# Burp Suite vs Checkmarx

**Leader by Vioscale score:** Checkmarx

| Attribute | Burp Suite | Checkmarx |
|---|---|---|
| **Vioscale score** | 37.6 (41% (low)) | 53.7 (46% (low)) |
| deployment.options | - | `{"cloud":true}` |
| description.long | A security testing tool for web applications and APIs that combines manual and automated vulnerability scanning. Includes CI pipeline integration and is used by security professionals, AppSec teams, and development organizations. | An integrated platform combining static analysis, dynamic testing, dependency scanning, and AI-powered agents to identify and prioritize vulnerabilities across the entire software development lifecycle, from code to cloud deployment. |
| features.capabilities | `{"dast":true,"ci_native":true}` | `{"sca":true,"dast":true,"sast":true,"sbom":true,"hosting":"cloud","ci_native":true,"ide_plugin":true,"reachability":true}` |
| integrations.count | - | 1 |
| integrations.list | - | `[{"name":"Wiz"}]` |
| market.availability | - | `{"hqCountry":"IL","primaryMarkets":["US","GB"],"availabilityScope":"global","availableCountries":["US","GB","PT","FR","AU","IN","SG","DE","IL"],"notAvailableCountries":[]}` |
| platform.support | - | `{"web":true}` |
| pricing | - | `{"type":"quote","plans":[{"free":false,"name":"Essentials","summary":"Custom quote required","features":["SAST","SCA","API Security","ASPM visibility","Core reporting"],"description":"Core application security coverage. Establish a unified foundation for identifying, managing, and reporting application risk.","contactSales":true},{"free":false,"name":"Professional","summary":"Custom quote required","features":["Everything in Essentials","DAST","IaC Security","AI Security","Advanced ASPM","PR Decorations"],"description":"Advanced protection and AI-powered security. Scale your AppSec program with AI-assisted remediation and deeper multi-layer coverage.","contactSales":true},{"free":false,"name":"Enterprise","summary":"Custom quote required","features":["Everything in Professional","Supply Chain Security","Container Security","Runtime Protection","Custom Policies","Executive Reporting"],"description":"Complete coverage and full compliance. Maximum coverage and control for organizations with the most demanding security requirements.","contactSales":true}],"summary":"All three tiers require custom quote. No published per-seat or usage-based pricing.","freeTier":false,"sourceUrl":"https://checkmarx.com","retrievedAt":"2026-08-05T14:23:25.473Z"}` |
| pricing.free_tier | - | no |
| pricing.model | commercial | commercial |
| pricing.price_level | - | unknown |
| pricing.transparent | - | no |
| reliability.status_page | yes | - |
| security.fedramp | yes | yes |
| security.gdpr | yes | yes |
| security.hipaa | yes | - |
| security.iso27001 | - | yes |
| security.pci | yes | - |
| security.soc2 | - | yes |

## Capabilities (DevSecOps Tools)

| Capability | Burp Suite | Checkmarx |
|---|:--:|:--:|
| **Scan types** |  |  |
| SAST (static analysis) | - | ✓ |
| DAST (dynamic analysis) | ✓ | ✓ |
| SCA / dependency scanning | - | ✓ |
| Secret scanning | - | - |
| Container / image scanning | - | - |
| IaC misconfiguration scanning | - | - |
| **Governance** |  |  |
| OSS licence compliance | - | - |
| SBOM generation (SPDX/CycloneDX) | - | ✓ |
| **Remediation** |  |  |
| Automated fix / upgrade PRs | - | - |
| **Prioritisation** |  |  |
| Reachability / exploitability prioritisation | - | ✓ |
| **Deployment** |  |  |
| Hosting | - | Cloud only |
| **Integration** |  |  |
| First-class CI / pipeline integration | ✓ | ✓ |
| In-editor / IDE scanning | - | ✓ |
| **Licensing** |  |  |
| OSS engine available | - | - |

*Source: Vioscale. Generated 2026-09-01T17:31:42.306Z. "-" = undocumented, not absent.*
