All in-house developed code or a third-party developed code on our behalf is scanned via Fortify on Demand. Any results for unsecure code, vulnerabilities, or issues are passed back to the development teams for remediation.
Security Systems Analyst at a retailer with 5,001-10,000 employees
An extremely scalable, flexible, and stable solution that reduces the overall risk and gives us assurance
Pros and Cons
- "Being able to reduce risk overall is a very valuable feature for us."
- "They have a release coming out, which is full of new features. Based on their roadmap, there's nothing that I would suggest for them to put in it that they haven't already suggested. However, I am a customer, so I always think the pricing is something that could be improved. I am working with them on that, and they're very flexible. They work with their customers and kind of tailor the product to the customer's needs. So far, I am very happy with what they're able to provide. Their subscriptions could use a little bit of a reworking, but that would be about it."
What is our primary use case?
How has it helped my organization?
Secure code is an important part of our day-to-day development activities. So, having code out there gives us some reasonable assurance that it is not vulnerable or open to attack. It certainly makes our overall risk posture better.
What is most valuable?
Being able to reduce risk overall is a very valuable feature for us.
What needs improvement?
They have a release coming out, which is full of new features. Based on their roadmap, there's nothing that I would suggest for them to put in it that they haven't already suggested. However, I am a customer, so I always think the pricing is something that could be improved. I am working with them on that, and they're very flexible. They work with their customers and kind of tailor the product to the customer's needs. So far, I am very happy with what they're able to provide. Their subscriptions could use a little bit of a reworking, but that would be about it.
Buyer's Guide
Fortify on Demand
June 2025

Learn what your peers think about Fortify on Demand. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
857,028 professionals have used our research since 2012.
What do I think about the stability of the solution?
It is a very stable product. They are constantly updating and keeping it up to date. There are no issues.
What do I think about the scalability of the solution?
It is extremely scalable and flexible. We scan very small applications from our in-house innovations team and all the way up to millions of lines of code from our e-commerce teams. We currently have about 50 users, but the number varies. Some development teams are fairly small, and some are fairly large.
How are customer service and support?
Technical support is very good. I've never had an issue that we couldn't resolve. If we have a scan running and we need it to finish sooner, they will allocate extra resources to it if we identify. We've had very good results with their tech support.
Which solution did I use previously and why did I switch?
This is the first solution that was implemented. I inherited this from somebody else. We are a government organization, so we have to do an RFP next year to renew. We'll see how it goes.
How was the initial setup?
The basic scanning is not very complex. When you get into more detailed scanning such as APIs, the level of complexity is moderate. However, when you are scanning that type of application, you usually have teams available that know what to do and what the configuration needs to be. We did our first scan within two days.
What about the implementation team?
It was implemented in-house. We have in-house expertise. Our strategy was basically just to stand it up and use the default settings initially with a pilot. We planned to do some pilot scans and get a good feel for the product, and then adjust accordingly on an ongoing basis.
I managed it for two years single-handedly. As we expand and add more and more applications, we are adding extra hands. If we're looking at an FTE, equivalency is probably 0.5 to 0.75 people to manage it.
What was our ROI?
Looking for a return on investment on security is a little challenging. Some CIOs might argue one way or another. Some look at it as a cost, and some look at it as cost avoidance. I'm a security professional, and I look at it as cost avoidance. So, we're avoiding breaches, people being able to manipulate the code or cause any issues, and downtime. I always look at the positives of the product. If we eliminate any of the security risks or attack factors on these products before they go live, we're doing due diligence in making sure that the product stays up and running, especially for something like e-commerce.
What's my experience with pricing, setup cost, and licensing?
Their subscriptions could use a little bit of a reworking, but I am very happy with what they're able to provide.
What other advice do I have?
We plan to keep using this solution. Every year, we seem to have more and more code, and they add more and more features such as third-party library assessments, etc. Open source has become a big thing as companies try and save money, but with open source comes additional risk. This solution helps us mitigate the risk of those open-source components. So, we're using this more and more as we move forward.
The important part of this is automation. There are lots of automation options for this tool. Initially, trying to do it manually was a great start, but we kind of got lost a little bit along the way of implementing it. We should have done more automation right from the beginning, made it our standard, and created the policies. Sometimes, you put the cart before the horse. The tool does a great job, and you get lost in the results. It does provide good results and good information, but I think it's very important to have those policies and procedures in place right up front with this product. It will save you a lot of time in the end.
The biggest lesson that I have learned from using this product is that even if you have the best people, there are always vulnerabilities and things that will surprise you.
