No more typing reviews! Try our Samantha, our new voice AI agent.

AWS WAF vs Checkmarx One comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
5.7
AWS WAF offers cost-effective security by reducing the need for extra staff and effectively blocking threats.
Sentiment score
5.6
Checkmarx One enhances security by automating vulnerability detection, reducing costs, and improving development efficiency through CI/CD integration.
With AWS WAF, it is easier for us to block unwanted malicious DDoS attacks and threats from coming into our web application.
Dev Ops Engineer at a tech vendor with 1,001-5,000 employees
Overall, between the fast scanning, automation, automatic reporting, and easy detection, it has reduced manual effort enough that we did not need an extra reviewer, even as our codebase or team size grew.
Senior GenAI Engineer at a tech vendor with 10,001+ employees
Based on my interactions with the clients, I can tell that there is a return on investment because if something is not profitable and it's not helping to save costs or vulnerabilities, clients wouldn't come back to renew their license year after year.
Chief Technology Officer at 3CS Aquarah Limited
 

Customer Service

Sentiment score
6.6
AWS WAF support is prompt and knowledgeable, but experiences vary in resolution speed and service costs.
Sentiment score
7.0
Checkmarx One support is praised for quick responses and knowledgeable staff, despite some reporting delays in technical support.
Resolving issues can take time because the support personnel may lack product expertise, leading to delays.
Security Engineer at a computer software company with 1,001-5,000 employees
They reach out when you send them a ticket, and within 24 hours or less, someone is able to get back to you to solve your problem.
Dev Ops Engineer at a tech vendor with 1,001-5,000 employees
If you raise a support case with Checkmarx, it is handled smoothly.
Senior Specialist at a tech vendor with 10,001+ employees
The customer support team is amazing and they provide on-phone call, email support, and on-website support.
Senior Solution Architect | L3+ Systems & Cloud Engineer | SRE Specialist at Canada Cloud Solution
I have relied on Checkmarx One customer support hundreds of times for several things, and Checkmarx One support is very proactive and very responsive.
Chief Technology Officer at 3CS Aquarah Limited
 

Scalability Issues

Sentiment score
7.5
AWS WAF is highly scalable, versatile for various infrastructures, but some users desire expanded features for broader adaptability.
Sentiment score
7.0
Checkmarx One is scalable for large workloads, but some users report challenges with configurations and licensing requirements.
AWS WAF does scale in the sense that it is fully managed and has automatic scaling.
Dev Ops Engineer at a tech vendor with 1,001-5,000 employees
Approximately four billion lines of code are being scanned monthly.
Cyber Security Expert at Nestle
Since it is cloud-based, the infrastructure and PaaS, IaaS, and SaaS are taken care of by the cloud marketplace.
Senior Solution Architect | L3+ Systems & Cloud Engineer | SRE Specialist at Canada Cloud Solution
Checkmarx One's scalability has changed my organization because the strong collaboration between the development and security team helps us to do things much faster.
Senior GenAI Engineer at a tech vendor with 10,001+ employees
 

Stability Issues

Sentiment score
8.3
AWS WAF is stable, effectively blocking threats, with minor issues in custom rules, and continuous improvements enhance reliability.
Sentiment score
7.3
Checkmarx One is generally stable but faces issues with large codebases, memory use, and session inconsistencies.
Since it protects web applications from common attacks such as SQL injection and XSS, it is very stable.
Dev Ops Engineer at a tech vendor with 1,001-5,000 employees
In terms of reliability, I would rate AWS WAF about six out of ten due to the need for improved signature sets.
Security Engineer at a computer software company with 1,001-5,000 employees
We faced issues with AWS WAF when writing the custom rules.
Infrastructure Lead at Danat Fz LLC
I would rate the stability of this solution a nine on a scale of 1 to 10 where one is low stability and 10 is high.
Specialist Leader at Deloitte
Checkmarx One is often down when the cloud provider experiences issues.
Cyber Security Expert at Nestle
 

Room For Improvement

AWS WAF requires enhanced features, security, user interface, documentation, seamless integrations, and added automation for improved effectiveness.
Checkmarx One needs enhancements in accuracy, speed, integration, UI, support, pricing, and features for enterprise usability.
Compared to firewalls, WAFs generally provide limited stateful analysis capabilities.
Security Engineer at a computer software company with 1,001-5,000 employees
The way we see it now is just mentioned as a percentage from bots and actual users, which should include proper graphs and detailed information.
Infrastructure Lead at Danat Fz LLC
The level of granularity is not great, and as you cross a certain threshold, the cost goes up by twenty or thirty percent every time.
Security Engineer Dev Sec Ops at a outsourcing company with 1,001-5,000 employees
Integration into the IDE being used would be beneficial so that code does not need to be uploaded to the website and an IDE-friendly report could be generated.
Senior Software Engineer at a financial services firm with 10,001+ employees
It could suggest how the code base is written and automatically populate the source code with three different solution options to choose from.
Specialist Leader at Deloitte
If you can improve the speed optimization, it takes around 30 to 40 minutes for checking a build. If you can make it within five minutes or 10 minutes, that would be great.
Senior Software Engineer at Tech Mahindra Limited
 

