Checkmarx One is an enterprise cloud-native application security platform focused on providing cross-tool, correlated results to help AppSec and developer teams prioritize where to focus time and resources.



| Product | Market Share (%) |
|---|---|
| Checkmarx One | 10.2% |
| SonarQube | 19.2% |
| Veracode | 6.1% |
| Other | 64.5% |
| Title | Rating | Mindshare | Recommending | |
|---|---|---|---|---|
| SonarQube | 4.0 | 19.2% | 83% | 134 interviewsAdd to research |
| Wiz | 4.5 | N/A | 96% | 33 interviewsAdd to research |
| Company Size | Count |
|---|---|
| Small Business | 24 |
| Midsize Enterprise | 9 |
| Large Enterprise | 40 |
| Company Size | Count |
|---|---|
| Small Business | 621 |
| Midsize Enterprise | 368 |
| Large Enterprise | 1883 |
Checkmarx One offers comprehensive application scanning across the SDLC:
Checkmarx One provides everything you need to secure application development from the first line of code through deployment and runtime in the cloud. With an ever-evolving set of AppSec engines, correlation and prioritization features, and AI capabilities, Checkmarx One helps consolidate expanding lists of AppSec tools and make better sense of results. Its capabilities are designed to provide an improved developer experience to build trust with development teams and ensure the success of your AppSec program investment.
YIT, Salesforce, Coca-Cola, SAP, U.S. Army, Liveperson, Playtech
Case Study: Liveperson Implements Innovative Secure SDLC
| Author info | Rating | Review Summary |
|---|---|---|
| Senior Solution Architect | L3+ Systems & Cloud Engineer | SRE Specialist at Canada Cloud Solution | 3.5 | I’ve used Checkmarx One extensively to improve developer workflow and application security, appreciating its strong SAST, SCA, and CI/CD integrations, though it could benefit from faster scans, deeper language support, and more contextual IDE guidance. |
| Senior Software Engineer at a tech vendor with 10,001+ employees | 4.5 | I've been using Checkmarx One for years to streamline code validation, improve quality, and ensure compliance, saving significant time weekly, though I’d like to see faster reporting speeds and a more intuitive UI. |
| Cyber Security Expert at a manufacturing company with 10,001+ employees | 4.5 | I use Checkmarx One for SAST and SCA scans, appreciating its CI/CD integration and SCM support; while reporting could improve, it’s boosted our speed to market and handles extensive global code scanning effectively. |
| Senior GenAI Engineer at a tech vendor with 10,001+ employees | 4.0 | I've used Checkmarx One for three years to streamline vulnerability detection through CI/CD integration, saving time and reducing manual reviews, though it could improve scan speed, false positives, and integration with modern development tools. |
| ML Engineer - Specialist at a tech vendor with 10,001+ employees | 4.5 | I've used Checkmarx One extensively in DevSecOps for secure code scanning and CI/CD integration; it's versatile and stable, though scan speed and false positives could improve. It supports many languages and helps ensure compliance in cloud and on-prem environments. |
| Chief Technology Officer at 3CS Aquarah Limited | 4.0 | I implement Checkmarx One for clients, and it's reliable, easy to set up, and delivers quick results, especially in secure code development. Its Codebashing feature stands out, though I’d like to see RASP capabilities in the future. |
| Specialist Leader at Deloitte | 4.5 | I work as a partner with Checkmarx One and find its initial setup straightforward, although hybrid deployment is preferred. The tool shows clear ROI, but automated code fixing would enhance its capabilities. Enterprise clients benefit from its effective security scans. |
| Senior Software Engineer at a financial services firm with 10,001+ employees | 3.5 | I've used Checkmarx One for about three years to run SAST scans via our CI/CD pipeline, finding it effective though sometimes noisy with false positives; its CWE summaries and fix guidance are particularly useful in my daily work. |