shouldiuse.io

Report

Should I Use Checkmarx?

checkmarx.com·Analyzed 16 hours ago··Based on 16 sources

Agentic application security platform combining hybrid scanning, AI-powered agents, and unified risk intelligence

Depends

Depends

Buy if you are a large organization with dedicated security staff that needs enterprise-grade SAST, SCA, and agentic AI scanning in one platform.

Enterprise AppSec with real depth — but quote-only pricing, hour-long scans, and a 2026 breach. Overkill for small teams.

Confidence: Medium

4.3/5

G2 rating

73 reviews

4.6/5

Gartner Peer Insights

Customers' Choice 2024

$2.5B

Valuation

Hellman & Friedman acquisition

1,385+

Customers detected

companies using Checkmarx One (Bloomberry)

Value for money2

Quote-only pricing, no published tiers, sales friction reported

Ease of use4

Users consistently praise ease of use on G2

Feature depth5

SAST, SCA, container, hybrid scanning, agentic AI combined

Security posture2

Confirmed 2026 supply chain breach with data stolen

Pros

  • Users consistently praise ease of use¹
  • SAST, SCA, container, and agentic AI in one platform
  • 4.6/5 on Gartner Peer Insights
  • FedRAMP-listed offering for government buyers13
  • VS Code extension and straightforward rule writing

Cons

  • Scans can take hours on large codebases³
  • No published pricing; quote-only sales process16
  • Confirmed 2026 supply chain breach with stolen data11
  • Reddit users cite sales and communication issues

Gotchas

  • highMarch 2026 supply chain attack: data confirmed stolen; run vendor risk review11
  • mediumQuote-based pricing; expect negotiation, often via AWS Marketplace
  • mediumHour-long scans can slow CI/CD pipelines on big repos³
  • lowGuess: platform lock-in makes migrating scan history to rivals painful16

Best for

  • Enterprise dev teams at scale
  • Orgs needing SAST + SCA unified
  • Companies with dedicated AppSec staff
  • Government buyers (FedRAMP via CXG)

Not for

  • Small teams and startups — heavy overkill
  • Anyone wanting transparent, published pricing
  • Teams without staff to tune noisy scanner results
  • Solo developers — a linter and Semgrep cover you

Companies that use it

  • PCL Construction
  • Time Inc.
  • Specops Software

Pricing

Quote-based enterprise packages

Not disclosed

  • Premium Service package sold via AWS Marketplace
  • Negotiated deals commonly achieve discounts (Vendr)

Security

Confirmed supply chain attack in March 2026 with stolen data; Checkmarx published ongoing incident updates through July 2026.

  • Supply chain attack (March 2026)Checkmarx confirmed hackers stole data in a supply chain compromise; ongoing security updates posted as of July 2026.11

What users say

Reviews trend positive (4.2–4.6 across G2 and Gartner), with praise for ease of use offset by complaints about slow scans and sales friction.

Checkmarx is solid for SAST and SC[A]
Reddit, r/cybersecurity
Checkmarx scans can take hours
StackHawk comparison guide
Users consistently praise the ease of [use]
G2 reviews

Alternatives

Compare Checkmarx with each alternative.

Semgrep

Fast, lightweight SAST with simple custom rules

Aikido

All-round security platform built for smaller, faster-moving teams

Full analysis

Based on ~30 public sources; pricing is quote-only so no figures verified.

Sources

  1. review
  2. review
  3. review
  4. review
  5. review
  6. review
  7. official
  8. review
  9. review
  10. official
  11. security
  12. security
  13. official
  14. news
  15. news
  16. review

Rate this review

Anonymous. You can change your vote.

Loading votes…

Ask a follow-up

Ask if a use case fits. Answers stay inside this report and its sources.

    Comments

    One queue. No replies. Give a display name first. Limit: 7 comments per day.

    Save a name to write a comment.

    No comments yet.