Try our new research platform with insights from 80,000+ expert users

Check Point CloudGuard Code Security vs Checkmarx One comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 7, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Check Point CloudGuard Code...
Ranking in DevSecOps
8th
Average Rating
8.4
Reviews Sentiment
7.5
Number of Reviews
12
Ranking in other categories
Data Loss Prevention (DLP) (13th)
Checkmarx One
Ranking in DevSecOps
2nd
Average Rating
7.6
Reviews Sentiment
6.9
Number of Reviews
70
Ranking in other categories
Application Security Tools (3rd), Static Application Security Testing (SAST) (3rd), Vulnerability Management (21st), Static Code Analysis (2nd), API Security (3rd), Risk-Based Vulnerability Management (8th)
 

Mindshare comparison

As of May 2025, in the DevSecOps category, the mindshare of Check Point CloudGuard Code Security is 1.6%, up from 1.1% compared to the previous year. The mindshare of Checkmarx One is 16.5%, down from 21.9% compared to the previous year. It is calculated based on PeerSpot user engagement data.
DevSecOps
 

Featured Reviews

Nagendra Nekkala. - PeerSpot reviewer
Good security and functionality with helpful support
The security on offer is great. It's secure in terms of testing all the workloads. We can test across any workload or multiple clouds. It offers unified prevention. It also offers posture management by verifying proper scanning. We use the GSL builder. It's easy to write customer rules or policies using it. Of course, you do need proper training on the product first. It takes around one week to get trained. We've been able to reduce human error, and you can build the rules for better coverage. It provides functionality across cloud providers. The solution helps us save time. We've reduced the amount of time spent by 25%. Its unified security management console is a very complete dashboard. We can see all security threats and can gain visibility into what is happening. We have access to automation and can monitor the security of IT systems. The product offers role-based access control so that we can set up different privileges for admin users. Cloud Guard Spectrum is good for automating our organization's security across assets, workloads, and multiple clouds. With it, we have advanced pre-prevention across the cloud security network. It works for on-premises also. We can easily determine our organization's security posture. It will ensure my application's availability time across the enterprise. Network security helped us reduce our compliance and audit activities. We've saved about 20% of our time. Having a cloud detection response helps to very quickly identify security threats in our environment. It's automated so it saves us time. That way, people can work on other projects. On any given day, we're spending 20% less time in general worrying about detection and response. Our security operations are saving a lot of time using a unified platform.
Rohit Kesharwani - PeerSpot reviewer
Provides good security analysis and security identification within the source code
We integrate Checkmarx into our software development cycle using GitLab's CI/CD pipeline. Checkmark has been the most helpful for us in the development stage. The solution's incremental scanning feature has impacted our development speed. The solution's vulnerability detection is around 80% to 90% accurate. I would recommend Checkmarx to other users because it is one of the good tools for doing security analysis and security identification within the source code. Overall, I rate Checkmarx a nine out of ten.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Knowing what measures we must take allows us to reduce costs associated with security in the cloud by providing early identification of a risk or a possible security breach."
"Having a cloud detection response helps to very quickly identify security threats in our environment."
"It helped us to reduce vulnerabilities."
"We have a strong sense of security assurance when utilizing CloudGuard, as it consistently delivers outstanding protection capabilities."
"Automation has helped a lot to identify and automatically execute policies, rules, and blocks due to its machine learning."
"We have had a number of real events where developers accidentally made commits of API keys, and we were able to detect and begin response actions in minutes. We had the API key revoked in less than five minutes in such events."
"Compared to what we used before, it's helping us to be more efficient in managing our traffic."
"Its fastest and most outstanding characteristic is ensuring a development line that will not lead to applying applications or code development."
"The most valuable features are the easy to understand interface, and it 's very user-friendly."
"The solution communicates where to fix the issue for the purpose of less iterations."
"The user interface is excellent. It's very user friendly."
"The solution improved the efficiency of our code security reviews. It helps tremendously because it finds hundreds of potential problems sometimes."
"The main advantage of this solution is its centralized reporting functionality, which lets us track issues, then see and report on the priorities via a web portal."
"The most valuable feature is the application tracking reporting."
"Vulnerability details is valuable."
"The most valuable features of Checkmarx are its integration with multiple SCM solutions and CICD tools, its ability to scale according to user licenses, and the quick scanning process."
 

