Try our new research platform with insights from 80,000+ expert users

Armis vs Checkmarx One comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Nov 6, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Zafran Security
Sponsored
Average Rating
9.6
Reviews Sentiment
7.8
Number of Reviews
6
Ranking in other categories
Vulnerability Management (16th), Continuous Threat Exposure Management (CTEM) (1st)
Armis
Average Rating
8.6
Reviews Sentiment
7.2
Number of Reviews
10
Ranking in other categories
IoT Security (2nd), Cyber Asset Attack Surface Management (CAASM) (1st), Risk-Based Vulnerability Management (8th), Cyber-Physical Systems Protection (1st)
Checkmarx One
Average Rating
7.6
Reviews Sentiment
6.9
Number of Reviews
71
Ranking in other categories
Application Security Tools (3rd), Static Application Security Testing (SAST) (3rd), Vulnerability Management (23rd), Container Security (22nd), Static Code Analysis (3rd), API Security (4th), Dynamic Application Security Testing (DAST) (4th), DevSecOps (4th), Risk-Based Vulnerability Management (9th)
 

Featured Reviews

Israel Cavazos Landini - PeerSpot reviewer
Weekly insights and risk analysis facilitate informed security decisions
I appreciate the weekly insights Zafran provides, which include critical topics for networks and IT security, allowing us to evaluate which insights apply to our environment. The organization score feature is valuable to keep the leadership team updated on how our infrastructure fares security-wise. The applicable risk level versus base risk level feature is beneficial because prior to Zafran, we only used the base risk level, but now understand that risk depends on the asset itself. Zafran is an excellent tool.
SaketShrivastava - PeerSpot reviewer
Comprehensive asset visibility and OT operations support enhance risk mitigation
I use Armis for asset discovery and vulnerability assessments of the OT network Armis is easy to use. Very few software solutions have OT capabilities that do not impact OT operations. Its asset visibility is good as well. This comprehensive feature set is crucial for our operations.…
Syed Hasan - PeerSpot reviewer
Partner experiences excellent technical support and seamless initial setup
In my opinion, if we are able to extract or show the report, and because everything is going towards agent tech and GenAI, it would be beneficial if it could get integrated with our code base and do the fix automatically. It could suggest how the code base is written and automatically populate the source code with three different solution options to choose from. This would be really helpful.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"We saw benefits from Zafran Security almost immediately after deploying it."
"Zafran has become an indispensable tool in our cybersecurity arsenal."
"Overall, we have seen about eighty-seven percent reduction of the number of vulnerabilities that require urgency to remediate, specifically the number of criticals."
"Zafran is an excellent tool."
"We are able to see the real risk of a vulnerability on our environment with our security tools."
"Armis is a straightforward and user-friendly solution."
"The initial setup and deployment were simple."
"Armis is easy to use."
"The most valuable feature of the solution is asset tracking."
"The technology is good."
"Armis is very easy to implement due to its agentless design and offers a granular level of visibility for all assets in the network."
"The tool is user-friendly and helps to detect vulnerabilities."
"Armis is very easy to implement due to its agentless design and offers a granular level of visibility for all assets in the network."
"The setup is fairly easy. We didn't struggle with the process at all."
"It is very useful because it fits our requirements. It is also easy to use. It is not complex, and we are satisfied with the results."
"The most valuable features of Checkmarx are its integration with multiple SCM solutions and CICD tools, its ability to scale according to user licenses, and the quick scanning process."
"The reports are very good because they include details on the code level, and make suggestions about how to fix the problems."
"I have seen a return on investment from Checkmarx One."
"One of the most valuable features is it is flexible."
"The most valuable feature for me is the Jenkins Plugin."
"Checkmarx pinpoints the vulnerability in the code and also presents the flow of malicious input across the application."
 

