Checkmarx One

Application Security Posture Management platform bundling SAST, SCA, IaC, container, API, secret, and DAST scanners under one risk model.

Quote-based pricingLast verified 2026-09-09

Deployment

Cloud · Self-Hosted (partial)

Languages

29+

Pricing model

Quote-based / Enterprise

Free tier

Partial

Workflow coverage

Where in the development lifecycle Checkmarx One operates.

Real-Time IDE FeedbackYes

VS Code, JetBrains, Visual Studio, Eclipse plugins; free KICS and SCA realtime scanners; ASCA as-you-type checks.

AI Agent Guardrail (MCP)Yes

Checkmarx Developer Assist is an agentic MCP-server-based assistant giving realtime prevention and remediation in the IDE.

Local CLI / Pre-CommitYes

Checkmarx One CLI ('cx') plus VS Code extension pre-commit scans; SCA Resolver runs resolution on-prem.

PR Inline ReviewYes

Decorates PRs/MRs with a summary comment of new and fixed vulnerabilities and policy violations.

Merge Gate BlockingYes

Policies can 'Break the Build' on violation; Protected Branches patterns govern which branches trigger scans and gates.

Full Repo ScanYes

Repository or zip scans up to 22M LOC; SAST and API Security also support incremental delta scans.

Scheduled / Continuous RescanPartial

Scans fire on push and pull/merge-request webhooks, plus Risk Recalculation; no scheduled or cron rescan documented.

Runtime / Production MonitoringNo

Cloud Insights correlates deployed images with source via third-party CNAPPs (Wiz, AWS, Sysdig), feeding runtime exposure into risk scores.

Analysis & detection

Every detection and code-analysis capability tracked for Checkmarx One.

SASTYes

Graph-based SAST needing no compilation; hundreds of queries per language, Best Fix Location, visual Attack Vector.

Taint / Data-Flow AnalysisYes

Attack Vector shows source-to-sink tainted data flow; Best Fix Location is chosen within that data-flow graph.

Secrets DetectionYes

Open-source 2ms engine scans working tree plus optional git commit history; also Slack, Discord, Confluence, Paligo.

Secrets ValidationPartial

Live Secrets Validation automatically determines if discovered secrets are still valid and exploitable; uses high-entropy analysis, contextual flagging, and structural pattern recognition. No provider-level verification; customers must rotate via issuing services.

SCA (Dependencies)Yes

File analysis, package-manager or lock-file resolution, and evidence analysis against Checkmarx vulnerability databases.

Reachability AnalysisYes

Exploitable Path reuses SAST to trace the call path to the vulnerable method; Python, Java, JavaScript, C# only.

Malicious Package DetectionYes

Suspected Malware taxonomy: typosquatting, StarJacking, ChainJacking, repojacking, account takeover, data exfiltration, crypto mining.

License ComplianceYes

Effective License designation, Full/Partial/No copyleft classification, license severity, and source-path evidence.

SBOM GenerationYes

CycloneDX (v1.3–v1.7 depending on surface) and SPDX v2.3, XML or JSON; can also scan an existing SBOM.

IaC ScanningYes

KICS engine across Ansible, CloudFormation, Dockerfile, Kubernetes, Terraform, Docker Compose, Crossplane, Pulumi, NifCloud.

Container ScanningYes

Dedicated Container Security scanner for Dockerfiles and named images, plus private registry auth for DockerHub, ECR, GCR, GAR.

Cloud Posture (CSPM)No

Cloud posture and runtime data come from third-party CNAPPs (Wiz, AWS, Sysdig) via Cloud Insights, not a native CSPM engine.

DAST / API ScanningYesadd-on

DAST is a platform engine and links to API Security, but requires separate DAST and API Security licenses.

Code Smells & MaintainabilityPartial

Custom SAST queries can target QA and business-logic purposes; no dedicated maintainability or code-smell engine.

Complexity MetricsNo

Not offered in vendor documentation reviewed as of 2026-09-05.

Duplication DetectionNo

Not offered in vendor documentation reviewed as of 2026-09-05.

Dead / Unused CodePartial

Enabling Exploitable Path surfaces genuinely unused dependencies; dead source-code detection not documented.

Test Coverage TrackingNo

Not offered in vendor documentation reviewed as of 2026-09-05.

