Try our new research platform with insights from 80,000+ expert users

AWS WAF vs Checkmarx One comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
6.9
AWS WAF enhances security and cost efficiency by integrating with AWS, reducing the need for additional security personnel.
Sentiment score
5.9
Organizations find Checkmarx One enhances secure delivery, reduces rework, and boosts efficiency, despite challenges in quantifying ROI numerically.
With AWS WAF, it is easier for us to block unwanted malicious DDoS attacks and threats from coming into our web application.
DevOps Engineer at a tech vendor with 1,001-5,000 employees
Overall, between the fast scanning, automation, automatic reporting, and easy detection, it has reduced manual effort enough that we did not need an extra reviewer, even as our codebase or team size grew.
Senior GenAI Engineer at a tech vendor with 10,001+ employees
Based on my interactions with the clients, I can tell that there is a return on investment because if something is not profitable and it's not helping to save costs or vulnerabilities, clients wouldn't come back to renew their license year after year.
Chief Technology Officer at 3CS Aquarah Limited
 

Customer Service

Sentiment score
6.7
AWS WAF support receives mixed reviews, praised for responsiveness and expertise, yet criticized for cost and inconsistent communication.
Sentiment score
7.0
Checkmarx One customer support is praised for responsiveness and expertise, but some users desire quicker response times.
Resolving issues can take time because the support personnel may lack product expertise, leading to delays.
Security Engineer at a computer software company with 1,001-5,000 employees
They reach out when you send them a ticket, and within 24 hours or less, someone is able to get back to you to solve your problem.
DevOps Engineer at a tech vendor with 1,001-5,000 employees
If you raise a support case with Checkmarx, it is handled smoothly.
ML Engineer - Specialist at a tech vendor with 10,001+ employees
The customer support team is amazing and they provide on-phone call, email support, and on-website support.
Senior Solution Architect | L3+ Systems & Cloud Engineer | SRE Specialist at Canada Cloud Solution
I have relied on Checkmarx One customer support hundreds of times for several things, and Checkmarx One support is very proactive and very responsive.
Chief Technology Officer at 3CS Aquarah Limited
 

Scalability Issues

Sentiment score
7.8
AWS WAF excels in scalability and auto-scaling, efficiently handling traffic for businesses of all sizes, though improvements are possible.
Sentiment score
7.1
Checkmarx One effectively scales for large workloads, with positive user experiences, but requires sufficient hardware for optimal performance.
AWS WAF does scale in the sense that it is fully managed and has automatic scaling.
DevOps Engineer at a tech vendor with 1,001-5,000 employees
Approximately four billion lines of code are being scanned monthly.
Cyber Security Expert at a manufacturing company with 10,001+ employees
Since it is cloud-based, the infrastructure and PaaS, IaaS, and SaaS are taken care of by the cloud marketplace.
Senior Solution Architect | L3+ Systems & Cloud Engineer | SRE Specialist at Canada Cloud Solution
Checkmarx One's scalability has changed my organization because the strong collaboration between the development and security team helps us to do things much faster.
Senior GenAI Engineer at a tech vendor with 10,001+ employees
 

Stability Issues

Sentiment score
8.3
AWS WAF is highly rated for stability due to reliable performance, strong protection, and effective redundancy features.
Sentiment score
7.3
Checkmarx One is stable and reliable but may slow or freeze with large scans and incremental scan issues.
Since it protects web applications from common attacks such as SQL injection and XSS, it is very stable.
DevOps Engineer at a tech vendor with 1,001-5,000 employees
In terms of reliability, I would rate AWS WAF about six out of ten due to the need for improved signature sets.
Security Engineer at a computer software company with 1,001-5,000 employees
We faced issues with AWS WAF when writing the custom rules.
Infrastructure Lead at Danat Fz LLC
I would rate the stability of this solution a nine on a scale of 1 to 10 where one is low stability and 10 is high.
Specialist Leader at Deloitte
Checkmarx One is often down when the cloud provider experiences issues.
Cyber Security Expert at a manufacturing company with 10,001+ employees
 

