Cx gives you the ability to push SAST down much lower in the SDLC process. With the use of multiple IDE plugins and the ability to do "incremental" scanning, a scan of your latest code does not bog down your machine as it is offloaded.
Senior Software Security Analyst at a financial services firm with 1,001-5,000 employees
It allows for SAST scanning of uncompiled code. More API functionality should be added.
Pros and Cons
- "It allows for SAST scanning of uncompiled code. Further, it natively integrates with all key repos formats (Git, TFS, SVN, Perforce, etc)."
- "Meta data is always needed."
How has it helped my organization?
What is most valuable?
It allows for SAST scanning of uncompiled code. Further, it natively integrates with all key repos formats (Git, TFS, SVN, Perforce, etc).
What needs improvement?
Meta data is always needed. More tutorials/videos for developers to fix their vulnerabilities is nice. Although the API is useful, I would like to see more functionality added.
What do I think about the stability of the solution?
I've had to restart services/bounce the VM on two rare occasions.
Buyer's Guide
Checkmarx One
June 2025

Learn what your peers think about Checkmarx One. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
857,028 professionals have used our research since 2012.
What do I think about the scalability of the solution?
It scales very easy.
How are customer service and support?
Customer Service:
Customer service is good. Engineers have been quick to get back to me regarding issues and custom work that I have performed.
Technical Support:
Technical support is very knowledgeable.
How was the initial setup?
Initial setup couldn't be any easier. Cx has good documentation on environment requirements. As long as you meet those, the installation process takes maybe 30 minutes for an initial setup; perhaps a bit longer if you're adding multiple engines.
What about the implementation team?
An in-house team implemented it.
What's my experience with pricing, setup cost, and licensing?
Everything is negotiable. Checkmarx approached our dealings in good faith and clearly wanted to be around for awhile. It is much more inexpensive than some alternatives.
Which other solutions did I evaluate?
Before choosing, we also evaluated Fortify, IBM Appscan, Veracode, etc.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Full Stack Developer at a tech services company with 51-200 employees
It helps with vulnerability scanning of codes to prevent vulnerability of our applications.
What is most valuable?
It provides us with code analysis.
How has it helped my organization?
It helps with vulnerability scanning of codes to prevent vulnerability of our applications.
For how long have I used the solution?
I've used it for one year.
What was my experience with deployment of the solution?
No issues encountered.
Which solution did I use previously and why did I switch?
Straight forward. Easy to follow steps.
I worked for an IT security firm and it was quite easy to setup the product for demo purposes virtually and even physically on the client premises
How was the initial setup?
It was straightforward, as it has easy to follow steps.
I worked for an IT security firm and it was quite easy to setup the product for demo purposes virtually and even physically on the client premises.
What's my experience with pricing, setup cost, and licensing?
The license is fairly costly but worth the investment.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partners
Buyer's Guide
Checkmarx One
June 2025