Setup Cost

AWS WAF pricing is seen as affordable but can be costly in high-demand scenarios like DDoS attacks.
Checkmarx One is often costly but provides quality and security, with costs varying by team size and selected modules.
Due to our status as an AWS shop, AWS WAF is cost-effective for us, and we benefit from discounts due to our extensive use of AWS services.
Security Engineer at a computer software company with 1,001-5,000 employees
The licensing cost for AWS WAF is just pay-as-you-go; it is a service-based model.
Infrastructure Lead at Danat Fz LLC
For a small team under 50 developers, normal expenses come under 30 to 60K.
Senior Solution Architect | L3+ Systems & Cloud Engineer | SRE Specialist at Canada Cloud Solution
Due to the number of years I've implemented Checkmarx One, there are rebates and discounts from the OEM which makes it a lot more profitable.
Chief Technology Officer at 3CS Aquarah Limited
The pricing should be reasonable, matching what we are paying for.
Senior GenAI Engineer at a tech vendor with 10,001+ employees
 

Valuable Features

AWS WAF enhances security with configurable rules, seamless AWS integration, scalability, and ease of deployment for threat protection.
Checkmarx One offers comprehensive vulnerability scanning, seamless CI/CD integration, and enhances productivity with ease of use and automation.
The biggest benefit of AWS WAF for us is to filter malicious requests, so we can protect our environment and application from malicious actors.
Infrastructure Lead at Danat Fz LLC
It has also helped to improve the posture of our application, prevent all DDoS attacks, and unnecessary traffic and SQL injection that is reducing the performance of our application.
Dev Ops Engineer at a tech vendor with 1,001-5,000 employees
The specific outcomes showing how AWS WAF has helped our organization include improving our security posture by reducing the attack surface and reducing malicious attacks.
Senior Cloud Security at a healthcare company with 5,001-10,000 employees
Since replacing the previous tool, SAST and SCA scans are conducted in a couple of minutes instead of hours or days.
Cyber Security Expert at Nestle
The best features Checkmarx One offers, over the past years, include broad language and technical support that Checkmarx provides, covering most languages.
Senior Specialist at a tech vendor with 10,001+ employees
Checkmarx One has positively impacted our organization as we tend to find vulnerabilities very early in the development cycle.
Product security engineer at a tech vendor with 10,001+ employees
 

Categories and Ranking

AWS WAF
Average Rating
8.0
Reviews Sentiment
6.8
Number of Reviews
63
Ranking in other categories
Web Application Firewall (WAF) (8th)
Checkmarx One
Average Rating
7.8
Reviews Sentiment
6.6
Number of Reviews
81
Ranking in other categories
Application Security Tools (2nd), Static Application Security Testing (SAST) (2nd), Vulnerability Management (12th), Container Security (15th), Static Code Analysis (2nd), API Security (5th), Dynamic Application Security Testing (DAST) (2nd), DevSecOps (3rd), Risk-Based Vulnerability Management (10th), Application Security Posture Management (ASPM) (3rd), AI Security (3rd)
 

Mindshare comparison

AWS WAF and Checkmarx One aren’t in the same category and serve different purposes. AWS WAF is designed for Web Application Firewall (WAF) and holds a mindshare of 3.9%, down 6.9% compared to last year.
Checkmarx One, on the other hand, focuses on Application Security Tools, holds 7.3% mindshare, down 10.2% since last year.
Web Application Firewall (WAF) Mindshare Distribution
ProductMindshare (%)
AWS WAF3.9%
Imperva Application Security Platform7.4%
Cloudflare5.0%
Other83.7%
Web Application Firewall (WAF)
Application Security Tools Mindshare Distribution
ProductMindshare (%)
Checkmarx One7.3%
SonarQube10.8%
Snyk5.0%
Other76.9%
Application Security Tools
 