Diff / New-Code CoverageNo

Not offered in vendor documentation reviewed as of 2026-09-05.

Architecture GovernanceNo

Not documented anywhere in the module catalog, docs, or release notes; no module-boundary governance capability exists.

Technical Debt QuantificationNo

Not offered in vendor documentation reviewed as of 2026-09-05.

Behavioral Delivery AnalyticsPartial

Analytics tracks vulnerability trends, remediation status, and metrics by team, project, and environment; no code-behavioural analytics.

AI Logic Bug DetectionPartial

SAST queries cover business-logic flaws; AI is used for triage and remediation, not for logic-bug discovery.

PR Summaries & WalkthroughsPartial

PR comment summarises new and fixed vulnerabilities and policy violations; no change-by-change walkthrough.

Custom Rule AuthoringYes

SAST Query Editor/Auditor writes and edits queries with an AI Query Builder GPT; custom presets for SAST and IaC.

Autofix SuggestionsYes

AI Security Champion gives confidence score, explanation, and proposed remediation; KICS and IDE auto-remediation.

Autofix via Agentic PRsYes

SCA Auto Pull Request opens a manifest version-bump PR (default Off); transitive remediation is beta, npm only.

AI Triage / False-Positive FilteringYes

Per-project 'AI Triage & Remediation' auto-analyses eligible new vulnerabilities during PR scans; triage predicates persist across scans.

Monorepo SupportNo

Not offered in vendor documentation reviewed as of 2026-09-05.

AI capabilities

AI Review EngineYes

AI Security Champion explains and fixes scanner findings; AI Triage analyses new pull-request vulnerabilities.

BYO Model / BYOKPartial

Azure AI selectable at tenant level and Developer Assist switchable between GitHub Copilot and Claude; no customer-key BYOK.

MCP ServerYes

Checkmarx Developer Assist is delivered as an agentic MCP server for IDE-based AI assistants.

AI Usage GovernanceNo

No AI-generated-code governance; AI Supply Chain Inventory covers AI components and dependencies instead.

Chat With ReviewerYes

AI Security Champion is chat-based inside scan-result panels; Assistant SAST/Query Builder GPT is a chat query editor.

Learns From FeedbackPartial

Triage state and comments persist across scans on recurring instances; no documented model learning from feedback.

Code Excluded From TrainingNo

Trust Center's AI Governance section describes a Responsible AI Framework with no explicit training-data exclusion commitment.

Models used

OpenAI (default for AI Security Champion)Azure AI (account/tenant-level alternative for AI Security Champion)GitHub Copilot (default for Checkmarx Developer Assist)Claude (alternative for Checkmarx Developer Assist)

Compliance & governance

Audit LogsYes

Audit Trail API/UI logs user management, SAST triage, and reporting events; 365-day default retention.

SSO / SAMLYes

IAM console supports platform-level SAML v2.0 (Okta, Azure AD, generic), OpenID Connect, and LDAP login.

Role-Based Access ControlYes

Predefined roles (Admin, Access Control Manager, User Manager, SCA Manager, SCA Scanner, SCA Viewer, External Platform User), custom roles, Teams, project scoping.

Compliance Reporting ExportsYes

Scan summaries (HTML, JSON, console, Markdown), full reports (JSON, SARIF, SonarQube), PDF with email delivery, SBOMs, CSV exports.

Certifications

ISO/IEC 27001:2022SOC 2 Type IINIST SSDF

Standards mapping

OWASP Top 10 (2013)OWASP Top 10 (2017)OWASP API Top 10PCI DSS v3.2FISMA 2014NIST SP 800-53HIPAACWECVSSUS Executive Order 14028 (cited for SBOM transparency)

Integrations

GitHubYes
GitHub Enterprise ServerYes
GitLabYes
GitLab Self-ManagedYes
BitbucketYes
Bitbucket Data CenterYes
Azure DevOpsYes
REST APIYes
CLIYes
WebhooksPartial

CI/CD systems

JenkinsGitHub ActionsGitLab CI/CD (v1 and v2 pipeline templates)BambooTeamCityAzure DevOpsMavenAny other CI/CD via the Checkmarx One CLI Tool (cx)

IDEs

Visual Studio CodeJetBrains (IntelliJ)Visual StudioEclipseCursor (VS Code extension validated)Windsurf (VS Code extension validated)Kiro (VS Code extension validated)

Issue trackers

JiraGitHub IssuesAzure BoardsServiceNow

Chat & notifications

SlackMicrosoft TeamsEmail

Pricing & plans

Trial: No trial for the core AppSec platform (quote-only). Self-serve free trial for Developer Assist (IDE assistant) via dev.checkmarx.com; AI Triage & Remediation offers a sales-assisted free trial via a Checkmarx sales rep.

