Try our new research platform with insights from 80,000+ expert users

Checkmarx One vs Pentera comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Oct 9, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
7.5
Organizations saw ROI with Checkmarx One via improved development speed, cost savings, and enhanced security, despite quantification challenges.
Sentiment score
5.2
Pentera automates security tests, proving valuable for retests, but rising licensing costs pose ROI challenges for some users.
Some customers consider the ROI favorable, but facing difficulties now due to changes in the licensing model, which has made it more expensive compared to last year.
 

Customer Service

Sentiment score
7.1
Checkmarx One offers fast, expert support, though some users note resolution delays and additional support charges.
Sentiment score
6.0
Pentera's support team is reliable and responsive, but documentation needs updating; users rate support highly despite some inconsistency.
 

Scalability Issues

Sentiment score
7.1
Checkmarx One excels in scalability, integration, and automation, efficiently managing various organizational sizes though licensing can be restrictive.
Sentiment score
7.0
Pentera is highly scalable with adaptable equipment requirements, earning strong satisfaction ratings across various enterprise environments.
 

Stability Issues

Sentiment score
7.2
Checkmarx One is reliable with some performance issues during large scans; user ratings vary from six to ten.
Sentiment score
7.3
Pentera is praised for high stability, with most users rating it highly despite minor initial setup concerns.
I would rate the stability of this solution a nine on a scale of 1 to 10 where one is low stability and 10 is high.
 

Room For Improvement

Checkmarx One needs enhanced false positive reduction, language support, CD integration, pricing, UI, reporting, and automation improvements.
Pentera struggles with cost, licensing flexibility and needs better virtualization, dashboards, hardware support, and detailed credential information.
It could suggest how the code base is written and automatically populate the source code with three different solution options to choose from.
When the IP is imported into a system, we cannot withdraw or revoke the license.
 

Setup Cost

Checkmarx One offers high quality and performance, though its pricing varies and is often seen as expensive yet competitive.
Pentera's pricing receives mixed reviews, though many appreciate its value in effectively assessing ransomware protection.
 

Valuable Features

Checkmarx One provides comprehensive vulnerability analysis with intuitive features, efficient reporting, CI/CD integration, and extensive language support.
Pentera offers automated vulnerability assessments with valued features like attack surface mapping, AI reporting, and quick, effective processes.
My experience with the initial setup of Checkmarx One is straightforward; it is not complex compared to other tools that I have tried.
We can automate the Pentera processes by automatically creating scenarios to validate the system.
 

Categories and Ranking

Checkmarx One
Average Rating
7.6
Reviews Sentiment
6.9
Number of Reviews
71
Ranking in other categories
Application Security Tools (3rd), Static Application Security Testing (SAST) (3rd), Vulnerability Management (24th), Static Code Analysis (3rd), API Security (5th), DevSecOps (5th), Risk-Based Vulnerability Management (9th)
Pentera
Average Rating
7.8
Reviews Sentiment
6.7
Number of Reviews
10
Ranking in other categories
Penetration Testing Services (2nd), Breach and Attack Simulation (BAS) (2nd)
 

Mindshare comparison

Checkmarx One and Pentera aren’t in the same category and serve different purposes. Checkmarx One is designed for Application Security Tools and holds a mindshare of 9.9%, down 14.3% compared to last year.
Pentera, on the other hand, focuses on Breach and Attack Simulation (BAS), holds 29.3% mindshare, up 28.3% since last year.
Application Security Tools
Breach and Attack Simulation (BAS)
 

Featured Reviews

Syed Hasan - PeerSpot reviewer
Partner experiences excellent technical support and seamless initial setup
In my opinion, if we are able to extract or show the report, and because everything is going towards agent tech and GenAI, it would be beneficial if it could get integrated with our code base and do the fix automatically. It could suggest how the code base is written and automatically populate the source code with three different solution options to choose from. This would be really helpful.
Sabbir Ahmed - PeerSpot reviewer
Comprehensive attack surface coverage and real-world threat emulation strengthen security while licensing models need improvement
Comprehensive Attack Surface includes several features. Omni Attack Surface discovers, assesses, and exploits vulnerabilities across both internal networks and external assets, including cloud environments from a single platform. External Attack Surface Management (EASM) and Internal Network Validation test internal security controls and identify weaknesses within the internal network. Automated Penetration Testing features are provided through the Pentera Surface module. Surface provides automated validation and penetration testing features with a proactive, continuous, and highly realistic approach to cybersecurity validation, helping organizations understand and reduce their true cyber exposure. They have AI-based reporting that leverages AI to identify patterns of exploitability over time, aggregate results across sites, and highlight recurring weaknesses. They offer two types of reports: an elaborate technical report for CTOs and an Executive Summary for management. When customers see the reports after completing the POC, they are impressed by how detailed the technical report is, while management can understand what actions need to be taken to protect their network and infrastructure. Recent Gartner reports indicate that traditional VAPT companies perform vulnerability testing at specific times, which creates security gaps. Pentera provides continuous validation, running 24/7 in the infrastructure. This means when any vulnerability appears due to firmware upgrades, OS updates, or software changes, it can be automatically identified in real-time.
report
Use our free recommendation engine to learn which Application Security Tools solutions are best for your needs.
862,543 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
20%
Computer Software Company
14%
Manufacturing Company
10%
Government
6%
Financial Services Firm
13%
Computer Software Company
13%
Manufacturing Company
11%
Educational Organization
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What alternatives are there for Fortify WebInspect and Fortify SCA?
I would like to recommend Checkmarx. With Checkmarx, you are able to have an all in one solution for SAST and SCA as well. Veracode is only a cloud solution. Hope this helps.
What do you like most about Checkmarx?
Compared to the solutions we used previously, Checkmarx has reduced our workload by almost 75%.
What is your experience regarding pricing and costs for Checkmarx?
The pricing is relatively expensive due to the product's quality and performance, but it is worth it.
What do you like most about Pentera?
What I like the most about Pentera is its solution-oriented approach.
What needs improvement with Pentera?
The licensing and IP management need improvement. When the IP is imported into a system, we cannot withdraw or revoke the license.
What is your primary use case for Pentera?
I am using the OpenIntra solution for pentesting and managing candidates in my environment. I also use this solution for house customers.
 

Comparisons

 

Overview

 

Sample Customers

YIT, Salesforce, Coca-Cola, SAP, U.S. Army, Liveperson, Playtech Case Study: Liveperson Implements Innovative Secure SDLC
Blackstone Group Caterpillar Apria Healthcare Taylor Vinters Sandler Capital Management Drawbridge BNP Paribas British Red Cross
Find out what your peers are saying about Checkmarx One vs. Pentera and other solutions. Updated: January 2025.
862,543 professionals have used our research since 2012.