Checkmarx

Hybrid application security platform combining multiple scanning engines with AI-powered vulnerability analysis and prioritization

Vendor
Checkmarx Ltd.
Also known as
checkmarx

Available worldwide

What is Checkmarx?

Checkmarx integrates static analysis (SAST), dynamic analysis (DAST), dependency scanning (SCA), and specialized AI-based analysis to detect vulnerabilities across code, dependencies, and AI components. It prioritizes findings by exploitability and reachability while embedding directly into development tools and CI/CD pipelines.

Independently observed

Checkmarx pricing

Plans, per-tier features and add-ons, dated and linked to live pricing. Pricing changes often; always verify at source before you rely on it.

Pricing as of verify at live pricing ↗Independently observed
Quote-based

All three tiers require custom quote. No published per-seat or usage-based pricing.

Essentials

Contact sales
Contact sales

Core application security coverage. Establish a unified foundation for identifying, managing, and reporting application risk.

  • SAST
  • SCA
  • API Security
  • ASPM visibility
  • Core reporting

Professional

Contact sales
Contact sales

Advanced protection and AI-powered security. Scale your AppSec program with AI-assisted remediation and deeper multi-layer coverage.

  • Everything in Essentials
  • DAST
  • IaC Security
  • AI Security
  • Advanced ASPM
  • PR Decorations

Enterprise

Contact sales
Contact sales

Complete coverage and full compliance. Maximum coverage and control for organizations with the most demanding security requirements.

  • Everything in Professional
  • Supply Chain Security
  • Container Security
  • Runtime Protection
  • Custom Policies
  • Executive Reporting

What Checkmarx does

The capabilities that matter for devsecops tools, normalised so it lines up with every alternative. “-” means we haven't confirmed it, not that it's missing.

Scan types
SAST (static analysis)
DAST (dynamic analysis)
SCA / dependency scanning
Secret scanning
Container / image scanning
-
IaC misconfiguration scanning
Governance
OSS licence compliance
-
SBOM generation (SPDX/CycloneDX)
Remediation
Automated fix / upgrade PRs
-
Prioritisation
Reachability / exploitability prioritisation
Deployment
Hosting
Cloud only
Integration
First-class CI / pipeline integration
In-editor / IDE scanning
Licensing
OSS engine available
-
Independently observed

Platform & deployment

Independently observed
Platforms
  • Web
Deployment
  • Cloud / SaaS

Integrations (1)

Independently observed
  • Wiz

Security & compliance

Independently observed
  • SOC 2 Type IIactive
  • ISO 27001active

Checkmarx FAQ

Common questions about Checkmarx, answered from independent, dated evidence.

What is Checkmarx?

Checkmarx integrates static analysis (SAST), dynamic analysis (DAST), dependency scanning (SCA), and specialized AI-based analysis to detect vulnerabilities across code, dependencies, and AI components. It prioritizes findings by exploitability and reachability while embedding directly into development tools and CI/CD pipelines. It is indexed under DevSecOps Tools.

Source: https://checkmarx.com

How much does Checkmarx cost?

Checkmarx does not publish its prices. Pricing is quoted on request, across 3 plans (Essentials, Professional and Enterprise), so the figure depends on your seat count and requirements. We record this as a pricing-transparency signal rather than guessing a number. Pricing changes often, so verify at source before relying on it.

Source: https://checkmarx.com

What platforms does Checkmarx support?

We have confirmed browser-based access to Checkmarx. That is the extent of what we could verify from public sources, so it may well offer desktop or mobile clients we have not indexed.

Source: https://checkmarx.com

Can Checkmarx be self-hosted?

We have only confirmed a cloud / SaaS deployment for Checkmarx, so it appears to be vendor-hosted. If a self-hosted option exists we have not found it documented publicly.

Source: https://checkmarx.com

What security certifications does Checkmarx have?

We have independently confirmed SOC 2, ISO 27001 and GDPR for Checkmarx. Certifications we do not list are ones we have not been able to verify from public sources, which is not the same as Checkmarx not holding them. Always confirm compliance directly before you rely on it.

Source: https://checkmarx.com/blog/security-in-vibe-coding/

Where is Checkmarx available?

