# Checkmarx vs Socket

| Attribute | Checkmarx | Socket |
|---|---|---|
| **Vioscale score** | 53.7 (46% (low)) | 49.9 (71% (medium)) |
| deployment.options | `{"cloud":true}` | `{"cloud":true,"self_hosted":true}` |
| description.long | An integrated platform combining static analysis, dynamic testing, dependency scanning, and AI-powered agents to identify and prioritize vulnerabilities across the entire software development lifecycle, from code to cloud deployment. | A developer-focused security platform that analyzes the behavior of software dependencies to identify and block malware, mining software, and other supply chain threats. Socket protects against both known and emerging threats with real-time detection across package managers and programming languages. |
| features.capabilities | `{"sca":true,"dast":true,"sast":true,"sbom":true,"hosting":"cloud","ci_native":true,"ide_plugin":true,"reachability":true}` | `{"sca":true,"sast":true,"hosting":"both","ci_native":true,"ide_plugin":true,"open_source":true,"reachability":true,"secret_scanning":true,"container_scanning":true,"license_compliance":true}` |
| integrations.count | 1 | 6 |
| integrations.list | `[{"name":"Wiz"}]` | `[{"name":"GitHub"},{"name":"npm"},{"name":"PyPI"},{"name":"Cargo"},{"name":"Go packages"},{"name":"VSCode"}]` |
| market.availability | `{"hqCountry":"IL","primaryMarkets":["US","GB"],"availabilityScope":"global","availableCountries":["US","GB","PT","FR","AU","IN","SG","DE","IL"],"notAvailableCountries":[]}` | `{"hqCountry":"US","primaryMarkets":[],"availabilityScope":"global","availableCountries":[],"notAvailableCountries":[]}` |
| platform.support | `{"web":true}` | `{"cli":true,"web":true}` |
| pricing | `{"type":"quote","plans":[{"free":false,"name":"Essentials","summary":"Custom quote required","features":["SAST","SCA","API Security","ASPM visibility","Core reporting"],"description":"Core application security coverage. Establish a unified foundation for identifying, managing, and reporting application risk.","contactSales":true},{"free":false,"name":"Professional","summary":"Custom quote required","features":["Everything in Essentials","DAST","IaC Security","AI Security","Advanced ASPM","PR Decorations"],"description":"Advanced protection and AI-powered security. Scale your AppSec program with AI-assisted remediation and deeper multi-layer coverage.","contactSales":true},{"free":false,"name":"Enterprise","summary":"Custom quote required","features":["Everything in Professional","Supply Chain Security","Container Security","Runtime Protection","Custom Policies","Executive Reporting"],"description":"Complete coverage and full compliance. Maximum coverage and control for organizations with the most demanding security requirements.","contactSales":true}],"summary":"All three tiers require custom quote. No published per-seat or usage-based pricing.","freeTier":false,"sourceUrl":"https://checkmarx.com","retrievedAt":"2026-08-05T14:23:25.473Z"}` | `{"type":"hybrid","summary":"Free tier available with GitHub app and Socket Firewall; enterprise pricing available","freeTier":true,"sourceUrl":"https://socket.dev/blog/github-actions-pricing-whiplash","retrievedAt":"2026-08-14T09:21:38.534Z"}` |
| pricing.free_tier | no | yes |
| pricing.model | commercial | freemium |
| pricing.price_level | unknown | low |
| pricing.transparent | no | - |
| reliability.status_page | - | yes |
| security.disclosure_policy | - | yes |
| security.fedramp | yes | - |
| security.gdpr | yes | - |
| security.iso27001 | yes | - |
| security.soc2 | yes | yes |

## Capabilities (DevSecOps Tools)

| Capability | Checkmarx | Socket |
|---|:--:|:--:|
| **Scan types** |  |  |
| SAST (static analysis) | ✓ | ✓ |
| DAST (dynamic analysis) | ✓ | - |
| SCA / dependency scanning | ✓ | ✓ |
| Secret scanning | - | ✓ |
| Container / image scanning | - | ✓ |
| IaC misconfiguration scanning | - | - |
| **Governance** |  |  |
| OSS licence compliance | - | ✓ |
| SBOM generation (SPDX/CycloneDX) | ✓ | - |
| **Remediation** |  |  |
| Automated fix / upgrade PRs | - | - |
| **Prioritisation** |  |  |
| Reachability / exploitability prioritisation | ✓ | ✓ |
| **Deployment** |  |  |
| Hosting | Cloud only | Cloud + self-hosted |
| **Integration** |  |  |
| First-class CI / pipeline integration | ✓ | ✓ |
| In-editor / IDE scanning | ✓ | ✓ |
| **Licensing** |  |  |
| OSS engine available | - | ✓ |

*Source: Vioscale. Generated 2026-09-01T14:52:55.915Z. "-" = undocumented, not absent.*
