Try our new research platform with insights from 80,000+ expert users

Check Point CloudGuard Code Security vs Checkmarx One comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 7, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Check Point CloudGuard Code...
Ranking in DevSecOps
8th
Average Rating
8.4
Reviews Sentiment
7.5
Number of Reviews
12
Ranking in other categories
Data Loss Prevention (DLP) (13th)
Checkmarx One
Ranking in DevSecOps
2nd
Average Rating
7.6
Reviews Sentiment
6.9
Number of Reviews
70
Ranking in other categories
Application Security Tools (3rd), Static Application Security Testing (SAST) (3rd), Vulnerability Management (21st), Static Code Analysis (2nd), API Security (3rd), Risk-Based Vulnerability Management (8th)
 

Mindshare comparison

As of April 2025, in the DevSecOps category, the mindshare of Check Point CloudGuard Code Security is 2.0%, up from 1.1% compared to the previous year. The mindshare of Checkmarx One is 16.3%, down from 22.3% compared to the previous year. It is calculated based on PeerSpot user engagement data.
DevSecOps
 

Featured Reviews

Nagendra Nekkala. - PeerSpot reviewer
Good security and functionality with helpful support
The security on offer is great. It's secure in terms of testing all the workloads. We can test across any workload or multiple clouds. It offers unified prevention. It also offers posture management by verifying proper scanning. We use the GSL builder. It's easy to write customer rules or policies using it. Of course, you do need proper training on the product first. It takes around one week to get trained. We've been able to reduce human error, and you can build the rules for better coverage. It provides functionality across cloud providers. The solution helps us save time. We've reduced the amount of time spent by 25%. Its unified security management console is a very complete dashboard. We can see all security threats and can gain visibility into what is happening. We have access to automation and can monitor the security of IT systems. The product offers role-based access control so that we can set up different privileges for admin users. Cloud Guard Spectrum is good for automating our organization's security across assets, workloads, and multiple clouds. With it, we have advanced pre-prevention across the cloud security network. It works for on-premises also. We can easily determine our organization's security posture. It will ensure my application's availability time across the enterprise. Network security helped us reduce our compliance and audit activities. We've saved about 20% of our time. Having a cloud detection response helps to very quickly identify security threats in our environment. It's automated so it saves us time. That way, people can work on other projects. On any given day, we're spending 20% less time in general worrying about detection and response. Our security operations are saving a lot of time using a unified platform.
Rohit Kesharwani - PeerSpot reviewer
Provides good security analysis and security identification within the source code
We integrate Checkmarx into our software development cycle using GitLab's CI/CD pipeline. Checkmark has been the most helpful for us in the development stage. The solution's incremental scanning feature has impacted our development speed. The solution's vulnerability detection is around 80% to 90% accurate. I would recommend Checkmarx to other users because it is one of the good tools for doing security analysis and security identification within the source code. Overall, I rate Checkmarx a nine out of ten.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"We have had a number of real events where developers accidentally made commits of API keys, and we were able to detect and begin response actions in minutes. We had the API key revoked in less than five minutes in such events."
"The implementation of this tool for security management and control is very simple."
"Its fastest and most outstanding characteristic is ensuring a development line that will not lead to applying applications or code development."
"Knowing what measures we must take allows us to reduce costs associated with security in the cloud by providing early identification of a risk or a possible security breach."
"The data center security system has provided real-time analytics on performance and data configuration processes."
"Check Point CloudGuard Code Security helps to improve the code security of our company, generating rapid and complete assessments to be able to make decisions for improvements."
"It helped us to reduce vulnerabilities."
"Automation has helped a lot to identify and automatically execute policies, rules, and blocks due to its machine learning."
"The report function is the solution's greatest asset."
"Compared to the solutions we used previously, Checkmarx has reduced our workload by almost 75%."
"Less false positive errors as compared to any other solution."
"The user interface is excellent. It's very user friendly."
"Most valuable features include: ease of use, dashboard. interface and the ability to report."
"It's not an obstacle for developers. They can easily write their code and make it more secure with Checkmarx."
"The solution allows us to create custom rules for code checks."
"The tool's valuable features include integrating GPT and Copilot. Additionally, the UI web representation is very user-friendly, making navigation easy. GPT has made several improvements to my security code."
 

Cons

"The ease of use could be better."
"The enhancements are needed in the logging system and log management processes."
"I would like this solution to be extended to cellular devices or tablets."
"There are a lot of opportunities for how they can use their technology to do more. That would be more like sensitive data discovery and other things besides Git Repos, but then you are expanding the scope of what necessarily their product is."
"The solution should improve false-positives."
"It is generally difficult to find documentation about the product, and there is relatively little to find."
"I am satisfied with the performance and results enhanced by this product since we deployed it."
"We need to have many of the baselines or development guides providing less complex writing or development."
"The lack of ability to review compiled source code. It would then be able to compete with other scanning tools, such as Veracode."
"Its user interface could be improved and made more friendly."
"The solution's user interface could be improved because it seems outdated."
"Checkmarx is not good because it has too many false positive issues."
"I would like to see the tool’s pricing improved."
"The integration could improve by including, for example, DevSecOps."
"The reports are good, but they still need to be improved considering what the UI offers."
"Checkmarx has a slightly difficult compilation with the CI/CD pipeline."
 

Pricing and Cost Advice

"It is extremely affordable and high value for cost."
"The solution is costly."
"We're using a commercial version of Checkmarx, and we paid for the solution for one year. The price is high and could be reduced."
"This solution is expensive. The customized package allows you to buy additional users at any time."
"I would rate the solution’s pricing an eight out of ten. The tool’s pricing is higher than others and it is for the license alone."
"It is the right price for quality delivery."
"We got a special offer for a 30% reduction for three years, after our first year. I think for a real source-code scanning tool, you have to add a lot of money for Open Source Analysis, and AppSec Coach (160 Euro per user per year)."
"It is an expensive solution."
"​Checkmarx is not a cheap scanning tool, but none of the security tools are cheap. Checkmarx is a powerful scanning tool, and it’s essential to have one of these products."
report
Use our free recommendation engine to learn which DevSecOps solutions are best for your needs.
845,406 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
27%
Financial Services Firm
14%
Manufacturing Company
11%
Government
10%
Financial Services Firm
21%
Computer Software Company
14%
Manufacturing Company
10%
Government
5%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Spectral?
We have had a number of real events where developers accidentally made commits of API keys, and we were able to detect and begin response actions in minutes. We had the API key revoked in less than...
What needs improvement with Spectral?
The solution should improve vulnerability in-depth, false-positive reduction, integration with other tools, performance optimization, and the user interface.
What alternatives are there for Fortify WebInspect and Fortify SCA?
I would like to recommend Checkmarx. With Checkmarx, you are able to have an all in one solution for SAST and SCA as well. Veracode is only a cloud solution. Hope this helps.
What do you like most about Checkmarx?
Compared to the solutions we used previously, Checkmarx has reduced our workload by almost 75%.
What is your experience regarding pricing and costs for Checkmarx?
The pricing is relatively expensive due to the product's quality and performance, but it is worth it.
 

Also Known As

Spectral
No data available
 

Overview

 

Sample Customers

Doddle, Bangalore International Airport, Grupo financiero ACOBO, DigitalTrack
YIT, Salesforce, Coca-Cola, SAP, U.S. Army, Liveperson, Playtech Case Study: Liveperson Implements Innovative Secure SDLC
Find out what your peers are saying about Check Point CloudGuard Code Security vs. Checkmarx One and other solutions. Updated: March 2025.
845,406 professionals have used our research since 2012.