Featured Reviews

Azam S M - PeerSpot reviewer
Infrastructure Lead at Danat Fz LLC
Has successfully filtered malicious traffic and allowed country-specific access controls
For improvement in AWS WAF, we can have better monitoring. One of the things that should be improved in AWS WAF is the monitoring; we need to identify the requests and where they are coming from. If it's a bot, we should differentiate the requests, whether they are automated or not. The way we see it now is just mentioned as a percentage from bots and actual users, which should include proper graphs and detailed information. We also need a feature where we can filter specific requests. If there are scripts in the requests, we should be able to filter those requests to see if there are any scripts running from them.
Shahzad Shahzad - PeerSpot reviewer
Senior Solution Architect | L3+ Systems & Cloud Engineer | SRE Specialist at Canada Cloud Solution
Enable secure development workflows while identifying opportunities for faster scans and improved AI guidance
Checkmarx One is a very strong platform, but there are several areas where it can improve to support modern DevSecOps workflows even better. For example, better real-time developer guidance is needed. The IDE plugin should offer richer AI-powered auto-fixes similar to SNYK Code or GitHub Copilot Security, as current guidance is good but not deeply contextual for large-scale enterprise codebases. This matters because it reduces developer friction and accelerates shift-left adoption. More transparency control over the correlation engines is another need. The correlation engine is powerful but not fully transparent. Users want to understand why vulnerabilities were correlated or de-prioritized, which helps AppSec teams trust the prioritization logic. Faster SAST scan and more language coverage is needed since SAST scan can still be slow for very large mono-repos and there is limited deep support for new language frameworks like Rust and Go, along with advanced coverage for serverless-specific frameworks. This matters because large organizations want sub-minute scans in CI/CD as cloud-native ecosystems evolve fast. A strong API security module is another area for enhancement. API security scanning could be improved with active testing, API discovery, full Swagger, OpenAPI, drift detection, and schema-based fuzzing. This is important as API attacks are one of the biggest AppSec risks in 2025. Checkmarx One is strong, but I see a few areas for improvement including faster SAST scanning for large mono-repos, deeper language framework support, more transparent correlation logic, and stronger API security that includes discovery and runtime context. The IDE plugin could offer more AI-assisted fixes, and the SBOM lifecycle tracking can evolve further. Enhancing integration with SIEM and SOAR would also make enterprise adoption smoother, and these improvements would help developers and AppSec teams move faster with more accuracy.
report
Use our free recommendation engine to learn which Web Application Firewall (WAF) solutions are best for your needs.
911,994 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
13%
Manufacturing Company
9%
Comms Service Provider
7%
Computer Software Company
7%
Financial Services Firm
15%
Manufacturing Company
9%
Computer Software Company
7%
Outsourcing Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business22
Midsize Enterprise12
Large Enterprise28
By reviewers
Company SizeCount
Small Business32
Midsize Enterprise9
Large Enterprise46
 

Questions from the Community

What are the limitations of AWS WAF vs alternative WAFs?
Hi Varun, I have had experienced with several WAF deployments and deep technical assessments of the following: 1. Imperva WAF 2. F5 WAF 3. Polarisec Cloud WAF Typical limitations on cloud WAF is t...
How does AWS WAF compare to Microsoft Azure Application Gateway?
Our organization ran comparison tests to determine whether Amazon’s Web Service Web Application Firewall or Microsoft Azure Application Gateway web application firewall software was the better fit ...
What is your experience regarding pricing and costs for AWS WAF?
AWS WAF is affordable; it depends on the number of rules you apply. The licensing cost for AWS WAF is just pay-as-you-go; it is a service-based model.
What alternatives are there for Fortify WebInspect and Fortify SCA?
I would like to recommend Checkmarx. With Checkmarx, you are able to have an all in one solution for SAST and SCA as well. Veracode is only a cloud solution. Hope this helps.
What is the biggest difference between Veracode and Checkmarx?
According to my experience of using both the tools in different organizations Veracode is a Cloud-native, managed AppSec platform with strong focus on ease of use, it is SaaS delivery, and provide...
What is your experience regarding pricing and costs for Checkmarx?
Checkmarx One is a premium solution, so budget accordingly. Make sure you understand how licensing scales with additional applications and users. I advise negotiating multi-year contracts or bundle...
 

Also Known As

AWS Web Application Firewall
No data available
 

Overview

 

Sample Customers

eVitamins, 9Splay, Senao International
YIT, Salesforce, Coca-Cola, SAP, U.S. Army, Liveperson, Playtech Case Study: Liveperson Implements Innovative Secure SDLC
Find out what your peers are saying about Imperva, Radware, F5 and others in Web Application Firewall (WAF). Updated: September 2026.
911,994 professionals have used our research since 2012.