I would rate Micro Focus Fortify on Demand a nine out of ten.
Which deployment model are you using for this solution?
Private Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Production Manager for Nearshore SWaT at a computer software company with 1,001-5,000 employees
Stable and shows the vulnerabilities online while checking the code, but it is quite expensive
Pros and Cons
- "The feature that I find the most useful is being able to just see the vulnerabilities online while checking the code and then checking suggestions for fixing them."
- "The thing that could be improved is reducing the cost of usage and including some of the most pricey features, such as dynamic analysis and that sort of functionality, which makes the difference between different types of tools."
What is our primary use case?
We use Micro Focus Fortify on Demand to check the vulnerabilities of developments that we perform.
What is most valuable?
The feature that I find the most useful is being able to just see the vulnerabilities online while checking the code and then checking suggestions for fixing them.
What needs improvement?
The thing that could be improved is reducing the cost of usage and including some of the most pricey features, such as dynamic analysis and that sort of functionality, which makes the difference between different types of tools.
For how long have I used the solution?
I have been using this product for four years.
What do I think about the stability of the solution?
It is stable.
What do I think about the scalability of the solution?
It is scalable. However, it poses a challenge in terms of pricing and licensing.
How are customer service and technical support?
I haven't contacted their support, but I know that a team was in touch with Fortify technical support because they do get to have a lot of questions about migrating the software, licensing, and other stuff. They contact the support quite often. I know that they get responses, not always the ones they would like, but they do get a response from them.
Which solution did I use previously and why did I switch?
I have used SonarQube but not at the same level. It has some functionalities that are related to security. It does not go as deep as Micro Focus Fortify on Demand.
We have evaluated other tools that are competitors of Micro Focus Fortify on Demand, but we still decided to keep Micro Focus Fortify on Demand.
How was the initial setup?
I wasn't responsible for setting it up.
What about the implementation team?
We have a team that works with the product. All development teams work with this team to accomplish the goals. Everything was set up by this team, and afterward, the development team just has to look at the reports and vulnerabilities so that they can run scans.
What's my experience with pricing, setup cost, and licensing?
It is quite expensive. Pricing and the licensing model could be improved.
What other advice do I have?
Before using it, evaluate other possibilities because it's quite expensive if you don't have the need to use it. For example, replace it with SonarQube or another competitor's tool that may not do quite the same thing, but it is enough for what you want for your objectives. It could be a cheaper way to get to those goals.
I would rate Micro Focus Fortify on Demand a seven out of ten. Improvement in pricing would be the biggest thing that would improve the scoring.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Fortify on Demand
June 2025

Learn what your peers think about Fortify on Demand. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
857,028 professionals have used our research since 2012.
Vice President - Solution Architecture at a financial services firm with 10,001+ employees
Easy to use and the reporting is good, but does not support dynamic application security testing
Pros and Cons
- "Fortify on Demand is easy to use and the reporting is good."
- "The vulnerability analysis does not always provide guidelines for what the developer should do in order to correct the problem, which means that the code has to be manually inspected and understood."
What is our primary use case?
We are using Fortify on Demand as a static code analyzer. As it scans each application, it checks each line of code. When we are developing mobile applications there might be some kind of security vulnerability. One example is a check to see if information that is being transferred is not encrypted because this would be vulnerable to hackers who are trying to break into the system. We also look at whether were are using the network transport layer security.
Our overall goal at this time is to protect our mobile app because it is one of the ways that hackers can break into the system.
What is most valuable?
Fortify on Demand is easy to use and the reporting is good.
As for the static code analysis functionality, it is doing the job that it is supposed to do.
What needs improvement?
This solution cannot do dynamic application security testing. It needs to be able to simulate a situation where a hacker is trying to break into the system.
The vulnerability analysis does not always provide guidelines for what the developer should do in order to correct the problem, which means that the code has to be manually inspected and understood. Adding more information to provide a better analysis would be an improvement.
This solution would benefit from having more customization available for the reports.
For how long have I used the solution?
We have been evaluating Fortify on Demand for close to a year.
What do I think about the stability of the solution?
Fortify on Demand has been stable from what I have seen. We have not had any problem with the reports, and we have not seen any instability or glitches.
What do I think about the scalability of the solution?
In our trial, there are seven or eight applications that are relying on this solution. Different departments in our company have their own technology centers in different locations, and I am not aware of what the other departments are doing.
How are customer service and technical support?
I have not interacted with the Fortify on Demand technical support team directly. Our own infrastructure support is the group that would deal with them. My team only communicates with our internal support.
