Try our new research platform with insights from 80,000+ expert users

Check Point CloudGuard Code Security vs Checkmarx One comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Check Point CloudGuard Code...
Ranking in DevSecOps
7th
Average Rating
8.4
Reviews Sentiment
7.4
Number of Reviews
12
Ranking in other categories
Data Loss Prevention (DLP) (9th)
Checkmarx One
Ranking in DevSecOps
2nd
Average Rating
7.6
Reviews Sentiment
6.9
Number of Reviews
70
Ranking in other categories
Application Security Tools (3rd), Static Application Security Testing (SAST) (3rd), Vulnerability Management (20th), Static Code Analysis (2nd), API Security (2nd), Risk-Based Vulnerability Management (6th)
 

Featured Reviews

Nagendra Nekkala. - PeerSpot reviewer
Good security and functionality with helpful support
The security on offer is great. It's secure in terms of testing all the workloads. We can test across any workload or multiple clouds. It offers unified prevention. It also offers posture management by verifying proper scanning. We use the GSL builder. It's easy to write customer rules or policies using it. Of course, you do need proper training on the product first. It takes around one week to get trained. We've been able to reduce human error, and you can build the rules for better coverage. It provides functionality across cloud providers. The solution helps us save time. We've reduced the amount of time spent by 25%. Its unified security management console is a very complete dashboard. We can see all security threats and can gain visibility into what is happening. We have access to automation and can monitor the security of IT systems. The product offers role-based access control so that we can set up different privileges for admin users. Cloud Guard Spectrum is good for automating our organization's security across assets, workloads, and multiple clouds. With it, we have advanced pre-prevention across the cloud security network. It works for on-premises also. We can easily determine our organization's security posture. It will ensure my application's availability time across the enterprise. Network security helped us reduce our compliance and audit activities. We've saved about 20% of our time. Having a cloud detection response helps to very quickly identify security threats in our environment. It's automated so it saves us time. That way, people can work on other projects. On any given day, we're spending 20% less time in general worrying about detection and response. Our security operations are saving a lot of time using a unified platform.
Rohit Kesharwani - PeerSpot reviewer
Provides good security analysis and security identification within the source code
We integrate Checkmarx into our software development cycle using GitLab's CI/CD pipeline. Checkmark has been the most helpful for us in the development stage. The solution's incremental scanning feature has impacted our development speed. The solution's vulnerability detection is around 80% to 90% accurate. I would recommend Checkmarx to other users because it is one of the good tools for doing security analysis and security identification within the source code. Overall, I rate Checkmarx a nine out of ten.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Knowing what measures we must take allows us to reduce costs associated with security in the cloud by providing early identification of a risk or a possible security breach."
"Check Point CloudGuard Code Security helps to improve the code security of our company, generating rapid and complete assessments to be able to make decisions for improvements."
"Having a cloud detection response helps to very quickly identify security threats in our environment."
"It helped us to reduce vulnerabilities."
"Its fastest and most outstanding characteristic is ensuring a development line that will not lead to applying applications or code development."
"We have had a number of real events where developers accidentally made commits of API keys, and we were able to detect and begin response actions in minutes. We had the API key revoked in less than five minutes in such events."
"Automation has helped a lot to identify and automatically execute policies, rules, and blocks due to its machine learning."
"The data center security system has provided real-time analytics on performance and data configuration processes."
"Most valuable features include: ease of use, dashboard. interface and the ability to report."
"The main thing we find valuable about Checkmarx is the ease of use. It's easy to initiate scans and triage defects."
"The most valuable features of Checkmarx are difficult to pinpoint because of the way the functionalities and the features are intertwined, it's difficult to say which part of them I prefer most. You initiate the scan, you have a scan, you have the review set, and reporting, they all work together as one whole process. It's not like accounting software, where you have the different features, et cetera."
"The administration in Checkmarx is very good."
"Overall, the ability to find vulnerabilities in the code is better than the tool that we were using before."
"It has all the features we need."
"Checkmarx has helped us deliver more secure products. We are able to do static code analysis with the tool before shipping our code to production. When the integration is in the pipeline, this tool gives us early notifications on code fixes."
"The solution has good performance, it is able to compute in 10 to 15 minutes."
 

