While they were very useful, they were not fully integrated. There was a significant gap between them. Overall, when moving to Checkmarx One, it helped us to unify all security checks under one tool, improve visibility, reduce manual effort, and have strong collaboration between the development and security teams.
How was the initial setup?
The setup eliminates a lot of manual coding reviews and reduces the dependency on a dedicated security analyst for the initial stage.
What was our ROI?
I have seen a return on investment with Checkmarx One as fewer employees are needed and time is also saved.Checkmarx One has definitely helped us to save time and reduce the need for additional security resources, meaning employees. One of the biggest advantages is that the scan runs automatically in our CI/CD pipeline. The results go right to the dashboard or the ticketing system. This eliminates a lot of manual coding reviews and reduces the dependency on a dedicated security analyst for the initial stage. In terms of saving time, I estimate that we have roughly saved twenty to thirty percent of the effort we spent in manual code reviews. For example, in our recent project, I reviewed around two thousand-plus lines of changes, which would naturally take a senior person three to four hours to review. Checkmarx One identified two major vulnerabilities within a second, and the developer fixed them before the migration. This automation protects us from needing additional code reviewers for peak release cycles. Overall, between the fast scanning, automation, automatic reporting, and easy detection, it has reduced manual effort enough that we did not need an extra reviewer, even as our codebase or team size grew.
What's my experience with pricing, setup cost, and licensing?
I am experiencing pricing, setup cost, and licensing for Checkmarx One. I did not see any challenges; the pricing should be reasonable, matching what we are paying for. It is actually reasonable.
Which other solutions did I evaluate?
Before choosing Checkmarx One, I evaluated other options such as
SonarQube.
What other advice do I have?
My advice to others looking into using Checkmarx One would be to look at it. Overall, the tool delivery gives the best result. If your plan is rolled out well, integrate it deeply into the workflow and fine-tune it in your environment so that you can see a better result in Checkmarx One. I would rate this review an eight out of ten.
Improves security workflows with deep pipeline integration and supports faster release cycles
What is our primary use case?
I have mostly been working in DevOps, infrastructure, cloud, and all three hyperscalers: AWS, Azure, and GCP.
I have used Checkmarx One for almost six to seven years now. Initially, when I started my career, I worked with different companies, especially in the financial domain, where I worked for financial and investment-based companies that typically had Black Duck and Checkmarx as security tools.
My main use case for Checkmarx One is that I have implemented it into my DevSecOps workflows, wherein we have Checkmarx scan enabled for our application components that were being developed by the developers. I have also been responsible for setting up Checkmarx installation, installing it into our own data centers because I have worked with many financial clients. From the infrastructure side, I have also been responsible for implementing Checkmarx into Windows and Linux servers. I have also been responsible for setting up the DevSecOps pipeline.
The most common use case that I think everyone uses with Checkmarx One is SAST, or Static Application Security Testing. We scan our source code and all the binaries to check for any injection or insecure authentication before we create any Docker builds. We also have SCA, or Software Composition Analysis, where we identify vulnerabilities and license or compliance risks in the open-source components that developers are working on. CI/CD integration is one workflow that we use, and now we are also working on AI remediation, where we provide developers with contextual explanations and secure code suggestions directly in their IDEs so they can fix their issues while coding. Additionally, policy enforcement and role-based access are also among the use cases that we currently have.
What is most valuable?
The best features Checkmarx One offers, over the past years, include broad language and technical support that Checkmarx provides, covering most languages. The framework compatibility is really great, even with monolithic applications, microservices applications, and container-based applications that are more cloud-native. All of those are compatible, and it also has IDE integration, which is more of a developer assist feature that has recently launched. We are already leveraging that. The deep pipeline integration is something that also has templates aligned with Jenkins and Jenkins plugins available. We are migrating to GitHub Actions, and that is something we are looking at too.
