See how Checkmarx's SAST, SCA, DAST, and API security modules work inside Checkmarx One, plus pricing structure and how it compares for enterprise AppSec.
Checkmarx is an application security testing company founded in 2006 and headquartered in Ramat Gan, Israel, with significant U.S. operations centered in Atlanta. The company was acquired by private equity firms Hellman & Friedman and TPG in 2020 in a deal valued at roughly $1.15 billion, and now employs over 900 people serving enterprise customers worldwide.
Its flagship product, Checkmarx One, is a cloud-based application security platform that unifies static analysis, software composition analysis, dynamic testing, and API security scanning into a single console, aimed at organizations running formal DevSecOps programs across large codebases and complex software supply chains.
Checkmarx One's core modules include SAST for scanning source code before deployment, SCA for identifying vulnerable or non-compliant open-source components and generating SBOMs, DAST for testing live applications, and API Security for discovering and assessing exposed API endpoints.
Additional capabilities cover Infrastructure-as-Code scanning, container security, and supply-chain risk detection, along with newer tooling focused on securing AI-generated code. The platform integrates with major CI/CD systems and source control platforms so security checks can run inside existing developer workflows.
Checkmarx does not publish standard pricing tiers. Customers choose which modules (SAST, SCA, DAST, API Security, etc.) match their needs and receive a custom quote based on factors like number of developers, scan volume, and contract term.
Organizations bundling multiple modules or committing to multi-year agreements typically negotiate better effective pricing than those buying a single module standalone, and larger engineering teams often unlock volume discounts.
Checkmarx is used for application security testing, covering static code analysis (SAST), open-source dependency scanning (SCA), dynamic testing (DAST), and API security, typically integrated into CI/CD pipelines.
Checkmarx does not publish standard pricing. Cost depends on which modules you license, number of developers, and contract length, and requires a custom quote from Checkmarx sales.
Checkmarx offers both. SAST and SCA were its original core products, and the Checkmarx One platform has since expanded to include DAST, API security, IaC scanning, and container security.
Checkmarx is privately held, owned by private equity firms Hellman & Friedman and TPG following their 2020 acquisition of the company.
Yes. Checkmarx One integrates with common CI/CD tools and source control platforms such as GitHub, GitLab, Bitbucket, and Azure DevOps to automate scans during the development process.