Checkmarx is available in Australia, Germany, France, the United Kingdom, Israel, India, Portugal and Singapore. The vendor is headquartered in Israel.

Source: https://checkmarx.com

Checkmarx alternatives

Other devsecops tools we track, ranked by the same independent score.

All Checkmarx alternatives, ranked →

Compare Checkmarx

Side by side against other devsecops tools, attribute by attribute, with a source on every value.

Independent · unbought · dated

The vioscaleAI score: one lens on the evidence

Not user reviews and not a paid placement: a confidence-weighted blend of the independent signals below (adoption, activity, security posture, and more), which you can sort and re-weight yourself. Vendors can correct their listing but can never move their rank, and stars are weighted low as a vanity metric. It is one way to read the evidence for Checkmarx, not the verdict.

Balanced composite 54 / 100
low · 46%
Signal contributions to the composite score
SignalScoreWeightContributionEvidence
Security posture700.2114.6
Capabilities960.054.9
Integrations90.050.4
Price level00.040.0-
Reliability00.090.0-
Pricing transparency00.050.0

Computed . Re-weight it by intent, or see the full method.

All data & sourcesshow ↓

Every value we hold, with its source, retrieval date, and confidence. This is the evidence behind the score: don't trust it, verify it.

Content

AttributeValueEvidence
Faq6 itemsmediumsource · 2026-09-10 · 64%

Features

AttributeValueEvidence
CapabilitiesSca: Yes · Dast: Yes · Sast: Yes · Sbom: Yes · Hosting: cloud · Ci native: Yesmediumsource · 2026-09-07 · 60%

Integrations

AttributeValueEvidence
Count1mediumsource · 2026-09-04 · 60%

Market

AttributeValueEvidence
AvailabilityHqCountry: IL · PrimaryMarkets: … · AvailabilityScope: global · AvailableCountries: … · NotAvailableCountries: …highsource · 2026-09-07 · 75%

Pricing

AttributeValueEvidence
Modelcommercialmediumsource · 2026-08-05 · 60%
Free tierNomediumsource · 2026-08-05 · 60%
Price levelunknownmediumsource · 2026-08-05 · 60%
TransparentNomediumsource · 2026-08-05 · 60%

Security

AttributeValueEvidence
Iso27001Yeshighsource · 2026-09-07 · 75%
Soc2Yeshighsource · 2026-09-07 · 75%
CertificationsSOC 2 Type II, ISO 27001mediumsource · 2026-09-07 · 60%
Trust centerhttps://checkmarx.com/blog/security-in-vibe-coding/mediumsource · 2026-09-07 · 60%
FedrampYeshighsource · 2026-08-14 · 75%
GdprYeshighsource · 2026-08-14 · 75%
Still deciding?

Is Checkmarx the right choice for you?

Tell us the job, the constraints and what you weigh most, and we will rank Checkmarx against the rest of the devsecops tools we index, using the same dated evidence weighted your way.

Free to run, no account needed to start. How the evaluation works

For the makers of Checkmarx

Is this your product?

This profile was built from public sources without asking you. You can take the badge below and use it anywhere, and you can claim the profile to correct anything we got wrong. Both are free, and neither moves Checkmarx up or down: nobody can buy rank here, including you.

Take the badge

Live, always current, and free to use on your own site. It shows Checkmarx's independent score and links back to this profile.

Checkmarx, verified on vioscaleAI
HTML
<a href="https://www.vioscale.ai/software/checkmarx" target="_blank" rel="noopener">
  <img src="https://www.vioscale.ai/badge/software/checkmarx.svg" alt="Checkmarx, verified on vioscaleAI" width="330" height="76" loading="lazy" />
</a>
Markdown, for a README →
Markdown
[![Checkmarx, verified on vioscaleAI](https://www.vioscale.ai/badge/software/checkmarx.svg)](https://www.vioscale.ai/software/checkmarx)

Claim the profile

Verify you control the domain and you can correct the facts, add the sources we should be reading, and see how AI assistants are describing Checkmarx. Free, and it does not change the score.

  • Correct anything wrong, with evidence
  • Point our crawler at the pages that matter
  • See which AI systems are reading this profile
Claim Checkmarx

Not the owner? How vendor profiles work