Code Security Platform
Checkmarx One
Application Security Posture Management platform bundling SAST, SCA, IaC, container, API, secret, and DAST scanners under one risk model.
Deployment
Cloud · Self-Hosted (partial)
Languages
29+
Pricing model
Quote-based / Enterprise
Free tier
Partial
Workflow coverage
Where in the development lifecycle Checkmarx One operates.
VS Code, JetBrains, Visual Studio, Eclipse plugins; free KICS and SCA realtime scanners; ASCA as-you-type checks.
Checkmarx Developer Assist is an agentic MCP-server-based assistant giving realtime prevention and remediation in the IDE.
Checkmarx One CLI ('cx') plus VS Code extension pre-commit scans; SCA Resolver runs resolution on-prem.
Decorates PRs/MRs with a summary comment of new and fixed vulnerabilities and policy violations.
Policies can 'Break the Build' on violation; Protected Branches patterns govern which branches trigger scans and gates.
Repository or zip scans up to 22M LOC; SAST and API Security also support incremental delta scans.
Scans fire on push and pull/merge-request webhooks, plus Risk Recalculation; no scheduled or cron rescan documented.
Cloud Insights correlates deployed images with source via third-party CNAPPs (Wiz, AWS, Sysdig), feeding runtime exposure into risk scores.
Analysis & detection
Every detection and code-analysis capability tracked for Checkmarx One.
Graph-based SAST needing no compilation; hundreds of queries per language, Best Fix Location, visual Attack Vector.
Attack Vector shows source-to-sink tainted data flow; Best Fix Location is chosen within that data-flow graph.
Open-source 2ms engine scans working tree plus optional git commit history; also Slack, Discord, Confluence, Paligo.
Live Secrets Validation automatically determines if discovered secrets are still valid and exploitable; uses high-entropy analysis, contextual flagging, and structural pattern recognition. No provider-level verification; customers must rotate via issuing services.
File analysis, package-manager or lock-file resolution, and evidence analysis against Checkmarx vulnerability databases.
Exploitable Path reuses SAST to trace the call path to the vulnerable method; Python, Java, JavaScript, C# only.
Suspected Malware taxonomy: typosquatting, StarJacking, ChainJacking, repojacking, account takeover, data exfiltration, crypto mining.
Effective License designation, Full/Partial/No copyleft classification, license severity, and source-path evidence.
CycloneDX (v1.3–v1.7 depending on surface) and SPDX v2.3, XML or JSON; can also scan an existing SBOM.
KICS engine across Ansible, CloudFormation, Dockerfile, Kubernetes, Terraform, Docker Compose, Crossplane, Pulumi, NifCloud.
Dedicated Container Security scanner for Dockerfiles and named images, plus private registry auth for DockerHub, ECR, GCR, GAR.
Cloud posture and runtime data come from third-party CNAPPs (Wiz, AWS, Sysdig) via Cloud Insights, not a native CSPM engine.
DAST is a platform engine and links to API Security, but requires separate DAST and API Security licenses.
Custom SAST queries can target QA and business-logic purposes; no dedicated maintainability or code-smell engine.
Not offered in vendor documentation reviewed as of 2026-09-05.
Not offered in vendor documentation reviewed as of 2026-09-05.
Enabling Exploitable Path surfaces genuinely unused dependencies; dead source-code detection not documented.
Not offered in vendor documentation reviewed as of 2026-09-05.
Not offered in vendor documentation reviewed as of 2026-09-05.
Not documented anywhere in the module catalog, docs, or release notes; no module-boundary governance capability exists.
Not offered in vendor documentation reviewed as of 2026-09-05.
Analytics tracks vulnerability trends, remediation status, and metrics by team, project, and environment; no code-behavioural analytics.
SAST queries cover business-logic flaws; AI is used for triage and remediation, not for logic-bug discovery.
PR comment summarises new and fixed vulnerabilities and policy violations; no change-by-change walkthrough.
SAST Query Editor/Auditor writes and edits queries with an AI Query Builder GPT; custom presets for SAST and IaC.
AI Security Champion gives confidence score, explanation, and proposed remediation; KICS and IDE auto-remediation.
SCA Auto Pull Request opens a manifest version-bump PR (default Off); transitive remediation is beta, npm only.
Per-project 'AI Triage & Remediation' auto-analyses eligible new vulnerabilities during PR scans; triage predicates persist across scans.
Not offered in vendor documentation reviewed as of 2026-09-05.
AI capabilities
AI Security Champion explains and fixes scanner findings; AI Triage analyses new pull-request vulnerabilities.
Azure AI selectable at tenant level and Developer Assist switchable between GitHub Copilot and Claude; no customer-key BYOK.
Checkmarx Developer Assist is delivered as an agentic MCP server for IDE-based AI assistants.