The dashboard and reporting part in Checkmarx One is valuable. We have a unified dashboard and reporting, which is a single pane for all the vulnerabilities and trends with respect to vulnerabilities. On the dashboard side, things could be improved a bit.
Checkmarx One has positively impacted my organization, especially in our CI/CD integration, where when we try to build any feature, they are always scanned by Checkmarx before they get released. If they do not fulfill the compliance guidelines as per the organization or the compliance and governance requests, we also have responsible AI guidelines because, at SAP, we currently have a GenAI platform, so all those requirements are fulfilled only when features are released into our team.
What needs improvement?
Checkmarx One can be improved on the side of faster scans, especially when our CI pipelines are scanning for vulnerabilities. Performance improvements can be made, but it depends on which kind of offering we are adapting for Checkmarx, whether it is cloud-based or in-house installation.
Reducing false positives is something I would suggest, but again, it depends on how Checkmarx One is set up. It already uses data flow design and has more precise vulnerability detection, which could improve developer trust.
Currently, we are consuming Checkmarx One from AWS. We have a few use cases through AWS CodePipeline, and the integration is very smooth there. We have opted for the offering available in the AWS Marketplace.
What do I think about the stability of the solution?
What do I think about the scalability of the solution?
The scalability of Checkmarx One depends on meeting the initial hardware requirements specified in Checkmarx's official documentation. Hardware performance affects scalability, but we have not faced any issues.
How are customer service and support?
We have worked with the Checkmarx support team, and the experience was very smooth. If you raise a support case with Checkmarx, it is handled smoothly. There have been instances where they agreed to join meetings and help us out. I have not faced any issues personally up to now.
How would you rate customer service and support?
What was our ROI?
I have not been able to calculate ROI as I am more focused on technical aspects as a software engineer. The management of different organizations calculates ROI, but we have observed reduced costs when using the SaaS offerings in AWS.
Which other solutions did I evaluate?
We have not used a different solution for now, although some financial clients I worked with previously used both Black Duck and Checkmarx.
What other advice do I have?
The effects on my team's productivity and risk reduction include faster release cycles. We have a dedicated security team who fetches reports from Checkmarx One and works closely with developers to resolve all the issues, leading to improvements in vulnerabilities and timelines.
The pricing, setup cost, and licensing aspects are handled by the central team in large organizations. For instance, I worked at Accenture at the start of my career and later at Infosys. I worked on projects related to financial clients but cannot reveal the client names; those matters are taken care of by clients or the central team, and I am not privy to them because I focus more on technical expertise.
Performance also depends on the infrastructure where Checkmarx One is set up. We have a few AWS use cases where Checkmarx One is offered as a SaaS, but I have also experienced in-house setups in previous organizations, leading to performance degradation, which is not the responsibility of Checkmarx One software itself. Performance also depends on the engineers or stakeholders setting it up on the appropriate hardware and infrastructure.
Checkmarx One is a global security tool for scanning vulnerabilities and ensuring compliance. Every organization has its own compliance and governance requirements, and Checkmarx One fits well. Many organizations widely use Checkmarx One, and it is compatible with all compliance and governance requirements. I would rate this product nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Brilliant Code to Cloud Application
What do you like best about the product?
Is so user friendly and it is very easy to become familiar with all the numerous features. Although I wasn't around for the implementation, I've found that it is relatively straightforward to integrate further functionality. The Scanning tools (IaC, SAST, SCA, API etc.) are all excellent and provide us with all the staus and visibility that we require. If we ever have issues that can't be resolved the Customer Support team at Checkmarx always are there to help us out.
What do you dislike about the product?
The dahsboards layour and display could be improved.
What problems is the product solving and how is that benefiting you?
Checkmarx is being used mainly for the scanning and checking of code before it makes the journey to the Cloud (AWS). We are using it to look at all the languages and frameworks that we have in our Tech/Data Stack that are incorporated into our IT Landscape. One of the main benefits is that it allows our developers to identify, detect and remediate vulnerabilities at source. It also allows them to edit queries easily and quickly.