Checkmarx One (modular bundle)Not published — custom quote via online bundle builderNo tier or company-size positioning documented — packaging is by module selection, not named tiers
  • Checkmarx One platform (unified dashboard, data model, API) always included as the foundation
  • SAST is core/included; Secrets Detection, IaC Security, API Security, SCA, Malicious Package Protection, MPI API, Container Scanning, AI Supply Chain Security, and DAST are separately selected add-on modules
  • No named tiers (Essential/Professional/Enterprise no longer appear on the live pricing page as of 19 Aug 2026)
  • No published per-module or per-seat price; quote generated after module selection
  • No minimum seat count documented
Legacy CxSAST / CxSCA / CxOSA (self-hosted product line)Contact for pricingOrganisations requiring fully self-hosted or on-premises deployment
  • Centralized, Distributed, and High Availability architectures
  • Dynamic on-demand Engine allocation via Kubernetes or Docker
  • Described as a legacy product line alongside the modern Checkmarx One platform
  • No pricing, sizing requirements, or feature parity statement versus Checkmarx One documented

Who it's for

Notable strengths

  • Nine first-party scanners (SAST, SCA, IaC/KICS, Container, API, Secret Detection, AI Supply Chain, OSSF Scorecard, DAST) feeding one ASPM risk view
  • Exploitable Path reachability reuses the SAST engine to confirm whether a vulnerable dependency method is actually called
  • Deep supply-chain attack taxonomy (typosquatting, StarJacking, ChainJacking, repojacking, account takeover, crypto mining) with dedicated policy conditions
  • Granular policy engine with package, vulnerability, malware, and license conditions including EPSS score and percentile, plus break-the-build enforcement
  • SBOM generation in CycloneDX and SPDX, producible before a full scan completes (--sbom-first) or from an existing SBOM without submitting source code

Notable limitations

  • No published pricing and no per-module price breakdown; the 2026 pricing page is a quote-only bundle builder with no named tiers
  • No product-level certifications (SOC 2, ISO 27001, FedRAMP) named in the documentation
  • Exploitable Path reachability is limited to Python, Java, JavaScript, and C#, and ignores incremental scans
  • Hard scan limits: 22M LOC per repository/zip, 5.5M LOC for IaC Security, 6 GB compressed upload, .git folders over 5 GB excluded
  • Analytics excludes the API Security scanner, defaults to production branches only, and retains just one year of data

Similar tools

Other Code Security Platform tools in the directory.

FAQ

When should you choose Checkmarx One?

Checkmarx One best fits Enterprise, Regulated industries. Nine first-party scanners (SAST, SCA, IaC/KICS, Container, API, Secret Detection, AI Supply Chain, OSSF Scorecard, DAST) feeding one ASPM risk view

What languages does Checkmarx One support?

Checkmarx One supports 29+ languages and frameworks, including Java, C#, VB.NET, ASP, VB6, C, C++, PHP, Apex, Ruby, and 19 more.

What does Checkmarx One integrate with?

Checkmarx One integrates with GitHub, GitHub Enterprise Server, GitLab, GitLab Self-Managed, Bitbucket, Bitbucket Data Center, Azure DevOps for source control, CI systems including Jenkins, GitHub Actions, GitLab CI/CD (v1 and v2 pipeline templates), Bamboo, TeamCity, and 3 more, and IDEs including Visual Studio Code, JetBrains (IntelliJ), Visual Studio, Eclipse, Cursor (VS Code extension validated), and 2 more.

What tools are similar to Checkmarx One?

Similar Code Security Platform tools tracked here include Aikido, Corgea, GitHub Advanced Security, Semgrep.

What are Checkmarx One's plans and pricing?

Checkmarx One has paid plans starting around Quote-based pricing; enterprise pricing is quote-only.