Room For Improvement

AWS WAF requires improved integration, usability, security features, and flexible pricing to better support global users and services.
Checkmarx One needs improvements in accuracy, speed, language support, integration, usability, API security, reporting, and pricing flexibility.
Compared to firewalls, WAFs generally provide limited stateful analysis capabilities.
Security Engineer at a computer software company with 1,001-5,000 employees
The way we see it now is just mentioned as a percentage from bots and actual users, which should include proper graphs and detailed information.
Infrastructure Lead at Danat Fz LLC
Features like bot protection or DDoS mitigation, available with other WAF vendors, do not come natively with AWS WAF.
Security Analyst at M2P Fintech
Integration into the IDE being used would be beneficial so that code does not need to be uploaded to the website and an IDE-friendly report could be generated.
Senior Software Engineer at a financial services firm with 10,001+ employees
It could suggest how the code base is written and automatically populate the source code with three different solution options to choose from.
Specialist Leader at Deloitte
If you can improve the speed optimization, it takes around 30 to 40 minutes for checking a build. If you can make it within five minutes or 10 minutes, that would be great.
Senior Software Engineer at a tech vendor with 10,001+ employees
 

Setup Cost

AWS WAF offers cost-effective, pay-as-you-go pricing, starting at $5 monthly, valued for integration with AWS services.
Checkmarx One is costly but valued for features, flexible licensing, and negotiable multi-year contracts to reduce expenses.
Due to our status as an AWS shop, AWS WAF is cost-effective for us, and we benefit from discounts due to our extensive use of AWS services.
Security Engineer at a computer software company with 1,001-5,000 employees
The licensing cost for AWS WAF is just pay-as-you-go; it is a service-based model.
Infrastructure Lead at Danat Fz LLC
For a small team under 50 developers, normal expenses come under 30 to 60K.
Senior Solution Architect | L3+ Systems & Cloud Engineer | SRE Specialist at Canada Cloud Solution
Due to the number of years I've implemented Checkmarx One, there are rebates and discounts from the OEM which makes it a lot more profitable.
Chief Technology Officer at 3CS Aquarah Limited
The pricing should be reasonable, matching what we are paying for.
Senior GenAI Engineer at a tech vendor with 10,001+ employees
 

Valuable Features

AWS WAF offers threat blocking, scalability, automation, and seamless integration, enhancing security and performance with easy deployment and affordability.
Checkmarx One excels in code scanning, vulnerability detection, and integration, enhancing security, productivity, and developer skills.
The biggest benefit of AWS WAF for us is to filter malicious requests, so we can protect our environment and application from malicious actors.
Infrastructure Lead at Danat Fz LLC
It has also helped to improve the posture of our application, prevent all DDoS attacks, and unnecessary traffic and SQL injection that is reducing the performance of our application.
DevOps Engineer at a tech vendor with 1,001-5,000 employees
The cloud-native nature of AWS is crucial since most of our workload is in AWS, making AWS WAF native to Amazon Web Services.
Security Analyst at M2P Fintech
Since replacing the previous tool, SAST and SCA scans are conducted in a couple of minutes instead of hours or days.
Cyber Security Expert at a manufacturing company with 10,001+ employees
The best features Checkmarx One offers, over the past years, include broad language and technical support that Checkmarx provides, covering most languages.
ML Engineer - Specialist at a tech vendor with 10,001+ employees
Checkmarx One has positively impacted our organization as we tend to find vulnerabilities very early in the development cycle.
Product security engineer at a tech vendor with 10,001+ employees
 

Categories and Ranking

AWS WAF
Average Rating
8.0
Reviews Sentiment
7.0
Number of Reviews
61
Ranking in other categories
Web Application Firewall (WAF) (3rd)
Checkmarx One
Average Rating
7.8
Reviews Sentiment
6.7
Number of Reviews
80
Ranking in other categories
Application Security Tools (3rd), Static Application Security Testing (SAST) (3rd), Vulnerability Management (16th), Container Security (15th), Static Code Analysis (2nd), API Security (3rd), Dynamic Application Security Testing (DAST) (2nd), DevSecOps (3rd), Risk-Based Vulnerability Management (8th), Application Security Posture Management (ASPM) (3rd), AI Security (1st)
 

Mindshare comparison

AWS WAF and Checkmarx One aren’t in the same category and serve different purposes. AWS WAF is designed for Web Application Firewall (WAF) and holds a mindshare of 5.8%, down 11.0% compared to last year.
Checkmarx One, on the other hand, focuses on Application Security Tools, holds 10.2% mindshare, down 11.8% since last year.
Web Application Firewall (WAF) Market Share Distribution
ProductMarket Share (%)
AWS WAF5.8%
Fortinet FortiWeb8.1%
F5 Advanced WAF7.8%
Other78.3%
Web Application Firewall (WAF)
Application Security Tools Market Share Distribution
ProductMarket Share (%)
Checkmarx One10.2%
SonarQube17.9%
Snyk5.7%
Other66.2%
Application Security Tools
 