Which solution did I use previously and why did I switch?
We did not use another solution prior to starting our evaluation that includes Fortify on Demand. People were relying on some open-source static code analyzers. However, I don't think that it was very reliable.
How was the initial setup?
My understanding is the this is not a difficult solution to manage and maintain.
What about the implementation team?
Our server infrastructure team handles the deployment and maintenance of this solution. They update it regularly as patches or new versions are released. They look into all of the tools that we use and perform the installation, as well as manage them.
Which other solutions did I evaluate?
We are currently using WebInspect but it does not satisfy all of our requirements. We are continuing to research other tools from other vendors, including open-source technologies. We have not fully decided yet. Before deciding on any product or vendor, we have to look at the whole cost of procuring the product license, as well as the recurring cost.
What other advice do I have?
Fortify on Demand is a product that I recommend but the suitability of this solution depends on exactly what the requirements are. Every product has a unique feature as well as limitations with respect to what it can and can not do. What it comes down to is how the application is built, as well as the technology stack. The licensing costs are also something that needs to be considered.
Overall, it is a very good tool and it works well for what it is designed for.
I would rate this solution a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Chief Information Officer at Location world
Has good price and support and works very well for web applications
Pros and Cons
- "We have the option to test applications with or without credentials."
- "They have very good support, but there is always room for improvement."
What is our primary use case?
We use this solution for our web applications.
What is most valuable?
We have the option to scan web applications on demand. We have the option to do dynamic analysis. We also have an on-premise solution for static code analysis.
We have the option to test applications with or without credentials.
What needs improvement?
Overall, it's very good. They have very good support, but there is always room for improvement.
For how long have I used the solution?
I've been using this solution for two to three years.
How are customer service and support?
They are helpful, and we have a good relationship with them. I'd rate them an eight out of ten.
How would you rate customer service and support?
Positive
How was the initial setup?
It was straightforward. It took us two or three months because we had to integrate with our DevOps and pipeline solutions. It took a bit of extra time.
In terms of maintenance, we need to update the version. Micro Focus releases new versions every two months or so.
What about the implementation team?
We had our DevOps manager, and then we had two people from IT. We also had the support of the provider. We also worked with a partner to help us to implement faster.
What's my experience with pricing, setup cost, and licensing?
I'd rate it an eight out of ten in terms of pricing.
What other advice do I have?
Overall, I'd rate it a nine out of ten. We are very satisfied with it.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Advisor Solution Architect at a tech services company with 10,001+ employees
Moderately priced solution with fantastic stability
Pros and Cons
- "Fortify on Demand's best feature is that there's no need to install and configure it locally since it's on the cloud."
- "An improvement would be the ability to get vulnerabilities flowing automatically into another system."
What is our primary use case?
I mainly use Fortify on Demand for static scanning.
What is most valuable?
Fortify on Demand's best feature is that there's no need to install and configure it locally since it's on the cloud.
What needs improvement?
An improvement would be the ability to get vulnerabilities flowing automatically into another system.
For how long have I used the solution?
I've been using Fortify on Demand for over a year.
What do I think about the stability of the solution?
Fortify on Demand's stability is fantastic - I've never seen slowness, and it performs consistently.
Which solution did I use previously and why did I switch?
I previously used ShiftLeft, but Fortify on Demand gives me a portal, and it's much easier to get details about the issues affecting us.
How was the initial setup?
The initial setup is very simple because no installation is necessary - you just need to access the application and configure it.
What about the implementation team?
We used a vendor team.
What's my experience with pricing, setup cost, and licensing?
Fortify on Demand is moderately priced, but its pricing could be more flexible.
What other advice do I have?
I would rate Fortify on Demand nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Senior Manager at valuelabs LLP
It supports most languages and integrates well with other solutions
Pros and Cons
- "Fortify supports most languages. Other tools are limited to Java and other typical languages. IBM's solutions aren't flexible enough to support any language. Fortify also integrates with lots of tools because it has API support."
- "We have some stability issues, but they are minimal."
What is our primary use case?
Fortify is used for static scans — cold-scanning.
What is most valuable?
Fortify supports most languages. Other tools are limited to Java and other typical languages. IBM's solutions aren't flexible enough to support any language. Fortify also integrates with lots of tools because it has API support.
What needs improvement?
We have some stability issues, but they are minimal.
For how long have I used the solution?
We've been using Fortify for two or three years
What do I think about the stability of the solution?
Fortify is stable.
What do I think about the scalability of the solution?
Fortify is scalable.
