Checkmarx One is a broad, AI-powered application security platform covering SAST, DAST, SCA, container, secrets, IaC, and API security, priced through custom…
| Checkmarx | OpenVAS | |
|---|---|---|
| Primary category | Security | Security |
| Rating | Not documented | Not documented |
| Pricing model | Subscription | Open Source |
| Starting price | Not documented | Free (open source); Greenbone Enterprise appliances at custom pricing |
| Free plan | Not documented | Yes |
| Free trial | Not documented | Not documented |
| Platforms | Web | Not documented |
| Team collaboration | Not documented | Not documented |
| AI features | Yes | Not documented |
| Public API | Yes | Not documented |
Scan Coverage
Checkmarx: Checkmarx One covers NG SAST (source code analysis), DAST, SCA, container security, secrets detection, IaC security, and API security in one platform.
OpenVAS: OpenVAS performs authenticated and unauthenticated network vulnerability scanning across internet and industrial protocols; source code or dependency analysis is not documented.
Application-layer vulnerabilities (in code, dependencies, containers) and network-layer vulnerabilities require fundamentally different scanning engines.
AI-Powered Remediation
Checkmarx: Checkmarx includes AI-powered agents — Developer Assist and Triage & Remediation Assist — plus a Checkmarx MCP Server to help developers fix findings faster.
OpenVAS: Not documented as an OpenVAS feature.
AI-assisted triage and remediation can significantly reduce the manual effort of fixing large volumes of findings.
Pricing Transparency
Checkmarx: Checkmarx pricing is fully custom, calculated on developers, apps, and usage, with no public price list and no advertised free trial.
OpenVAS: OpenVAS is free and open source, forming the core of the free Greenbone Community Edition, with no cost to start.
Budget-constrained teams need to know upfront whether a tool is free to adopt or requires a sales conversation and enterprise budget.
Compliance Certifications
Checkmarx: Checkmarx holds SOC 2 Type II, ISO 27001 certification, and FedRAMP authorization, and was recognized as a Leader in the 2026 Gartner Magic Quadrant for Software Supply Chain Security.
OpenVAS: Not documented as holding formal compliance certifications; OpenVAS is instead positioned on its open-source pedigree and daily-updated feed since 2006.
Regulated industries and government-adjacent buyers often require vendor compliance attestations before procurement.
Custom Scan Scripting
Checkmarx: Not documented as a Checkmarx feature.
OpenVAS: OpenVAS includes an internal scripting language for writing custom vulnerability tests.
The ability to write custom detection logic matters for niche or internally developed protocols and systems.
| Feature | Checkmarx | OpenVAS |
|---|---|---|
| Static application security testing (SAST) | Available | Not documented |
| Dynamic application security testing (DAST) | Available | Not documented |
| Network / infrastructure vulnerability scanning | Not documented | Available |
| Software composition analysis (SCA) | Available | Not documented |
| IaC security scanning | Available | Not documented |
| Secrets detection in source code | Available | Not documented |
| Feature | Checkmarx | OpenVAS |
|---|---|---|
| AI-powered remediation agents | Available | Not documented |
| Model Context Protocol (MCP) server | Available | Not documented |
| Custom scan test scripting | Not documented | Available |
| Feature | Checkmarx | OpenVAS |
|---|---|---|
| Publicly published pricing | Unavailable | Available |
| Free / open-source tier | Unavailable | Available |
| Formal compliance certifications listed | Available | Not documented |
| Enterprise commercial support option | Available | Available |
Starting price reflects the lowest paid tier, not the full cost for every team size or usage level.
No individual plan breakdown documented yet.
Pros
Cons
Pros
Cons
No, Checkmarx One is priced through custom, quote-based sales conversations based on developers, apps, and usage, with no advertised free trial.
Yes, OpenVAS is open source and forms the core of the free Greenbone Community Edition.
This is not documented as a Checkmarx capability; its documented scope is application source code, dependencies, containers, IaC, and APIs.
This is not documented as an OpenVAS capability; its documented scope is authenticated and unauthenticated network protocol scanning.
Checkmarx includes AI-powered agents (Developer Assist, Triage & Remediation Assist) and a Checkmarx MCP Server; AI features are not documented for OpenVAS.
Checkmarx is built for enterprise application security teams needing broad SDLC coverage with custom pricing, while OpenVAS is built for teams needing a free, self-hosted network vulnerability scanner.
Read the full Checkmarx review · Read the full OpenVAS review