No AI-generated-code governance; AI Supply Chain Inventory covers AI components and dependencies instead.
AI Security Champion is chat-based inside scan-result panels; Assistant SAST/Query Builder GPT is a chat query editor.
Triage state and comments persist across scans on recurring instances; no documented model learning from feedback.
Trust Center's AI Governance section describes a Responsible AI Framework with no explicit training-data exclusion commitment.
Models used
Compliance & governance
Audit Trail API/UI logs user management, SAST triage, and reporting events; 365-day default retention.
IAM console supports platform-level SAML v2.0 (Okta, Azure AD, generic), OpenID Connect, and LDAP login.
Predefined roles (Admin, Access Control Manager, User Manager, SCA Manager, SCA Scanner, SCA Viewer, External Platform User), custom roles, Teams, project scoping.
Scan summaries (HTML, JSON, console, Markdown), full reports (JSON, SARIF, SonarQube), PDF with email delivery, SBOMs, CSV exports.
Certifications
Standards mapping
Integrations
CI/CD systems
IDEs
Issue trackers
Chat & notifications
Pricing & plans
Trial: No trial for the core AppSec platform (quote-only). Self-serve free trial for Developer Assist (IDE assistant) via dev.checkmarx.com; AI Triage & Remediation offers a sales-assisted free trial via a Checkmarx sales rep.
- Checkmarx One platform (unified dashboard, data model, API) always included as the foundation
- SAST is core/included; Secrets Detection, IaC Security, API Security, SCA, Malicious Package Protection, MPI API, Container Scanning, AI Supply Chain Security, and DAST are separately selected add-on modules
- No named tiers (Essential/Professional/Enterprise no longer appear on the live pricing page as of 19 Aug 2026)
- No published per-module or per-seat price; quote generated after module selection
- No minimum seat count documented
- Centralized, Distributed, and High Availability architectures
- Dynamic on-demand Engine allocation via Kubernetes or Docker
- Described as a legacy product line alongside the modern Checkmarx One platform
- No pricing, sizing requirements, or feature parity statement versus Checkmarx One documented
Who it's for
Notable strengths
- Nine first-party scanners (SAST, SCA, IaC/KICS, Container, API, Secret Detection, AI Supply Chain, OSSF Scorecard, DAST) feeding one ASPM risk view
- Exploitable Path reachability reuses the SAST engine to confirm whether a vulnerable dependency method is actually called
- Deep supply-chain attack taxonomy (typosquatting, StarJacking, ChainJacking, repojacking, account takeover, crypto mining) with dedicated policy conditions
- Granular policy engine with package, vulnerability, malware, and license conditions including EPSS score and percentile, plus break-the-build enforcement
- SBOM generation in CycloneDX and SPDX, producible before a full scan completes (--sbom-first) or from an existing SBOM without submitting source code
Notable limitations
- No published pricing and no per-module price breakdown; the 2026 pricing page is a quote-only bundle builder with no named tiers
- No product-level certifications (SOC 2, ISO 27001, FedRAMP) named in the documentation
- Exploitable Path reachability is limited to Python, Java, JavaScript, and C#, and ignores incremental scans
- Hard scan limits: 22M LOC per repository/zip, 5.5M LOC for IaC Security, 6 GB compressed upload, .git folders over 5 GB excluded
- Analytics excludes the API Security scanner, defaults to production branches only, and retains just one year of data
Similar tools
Other Code Security Platform tools in the directory.
FAQ
When should you choose Checkmarx One?
Checkmarx One best fits Enterprise, Regulated industries. Nine first-party scanners (SAST, SCA, IaC/KICS, Container, API, Secret Detection, AI Supply Chain, OSSF Scorecard, DAST) feeding one ASPM risk view
What languages does Checkmarx One support?
Checkmarx One supports 29+ languages and frameworks, including Java, C#, VB.NET, ASP, VB6, C, C++, PHP, Apex, Ruby, and 19 more.
What does Checkmarx One integrate with?
Checkmarx One integrates with GitHub, GitHub Enterprise Server, GitLab, GitLab Self-Managed, Bitbucket, Bitbucket Data Center, Azure DevOps for source control, CI systems including Jenkins, GitHub Actions, GitLab CI/CD (v1 and v2 pipeline templates), Bamboo, TeamCity, and 3 more, and IDEs including Visual Studio Code, JetBrains (IntelliJ), Visual Studio, Eclipse, Cursor (VS Code extension validated), and 2 more.
What tools are similar to Checkmarx One?
Similar Code Security Platform tools tracked here include Aikido, Corgea, GitHub Advanced Security, Semgrep.
What are Checkmarx One's plans and pricing?
Checkmarx One has paid plans starting around Quote-based pricing; enterprise pricing is quote-only.
Opens checkmarx.com in a new tab. Review Radar is not affiliated with Checkmarx.