How are customer service and support?
Whenever we have any issues, Micro Focus support has been helpful. They have lots of products, and they're established in the market. When you open a ticket, you get an immediate response by phone.
How was the initial setup?
The initial setup is straightforward and the second or third-tier support is available whenever we face an issue or something. Most of the components are plug-and-play, so it doesn't take much time.
What other advice do I have?
I rate Micro Focus Fortify on Demand. This is a good solution for doing static analysis. There is also a dynamic component, but we haven't used it because we are unsure how flexible it is. We are using it only for static scanning.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Security Information Manager at a tech services company with 10,001+ employees
Solid usability for security and vulnerability issues
Pros and Cons
- "The features that I have found most valuable include its security scan, the vulnerability finds, and the web interface to search and review the issues."
- "In terms of what could be improved, we need more strategic analysis reports, not just for one specific application, but for the whole enterprise. In the next release, we need more reports and more analytic views for all the applications. There is no enterprise view in Fortify. I would like enterprise views and reports."
What is our primary use case?
I use it for SAST, security analysis static code.
What is most valuable?
The features that I have found most valuable include its security scan, the vulnerability finds, and the web interface to search and review the issues.
What needs improvement?
In terms of what could be improved, we need more strategic analysis reports, not just for one specific application, but for the whole enterprise.
In the next release, we need more reports and more analytic views for all the applications. There is no enterprise view in Fortify. I would like enterprise views and reports.
For how long have I used the solution?
I am using Micro Focus Fortify on Demand for one year.
What do I think about the stability of the solution?
It is very stable.
What do I think about the scalability of the solution?
It is scalable. Micro Focus Fortify on Demand requires a big hardware with a big processing capacity, but it is scalable.
How are customer service and support?
Their customer support is very good. I sometimes need it, and I get the answer quickly. They are very helpful.
How was the initial setup?
The initial setup is not so easy, but not so difficult. I would say it is medium difficulty.
What other advice do I have?
On a scale of one to ten, I would give Micro Focus Fortify on Demand an eight.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Provides a lower number of false positives and is reliable and easy to use
Pros and Cons
- "The UL is easy to use compared to that of other tools, and it is highly reliable. The findings provide a lower number of false positives."
- "Integration to CI/CD pipelines could be improved. The reporting format could be more user friendly so that it is easy to read."
What is our primary use case?
We use it for normal, daily source code reviews and code analysis.
What is most valuable?
The UL is easy to use compared to that of other tools, and it is highly reliable. The findings provide a lower number of false positives.
It is easy to install, and the cost is fair.
What needs improvement?
I would like to see easier integration to CI/CD pipelines. The reporting format could be more user friendly so that it is easy to read.
For how long have I used the solution?
I've been working with Micro Focus Fortify on Demand for three years.
What do I think about the stability of the solution?
There were some issues with it before, but I think they have been fixed now.
What do I think about the scalability of the solution?
There were several limitations when I was using it before, but I am sure that they have been fixed by now.
How are customer service and technical support?
My experience with technical support has been very good.
How was the initial setup?
The initial setup is straightforward and not that complex. We had some support from IT.
What's my experience with pricing, setup cost, and licensing?
The price is fair compared to that of other solutions.
What other advice do I have?
If you are looking for commercial tools, Micro Focus Fortify on Demand is one of the best tools. It has all the features compared to those of its competitors. It is also within budget, if you're really focusing on security.
I would rate it at eight on a scale from one to ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Buyer's Guide
Download our free Fortify on Demand Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2025
Popular Comparisons
SonarQube Server (formerly SonarQube)
Checkmarx One
Veracode
Coverity
Mend.io
OWASP Zap
SonarQube Cloud (formerly SonarCloud)
GitHub Advanced Security
Sonatype Lifecycle
Acunetix
HCL AppScan
PortSwigger Burp Suite Professional
Qualys Web Application Scanning
Buyer's Guide
Download our free Fortify on Demand Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What Is The Biggest Difference Between Fortify on Demand And SonarQube?
- What are the costs for Micro Focus Fortify on Demand?
- If you had to both encrypt and compress data during transmission, which would you do first and why?
- When evaluating Application Security, what aspect do you think is the most important to look for?
- What are the Top 5 cybersecurity trends in 2022?
- What are the threats associated with using ‘bogus’ cybersecurity tools?
- We're evaluating Tripwire, what else should we consider?
- Which application security solutions include both vulnerability scans and quality checks?
- Is SonarQube the best tool for static analysis?
- Why Do I Need Application Security Software?