Learn what your peers think about Checkmarx One. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
857,028 professionals have used our research since 2012.
Co-Founder, CTO at a tech services company with 51-200 employees
It allows us to verify the dev department's code in order to minimize security holes, but it needs better role management.
What is most valuable?
They're all as valuable as each other.
How has it helped my organization?
We have used this product to verify the dev department's code in order to minimize security holes.
What needs improvement?
It needs better role management.
For how long have I used the solution?
I've used it for three years.
What was my experience with deployment of the solution?
No issues encountered.
What do I think about the stability of the solution?
No issues encountered.
What do I think about the scalability of the solution?
No issues encountered.
How are customer service and technical support?
Customer Service:
It's very good.
Technical Support:It's very good.
Which solution did I use previously and why did I switch?
This is the only solution I have used.
How was the initial setup?
Very straightforward.
What about the implementation team?
I implemented it myself.
What's my experience with pricing, setup cost, and licensing?
Licensing is expensive per X amount of lines in the code.
Which other solutions did I evaluate?
No other options were evaluated.
Disclosure: My company has a business relationship with this vendor other than being a customer: We are providing leads to Checkmarx.
Going for another POC with Checkmarx... This time implementing it with Jira, to open an automatic flow for better mitigation SLA and for Infosec visibility
Cyber-Ark Consultant at a tech services company with 51-200 employees
It is a very good product, but it needs a better understanding of file references.
What is most valuable?
It provides a graphical view of any vulnerabilities.
How has it helped my organization?
I have used it as a consultant.
What needs improvement?
It could be improved with more reporting of false positives and the understanding of file references.
For how long have I used the solution?
I've used it for one year.
What was my experience with deployment of the solution?
No issues encountered.
What do I think about the stability of the solution?
No issues encountered.
What do I think about the scalability of the solution?
One needs to be sure on the number of LOC that will be run and also the size of the code.
How are customer service and technical support?
Customer Service:
8/10.
Technical Support:8/10.
Which solution did I use previously and why did I switch?
I have used Armorize codesecure.
How was the initial setup?
It's a straightforward deployment, and it learns with time.
What about the implementation team?
I implement it.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Cyber Security Engineer at Defa3 cyber security
A stable solution that helps with dynamic application testing
Pros and Cons
- "We use the solution for dynamic application testing."
- "I would like the product to include more debugging and developed tools. It needs to also add enhancements on the coding side."
What is our primary use case?
We use the solution for dynamic application testing.
What needs improvement?
I would like the product to include more debugging and developed tools. It needs to also add enhancements on the coding side.
For how long have I used the solution?
I have been working with the product for seven months.
What do I think about the stability of the solution?
I would rate the product's stability a ten out of ten.
What do I think about the scalability of the solution?
I would rate the product's scalability a ten out of ten. My company has 15 users for the produc.
How are customer service and support?
The solution's technical support is good.
How would you rate customer service and support?
Positive
How was the initial setup?
The tool's setup is very straightforward and I would rate it a ten out of ten. The product's deployment took one to two months to complete. We required the technical and development team which consisted of four to five people to handle the deployment.
What's my experience with pricing, setup cost, and licensing?
The solution's price is high and you pay based on the number of users.
What other advice do I have?
I would rate the product a ten out of ten. The solution is the best tool for developers and organizations.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Security at a tech services company with 51-200 employees
Gives good results, but can be more user-friendly
Pros and Cons
- "Apart from software scanning, software composition scanning is valuable."
- "Its user interface could be improved and made more friendly."
What is our primary use case?
We use it for code scanning and security testing for our in-house application development. We are using its latest version.
What is most valuable?
Apart from software scanning, software composition scanning is valuable.
What needs improvement?
Its user interface could be improved and made more friendly.
When we change a window, the session times out, and we have to log in again. It can be improved from this aspect.
For how long have I used the solution?
I have been using this solution for about one year.
What do I think about the stability of the solution?
It has been stable during our work.
What do I think about the scalability of the solution?
We don't have so many applications. So, I have no idea about its scalability. It is enough for our work at the moment, and we have not had any problem with its scalability.
In our team, we have about 10 users.
How are customer service and support?
We are just users of this solution. There is another team that interacts with them. They get technical support from the vendor on this.
Which solution did I use previously and why did I switch?
In my previous company, I used SonarQube. In my opinion, Checkmarx gives better results, and its protection is better than SonarQube.
How was the initial setup?
Another team takes care of its deployment. We are just users. We just log into the server and use it for scanning.
What other advice do I have?
It has been working well. I would rate it a seven out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Arquitecto de soluciones at Tsoft
Has GPT and Copilot integration, and UI is easy to navigate
Pros and Cons
- "The tool's valuable features include integrating GPT and Copilot. Additionally, the UI web representation is very user-friendly, making navigation easy. GPT has made several improvements to my security code."
- "I can't create a business case with multiple-factor authentication."
What is our primary use case?
I use the tool for testing purposes.
What is most valuable?
The tool's valuable features include integrating GPT and Copilot. Additionally, the UI web representation is very user-friendly, making navigation easy. GPT has made several improvements to my security code.
What needs improvement?
I can't create a business case with multiple-factor authentication.
For how long have I used the solution?
I have been working with the product for two years.
How are customer service and support?
While support handles tickets and resolves specific issues, such as business cases, it can be frustrating waiting for responses. They often take a lot of time to address cases or provide resolutions.
How would you rate customer service and support?
Neutral
How was the initial setup?
Checkmarx One's deployment is easy. When we deployed it for a new client, it took around a month to complete. This involved setting up all parameters and sub-administrators. Additionally, finalizing the project involved several tasks, such as scanning with all security gates.
What was our ROI?
We can get a return in six months.
What's my experience with pricing, setup cost, and licensing?
The tool's pricing is fine.
What other advice do I have?
I rate the overall product an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner

Buyer's Guide
Download our free Checkmarx One Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2025
Product Categories
Application Security Tools Static Application Security Testing (SAST) Vulnerability Management Static Code Analysis API Security DevSecOps Risk-Based Vulnerability ManagementPopular Comparisons
SonarQube Server (formerly SonarQube)
GitLab
SentinelOne Singularity Cloud Security
Veracode
Coverity
Mend.io
CrowdStrike Falcon Cloud Security
OWASP Zap
Tenable Vulnerability Management
Fortify on Demand
SonarQube Cloud (formerly SonarCloud)
Orca Security
GitHub Advanced Security
Buyer's Guide
Download our free Checkmarx One Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What is the biggest difference between Veracode and Checkmarx?
- Checkmarx or Veracode. Which should we choose?
- What is the Biggest Difference Between Checkmarx and Fortify?
- What is the biggest difference between Checkmarx and SonarQube?
- Checkmarx vs SonarQube; SonarQube interoperability with Checkmarx or Veracode
- If you had to both encrypt and compress data during transmission, which would you do first and why?
- When evaluating Application Security, what aspect do you think is the most important to look for?
- What are the Top 5 cybersecurity trends in 2022?
- What are the threats associated with using ‘bogus’ cybersecurity tools?
- We're evaluating Tripwire, what else should we consider?
Hi Joe,
Given that you've continued to successfully use Checkmarx for an extended period of time since you contributed to our discussion that compares the solution to Veracode,
How does your experience compare one year later?
(See the discussion thread here:
www.itcentralstation.com)
Looking forward to your feedback