Featured Reviews

Azam S M - PeerSpot reviewer
Infrastructure Lead at Danat Fz LLC
Has successfully filtered malicious traffic and allowed country-specific access controls
For improvement in AWS WAF, we can have better monitoring. One of the things that should be improved in AWS WAF is the monitoring; we need to identify the requests and where they are coming from. If it's a bot, we should differentiate the requests, whether they are automated or not. The way we see it now is just mentioned as a percentage from bots and actual users, which should include proper graphs and detailed information. We also need a feature where we can filter specific requests. If there are scripts in the requests, we should be able to filter those requests to see if there are any scripts running from them.
Shahzad Shahzad - PeerSpot reviewer
Senior Solution Architect | L3+ Systems & Cloud Engineer | SRE Specialist at Canada Cloud Solution
Enable secure development workflows while identifying opportunities for faster scans and improved AI guidance
Checkmarx One is a very strong platform, but there are several areas where it can improve to support modern DevSecOps workflows even better. For example, better real-time developer guidance is needed. The IDE plugin should offer richer AI-powered auto-fixes similar to SNYK Code or GitHub Copilot Security, as current guidance is good but not deeply contextual for large-scale enterprise codebases. This matters because it reduces developer friction and accelerates shift-left adoption. More transparency control over the correlation engines is another need. The correlation engine is powerful but not fully transparent. Users want to understand why vulnerabilities were correlated or de-prioritized, which helps AppSec teams trust the prioritization logic. Faster SAST scan and more language coverage is needed since SAST scan can still be slow for very large mono-repos and there is limited deep support for new language frameworks like Rust and Go, along with advanced coverage for serverless-specific frameworks. This matters because large organizations want sub-minute scans in CI/CD as cloud-native ecosystems evolve fast. A strong API security module is another area for enhancement. API security scanning could be improved with active testing, API discovery, full Swagger, OpenAPI, drift detection, and schema-based fuzzing. This is important as API attacks are one of the biggest AppSec risks in 2025. Checkmarx One is strong, but I see a few areas for improvement including faster SAST scanning for large mono-repos, deeper language framework support, more transparent correlation logic, and stronger API security that includes discovery and runtime context. The IDE plugin could offer more AI-assisted fixes, and the SBOM lifecycle tracking can evolve further. Enhancing integration with SIEM and SOAR would also make enterprise adoption smoother, and these improvements would help developers and AppSec teams move faster with more accuracy.
report
Use our free recommendation engine to learn which Web Application Firewall (WAF) solutions are best for your needs.
880,511 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
15%
Computer Software Company
13%
Manufacturing Company
9%
Government
6%
Financial Services Firm
19%
Manufacturing Company
10%
Computer Software Company
10%
Government
5%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business22
Midsize Enterprise12
Large Enterprise26
By reviewers
Company SizeCount
Small Business32
Midsize Enterprise9
Large Enterprise45
 

Questions from the Community

What are the limitations of AWS WAF vs alternative WAFs?
Hi Varun, I have had experienced with several WAF deployments and deep technical assessments of the following: 1. Imperva WAF 2. F5 WAF 3. Polarisec Cloud WAF Typical limitations on cloud WAF is t...
How does AWS WAF compare to Microsoft Azure Application Gateway?
Our organization ran comparison tests to determine whether Amazon’s Web Service Web Application Firewall or Microsoft Azure Application Gateway web application firewall software was the better fit ...
What do you like most about AWS WAF?
The most valuable feature of AWS WAF is its highly configurable rules system.
What alternatives are there for Fortify WebInspect and Fortify SCA?
I would like to recommend Checkmarx. With Checkmarx, you are able to have an all in one solution for SAST and SCA as well. Veracode is only a cloud solution. Hope this helps.
What do you like most about Checkmarx?
Compared to the solutions we used previously, Checkmarx has reduced our workload by almost 75%.
What is your experience regarding pricing and costs for Checkmarx?
Checkmarx One is a premium solution, so budget accordingly. Make sure you understand how licensing scales with additional applications and users. I advise negotiating multi-year contracts or bundle...
 

Also Known As

AWS Web Application Firewall
No data available
 

Overview

 

Sample Customers

eVitamins, 9Splay, Senao International
YIT, Salesforce, Coca-Cola, SAP, U.S. Army, Liveperson, Playtech Case Study: Liveperson Implements Innovative Secure SDLC
Find out what your peers are saying about Fortinet, F5, Amazon Web Services (AWS) and others in Web Application Firewall (WAF). Updated: January 2026.
880,511 professionals have used our research since 2012.