Try our new research platform with insights from 80,000+ expert users

BMC Cloud Lifecycle Management vs Snyk comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Jun 4, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

BMC Cloud Lifecycle Management
Ranking in Cloud Management
38th
Average Rating
7.8
Reviews Sentiment
5.3
Number of Reviews
5
Ranking in other categories
Cloud Monitoring Software (45th)
Snyk
Ranking in Cloud Management
15th
Average Rating
8.0
Reviews Sentiment
7.4
Number of Reviews
48
Ranking in other categories
Application Security Tools (5th), Static Application Security Testing (SAST) (8th), Container Security (6th), Software Composition Analysis (SCA) (2nd), Software Development Analytics (2nd), Cloud Security Posture Management (CSPM) (16th), DevSecOps (2nd), Application Security Posture Management (ASPM) (1st)
 

Mindshare comparison

As of August 2025, in the Cloud Management category, the mindshare of BMC Cloud Lifecycle Management is 0.9%, up from 0.5% compared to the previous year. The mindshare of Snyk is 1.3%, up from 0.3% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Cloud Management
 

Featured Reviews

VB
Helps design blueprints in a cloud environment but the support is a major problem
One of the major problems is that support is not so good. I used to have a support expert in Spain but they left two years ago. BMC doesn't invest a lot in network automation but network automation is a major point in CLM. There aren't any experts here in Europe, maybe they have in America, I don't know. The main problem is the support in Europe. We had a lot of problems with the people who got put on our cases. The agents that we were assigned to were not so capable. They wanted to replicate the problem. If you have an incident, it takes a lot of time to troubleshoot the problem. The incident support is not so good. The technicians don't know the platform well. BMC doesn't want to invest in CLM. Two years ago we had a lot of problems. Maybe BMC realized that CLM is an end of life product.
meetharoon - PeerSpot reviewer
Affordable tool boosts code scanning efficiency but faces integration hurdles
The most important feature of Snyk is its cost-effectiveness compared to other solutions such as Check Point. It is easy to consolidate Snyk across multiple entities within a large organization. Additionally, our integration of Snyk into GitHub allows us to automatically scan codebases and identify issues, which has improved efficiency.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"CLM has a multi-cloud portal because they have the resources to implement in various environments in various ports."
"Supports unattended installs and image-based, script-based, or template-based provisioning."
"Integrates role-based access control with pre-configured policies for CIS, DISA, HIPAA, PCI, SOX, NIST, and SCAP documentation and remediation."
"Automates Java EE Application Deployment from an SCM system."
"By allowing end users to request their own services, the request process for systems is much quicker and more accurate."
"You can tie together your public and private cloud infrastructure into a "single pane of glass"."
"Assesses change impact or completes an audit using multiple dashboard views."
"The dependency checks of the libraries are very valuable, but the licensing part is also very important because, with open source components, licensing can be all over the place. Our project is not an open source project, but we do use quite a lot of open source components and we want to make sure that we don't have surprises in there."
"Snyk has given us really good results because it is fully automated. We don't have to scan projects every time to find vulnerabilities, as it already stores the dependencies that we are using. It monitors 24/7 to find out if there are any issues that have been reported out on the Internet."
"It has an accurate database of vulnerabilities with a low amount of false positives."
"It has improved our vulnerability rating and reduced our vulnerabilities through the tool during the time that we've had it. It's definitely made us more aware, as we have removed scoping for existing vulnerabilities and platforms since we rolled it out up until now."
"The solution's Open Source feature gives us notifications and suggestions regarding how to address vulnerabilities."
"It is easy for developers to use. The documentation is clear as well as the APIs are good and easily readable. It's a good solution overall."
"Provides clear information and is easy to follow with good feedback regarding code practices."
"Snyk categorizes the level of vulnerability into high, medium, and low, which helps organizations prioritize which issues to tackle first."
 

Cons

"One of the major problems is that support is not so good."
"The installation and configuration can be tricky due to it being built on Remedy."
"Needs integrations with other providers to provide a custom public cloud environment."
"It can be improved from the reporting perspective and scanning perspective. They can also improve it on the UI front."
"There is always more work to do around managing the volume of information when you've got thousands of vulnerabilities. Trying to get those down to zero is virtually impossible, either through ignoring them all or through fixing them. That filtering or information management is always going to be something that can be improved."
"The feature for automatic fixing of security breaches could be improved."
"It would be great if they can include dynamic, interactive, and run-time scanning features. Checkmarx and Veracode provide dynamic, interactive, and run-time scanning, but Snyk doesn't do that. That's the reason there is more inclination towards Veracode, Checkmarx, or AppScan. These are a few tools available in the market that do all four types of scanning: static, dynamic, interactive, and run-time."
"All such tools should definitely improve the signatures in their database. Snyk is pretty new to the industry. They have a pretty good knowledge base, but Veracode is on top because Veracode has been in this business for a pretty long time. They do have a pretty large database of all the findings, and the way that the correlation engine works is superb. Snyk is also pretty good, but it is not as good as Veracode in terms of maintaining a large space of all the historical data of vulnerabilities."
"We have seen cases where tools didn't find or recognize certain dependencies. These are known issues, to some extent, due to the complexity in the language or stack that you using. There are some certain circumstances where the tool isn't actually finding what it's supposed to be finding, then it could be misleading."
"A feature we would like to see is the ability to archive and store historical data, without actually deleting it. It's a problem because it throws my numbers off. When I'm looking at the dashboard's current vulnerabilities, it's not accurate."
"The reporting mechanism of Snyk could improve. The reporting mechanism is available only on the higher level of license. Adjusting the policy of the current setup of recording this report is something that can improve. For instance, if you have a certain license, you receive a rating, and the rating of this license remains the same for any use case. No matter if you are using it internally or using it externally, you cannot make the adjustment to your use case. It will always alert as a risky license. The areas of licenses in the reporting and adjustments can be improve"
 

Pricing and Cost Advice

Information not available
"The pricing is reasonable."
"You can get a good deal with Snyk for pricing. It's a little expensive, but it is worth it."
"The pricing is acceptable, especially for enterprises. I don't think it's too much of a concern for our customers. Something like $99 per user is reasonable when the stakes are high."
"The price of the solution is expensive compared to other solutions."
"It is pretty expensive. It is not a cheap product."
"We do have some missing licenses issues, especially with non-SPDX compliant one, but we expect this to be fixed soon"
"Snyk is an expensive solution."
"It's good value. That's the primary thing. It's not cheap-cheap, but it's good value."
report
Use our free recommendation engine to learn which Cloud Management solutions are best for your needs.
865,384 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
No data available
Financial Services Firm
15%
Computer Software Company
13%
Manufacturing Company
9%
Insurance Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

Ask a question
Earn 20 points
How does Snyk compare with SonarQube?
Snyk does a great job identifying and reducing vulnerabilities. This solution is fully automated and monitors 24/7 to find any issues reported on the internet. It will store dependencies that you a...
What do you like most about Snyk?
The most effective feature in securing project dependencies stems from its ability to highlight security vulnerabilities.
What needs improvement with Snyk?
There are a lot of false positives that need to be identified and separated. The inclusion of AI to remove false positives would be beneficial. So far, I've not seen any AI features to enhance vuln...
 

Also Known As

BMC CLM
Fugue
 

Overview

 

Sample Customers

JDA Software, Morningstar, Orange Business Services, Wipro
StartApp, Segment, Skyscanner, DigitalOcean, Comic Relief
Find out what your peers are saying about BMC Cloud Lifecycle Management vs. Snyk and other solutions. Updated: July 2025.
865,384 professionals have used our research since 2012.