Cons

"The costs are not transparent."
"It is generally difficult to find documentation about the product, and there is relatively little to find."
"The enhancements are needed in the logging system and log management processes."
"This is a highly technical solution for users who do not have security experience. It requires specialized knowledge of configurations to use it correctly."
"There needs to be better security around API integration."
"I am satisfied with the performance and results enhanced by this product since we deployed it."
"There are a lot of opportunities for how they can use their technology to do more. That would be more like sensitive data discovery and other things besides Git Repos, but then you are expanding the scope of what necessarily their product is."
"We need to have many of the baselines or development guides providing less complex writing or development."
"We would like to be able to run scans from our local system, rather than having to always connect to the product server, which is a longer process."
"Its pricing model can be improved. Sometimes, it is a little complex to understand its pricing model."
"We want to have a holistic view of the portfolio-level dashboard and not just an individual technical project level."
"It would be really helpful if the level of confidence was included, with respect to identified issues."
"They can support the remaining languages that are currently not supported. They can also create a different model that can identify zero-day attacks. They can work on different patterns to identify and detect zero-day vulnerability attacks."
"It is an expensive solution."
"Checkmarx could improve the solution reports and false positives. The false positives could be reduced. For example, we have alerts that are tagged as vulnerabilities but when you drill down they are not."
"If it is a very large code base then we have a problem where we cannot scan it."
 

Pricing and Cost Advice

"It is extremely affordable and high value for cost."
"It is not expensive, but sometimes, their pricing model or licensing model is not very clear. There are similar variables, such as projects or developers, and sometimes, it is a little bit confusing."
"This solution is expensive. The customized package allows you to buy additional users at any time."
"Be cautious of the one-year subscription date. Once it expires, your price will go up."
"If you want more, you have to pay more. You have to pay for additional modules or functionalities."
"Its price is fair. It is in or around the right spot. Ultimately, if the price is wrong, customers won't commit, but they do tend to commit. It is neither too cheap nor too expensive."
"We have purchased an annual license to use this solution. The price is reasonable."
"The average deal size was usually anywhere between $120K to $175K on an annual basis, which could be divided across 12 months."
"The solution is costly."
report
Use our free recommendation engine to learn which DevSecOps solutions are best for your needs.
824,053 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
25%
Financial Services Firm
17%
Government
12%
Manufacturing Company
9%
Financial Services Firm
22%
Computer Software Company
15%
Manufacturing Company
10%
Government
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Spectral?
We have had a number of real events where developers accidentally made commits of API keys, and we were able to detect and begin response actions in minutes. We had the API key revoked in less than...
What needs improvement with Spectral?
The solution should improve vulnerability in-depth, false-positive reduction, integration with other tools, performance optimization, and the user interface.
What alternatives are there for Fortify WebInspect and Fortify SCA?
I would like to recommend Checkmarx. With Checkmarx, you are able to have an all in one solution for SAST and SCA as well. Veracode is only a cloud solution. Hope this helps.
What do you like most about Checkmarx?
Compared to the solutions we used previously, Checkmarx has reduced our workload by almost 75%.
What is your experience regarding pricing and costs for Checkmarx?
The pricing is relatively expensive due to the product's quality and performance, but it is worth it.
 

Also Known As

Spectral
No data available
 

Learn More

 

Overview

 

Sample Customers

Doddle, Bangalore International Airport, Grupo financiero ACOBO, DigitalTrack
YIT, Salesforce, Coca-Cola, SAP, U.S. Army, Liveperson, Playtech Case Study: Liveperson Implements Innovative Secure SDLC
Find out what your peers are saying about Check Point CloudGuard Code Security vs. Checkmarx One and other solutions. Updated: December 2024.
824,053 professionals have used our research since 2012.