Cons

"They could include web functionalities such as sandboxing."
"The enhancements are needed in the logging system and log management processes."
"I would like this solution to be extended to cellular devices or tablets."
"The ease of use could be better."
"There needs to be better security around API integration."
"We need to have many of the baselines or development guides providing less complex writing or development."
"This is a highly technical solution for users who do not have security experience. It requires specialized knowledge of configurations to use it correctly."
"There are a lot of opportunities for how they can use their technology to do more. That would be more like sensitive data discovery and other things besides Git Repos, but then you are expanding the scope of what necessarily their product is."
"I can't create a business case with multiple-factor authentication."
"We can run only one project at a time."
"I would like to see the DAST solution in the future."
"They could work to improve the user interface. Right now, it really is lacking."
"Checkmarx is not good because it has too many false positive issues."
"We want to have a holistic view of the portfolio-level dashboard and not just an individual technical project level."
"We are trying to find out if there is a way to identify the run-time null values. I am analyzing different tools to check if there is any tool that supports run-time null value identification, but I don't think any of the tools in the market currently supports this feature. It would be helpful if Checkmarx can identify and throw an exception for a null value at the run time. It would make things a lot easier if there is a way for Checkmarx to identify nullable fields or hard-coded values in the code. The accessibility for customized Checkmarx rules is currently limited and should be improved. In addition, it would be great if Checkmarx can do static code and dynamic code validation. It does a lot of security-related scanning, and it should also do static code and dynamic code validation. Currently, for security-related validation, we are using Checkmarx, and for static code and dynamic code validation, we are using some other tools. We are spending money on different tools. We can pay a little extra money and use Checkmarx for everything."
"As the solution becomes more complex and feature rich, it takes more time to debug and resolve problems. Feature-wise, we have no complaints, but Checkmarx becomes harder to maintain as the product becomes more complex. When I talk to support, it takes them longer to fix the problem than it used to."
 

Pricing and Cost Advice

"It is extremely affordable and high value for cost."
"​Checkmarx is not a cheap scanning tool, but none of the security tools are cheap. Checkmarx is a powerful scanning tool, and it’s essential to have one of these products."
"Most of my customers opted for a perpetual license. They prefer to pay the highest amount up front for the perpetual license and then pay for additional support annually."
"This solution is expensive. The customized package allows you to buy additional users at any time."
"The solution is costly."
"If you want more, you have to pay more. You have to pay for additional modules or functionalities."
"It's relatively expensive."
"The solution's price is high and you pay based on the number of users."
"I would rate the solution’s pricing an eight out of ten. The tool’s pricing is higher than others and it is for the license alone."
report
Use our free recommendation engine to learn which DevSecOps solutions are best for your needs.
849,963 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
28%
Financial Services Firm
13%
Manufacturing Company
10%
Government
9%
Financial Services Firm
21%
Computer Software Company
14%
Manufacturing Company
10%
Government
5%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Spectral?
We have had a number of real events where developers accidentally made commits of API keys, and we were able to detect and begin response actions in minutes. We had the API key revoked in less than...
What needs improvement with Spectral?
The solution should improve vulnerability in-depth, false-positive reduction, integration with other tools, performance optimization, and the user interface.
What alternatives are there for Fortify WebInspect and Fortify SCA?
I would like to recommend Checkmarx. With Checkmarx, you are able to have an all in one solution for SAST and SCA as well. Veracode is only a cloud solution. Hope this helps.
What do you like most about Checkmarx?
Compared to the solutions we used previously, Checkmarx has reduced our workload by almost 75%.
What is your experience regarding pricing and costs for Checkmarx?
The pricing is relatively expensive due to the product's quality and performance, but it is worth it.
 

Also Known As

Spectral
No data available
 

Overview

 

Sample Customers

Doddle, Bangalore International Airport, Grupo financiero ACOBO, DigitalTrack
YIT, Salesforce, Coca-Cola, SAP, U.S. Army, Liveperson, Playtech Case Study: Liveperson Implements Innovative Secure SDLC
Find out what your peers are saying about Check Point CloudGuard Code Security vs. Checkmarx One and other solutions. Updated: April 2025.
849,963 professionals have used our research since 2012.