Cons

"The dashboarding and reporting functionality of Zafran Security is an area that definitely could use some improvements."
"I think the ability to have some enhanced reporting capabilities is something they can improve on, as they have good reports but we have asked for some specific reporting enhancements."
"Initially, we were somewhat concerned about the scalability of Zafran due to our large asset count and the substantial amount of information we needed to process."
"We face difficulties in integrating the product with ticketing tools like ServiceNow."
"The vulnerability assessment for Windows is not that great. It misses out on a lot of vulnerabilities."
"The solution's vulnerability testing could be improved."
"Armis doesn't have a back intel feature."
"We face issues during implementation."
"There are occasional issues with some built-in integrations that require troubleshooting, particularly with DHCP integration. Developing additional integrations would be beneficial."
"There isn't anything specific that needs improvement."
"Like any IT tool, continuous learning and improvement are essential for the solution."
"The lack of ability to review compiled source code. It would then be able to compete with other scanning tools, such as Veracode."
"You can't use it in the continuous delivery pipeline because the scanning takes too much time."
"C, C++, VB and T-SQL are not supported by this product. Although, C and C++ were advertised as being supported."
"It would be really helpful if the level of confidence was included, with respect to identified issues."
"Micro-services need to be included in the next release."
"Integration into the SDLC (i.e. support for last version of SonarQube) could be added."
"It is an expensive solution."
"I would like to see the rate of false positives reduced."
 

Pricing and Cost Advice

Information not available
"The tool is cheap."
"Its price is fair. It is in or around the right spot. Ultimately, if the price is wrong, customers won't commit, but they do tend to commit. It is neither too cheap nor too expensive."
"We're using a commercial version of Checkmarx, and we paid for the solution for one year. The price is high and could be reduced."
"If you want more, you have to pay more. You have to pay for additional modules or functionalities."
"The pricing is competitive and provides a lower TCO (total cost of ownership) for achieving application security."
"I believe pricing is better compared to other commercial tools."
"The number of users and coverage for languages will have an impact on the cost of the license."
"We got a special offer for a 30% reduction for three years, after our first year. I think for a real source-code scanning tool, you have to add a lot of money for Open Source Analysis, and AppSec Coach (160 Euro per user per year)."
"The solution is costly."
report
Use our free recommendation engine to learn which Risk-Based Vulnerability Management solutions are best for your needs.
865,384 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
10%
Computer Software Company
10%
Manufacturing Company
8%
Healthcare Company
5%
Government
12%
Computer Software Company
10%
Manufacturing Company
9%
Financial Services Firm
9%
Financial Services Firm
20%
Computer Software Company
13%
Manufacturing Company
10%
Government
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

What is your experience regarding pricing and costs for Zafran Security?
Since we stood Zafran Security up in our private cloud, we handle the maintenance on our side. As we opted not to use...
What needs improvement with Zafran Security?
In terms of areas for improvement, Zafran Security is doing a really great job as a new and emerging company. Oftenti...
What is your primary use case for Zafran Security?
My use cases for Zafran Security revolve around two primary areas. One is around vulnerability management and priorit...
What do you like most about Armis?
Armis is a straightforward and user-friendly solution.
What needs improvement with Armis?
The vulnerability assessment for Windows is not that great. It misses out on a lot of vulnerabilities. Additionally, ...
What is your primary use case for Armis?
I use Armis ( /products/armis-reviews ) for asset discovery and vulnerability assessments of the OT network.
What alternatives are there for Fortify WebInspect and Fortify SCA?
I would like to recommend Checkmarx. With Checkmarx, you are able to have an all in one solution for SAST and SCA as ...
What do you like most about Checkmarx?
Compared to the solutions we used previously, Checkmarx has reduced our workload by almost 75%.
What is your experience regarding pricing and costs for Checkmarx?
The pricing is relatively expensive due to the product's quality and performance, but it is worth it.
 

Overview

 

Sample Customers

Information Not Available
Samsung Research America, IDT Corporation, Gett
YIT, Salesforce, Coca-Cola, SAP, U.S. Army, Liveperson, Playtech Case Study: Liveperson Implements Innovative Secure SDLC
Find out what your peers are saying about Armis vs. Checkmarx One and other solutions. Updated: July 2025.
865,384 professionals have used our research since 2012.