Checkmarx Review, Pricing & Features

See how Checkmarx's SAST, SCA, DAST, and API security modules work inside Checkmarx One, plus pricing structure and how it compares for enterprise AppSec.

Category
Security
Pricing
Subscription
Verified
Not yet
Last updated
July 18, 2026
Founded
2006
Headquarters
Ramat Gan, Israel
Web AppAPIAI

Overview

Checkmarx is an application security testing company founded in 2006 and headquartered in Ramat Gan, Israel, with significant U.S. operations centered in Atlanta. The company was acquired by private equity firms Hellman & Friedman and TPG in 2020 in a deal valued at roughly $1.15 billion, and now employs over 900 people serving enterprise customers worldwide.

Its flagship product, Checkmarx One, is a cloud-based application security platform that unifies static analysis, software composition analysis, dynamic testing, and API security scanning into a single console, aimed at organizations running formal DevSecOps programs across large codebases and complex software supply chains.

Key Features

Checkmarx One's core modules include SAST for scanning source code before deployment, SCA for identifying vulnerable or non-compliant open-source components and generating SBOMs, DAST for testing live applications, and API Security for discovering and assessing exposed API endpoints.

Additional capabilities cover Infrastructure-as-Code scanning, container security, and supply-chain risk detection, along with newer tooling focused on securing AI-generated code. The platform integrates with major CI/CD systems and source control platforms so security checks can run inside existing developer workflows.

Pricing

Checkmarx does not publish standard pricing tiers. Customers choose which modules (SAST, SCA, DAST, API Security, etc.) match their needs and receive a custom quote based on factors like number of developers, scan volume, and contract term.

Organizations bundling multiple modules or committing to multi-year agreements typically negotiate better effective pricing than those buying a single module standalone, and larger engineering teams often unlock volume discounts.

Key Features

Pros & Cons

Pros

  • Consolidates SAST, SCA, DAST, and API security into one platform rather than multiple point tools
  • Established, mature vendor with broad programming language and framework coverage
  • Deep CI/CD and developer-workflow integrations for shifting security left
  • Backed by significant enterprise support infrastructure and a large customer base

Cons

  • No public pricing; getting an accurate cost requires a sales conversation
  • Modular licensing across SAST, SCA, DAST, and other add-ons can be complex to budget for
  • Primarily built for mid-size and large enterprises, less accessible for small teams
  • Can involve a steeper learning curve and tuning period to reduce false positives

Frequently Asked Questions

What is Checkmarx used for?

Checkmarx is used for application security testing, covering static code analysis (SAST), open-source dependency scanning (SCA), dynamic testing (DAST), and API security, typically integrated into CI/CD pipelines.

How much does Checkmarx cost?

Checkmarx does not publish standard pricing. Cost depends on which modules you license, number of developers, and contract length, and requires a custom quote from Checkmarx sales.

Is Checkmarx a SAST or SCA tool?

Checkmarx offers both. SAST and SCA were its original core products, and the Checkmarx One platform has since expanded to include DAST, API security, IaC scanning, and container security.

Who owns Checkmarx?

Checkmarx is privately held, owned by private equity firms Hellman & Friedman and TPG following their 2020 acquisition of the company.

Does Checkmarx integrate with CI/CD pipelines?

Yes. Checkmarx One integrates with common CI/CD tools and source control platforms such as GitHub, GitLab, Bitbucket, and Azure DevOps to automate scans during the development process.

Comparisons

Related Tools