

Checkmarx One and Claroty Platform compete in the security software category, focusing on code scanning and OT environments, respectively. Checkmarx One appears to have an edge in programming language support and integration, while Claroty excels in industrial control sector features.
Features: Checkmarx One supports a wide variety of programming languages, offers comprehensive code scanning without needing compilation, and integrates with key repositories. Incremental scanning capabilities and clear reporting enhance its utility. Claroty Platform provides valuable real-time monitoring and threat detection for OT environments, excels in asset management, and offers extensive visibility in industrial control sectors.
Room for Improvement: Checkmarx One could improve by reducing false positive rates, expanding language support to include languages like COBOL, and enhancing dynamic code testing. It also requires a more flexible licensing model. Claroty Platform needs better vulnerability management, improved integration capabilities, particularly regarding zero-day attack coverage, and more intuitive user interaction to enhance user experience.
Ease of Deployment and Customer Service: Checkmarx One offers deployment flexibility through public and private cloud options. Its customer service is viewed variably, with some users citing high responsiveness while others note delays. Claroty, mostly deployed on-premises, has high-quality technical support, though users report some inefficiencies in responsiveness.
Pricing and ROI: Checkmarx One is considered expensive, with a complex and rigid licensing model. However, its effectiveness in enhancing application security justifies its cost. Claroty Platform is also seen as pricey, especially for software versions. Despite this, its value for OT security is acknowledged. Determining ROI for both tools is challenging due to varying environments and organizational factors.
Overall, between the fast scanning, automation, automatic reporting, and easy detection, it has reduced manual effort enough that we did not need an extra reviewer, even as our codebase or team size grew.
Based on my interactions with the clients, I can tell that there is a return on investment because if something is not profitable and it's not helping to save costs or vulnerabilities, clients wouldn't come back to renew their license year after year.
If my infrastructure is critical infrastructure, the Claroty Platform saves time and resources.
If you raise a support case with Checkmarx, it is handled smoothly.
The customer support team is amazing and they provide on-phone call, email support, and on-website support.
I have relied on Checkmarx One customer support hundreds of times for several things, and Checkmarx One support is very proactive and very responsive.
Their response and support are effective and proactive.
They can rate support for the Claroty Platform from one to ten as eight to nine.
I have always found Claroty's technical support to have good engineers.
Approximately four billion lines of code are being scanned monthly.
Since it is cloud-based, the infrastructure and PaaS, IaaS, and SaaS are taken care of by the cloud marketplace.
Checkmarx One's scalability has changed my organization because the strong collaboration between the development and security team helps us to do things much faster.
The Claroty Platform offers a scalable solution that accommodates both cloud and on-premise deployments.
I would rate the scalability as eight or nine as the only issue faced was with login challenges, which could be improved.
The way the Claroty Platform has considered and included the active scanning part has made it quite scalable.
I would rate the stability of this solution a nine on a scale of 1 to 10 where one is low stability and 10 is high.
Checkmarx One is often down when the cloud provider experiences issues.
The platform runs with minimal delays and effectively manages workloads without intruding on the network.
Overall, I would rate the stability as eight out of ten.
Integration into the IDE being used would be beneficial so that code does not need to be uploaded to the website and an IDE-friendly report could be generated.
It could suggest how the code base is written and automatically populate the source code with three different solution options to choose from.
If you can improve the speed optimization, it takes around 30 to 40 minutes for checking a build. If you can make it within five minutes or 10 minutes, that would be great.
Additionally, reducing the overall cost of hardware and software solutions would be beneficial.
As AI is booming now, there are concerns about AI security.
Sometimes, these CVEs are not actually related to the device in the firmware at the site.
For a small team under 50 developers, normal expenses come under 30 to 60K.
Due to the number of years I've implemented Checkmarx One, there are rebates and discounts from the OEM which makes it a lot more profitable.
The pricing should be reasonable, matching what we are paying for.
One unique aspect of Claroty is that users get all the deployments for free.
The cost of the Claroty Platform is comparatively high.
The cost is as per the standard market.
Since replacing the previous tool, SAST and SCA scans are conducted in a couple of minutes instead of hours or days.
The best features Checkmarx One offers, over the past years, include broad language and technical support that Checkmarx provides, covering most languages.
Checkmarx One has positively impacted our organization as we tend to find vulnerabilities very early in the development cycle.
The ability to detect and classify assets, assess vulnerabilities, and manage patches and updates effectively is highly beneficial.
They offer threat detection, asset management, vulnerability management, and remote access, which makes them the sole vendor in the OT security space to offer all three services.
Additionally, their SRA solution, the Secure Remote Access solution, is very useful for industrial environments.
| Product | Market Share (%) |
|---|---|
| Checkmarx One | 1.3% |
| Claroty Platform | 0.8% |
| Other | 97.9% |

| Company Size | Count |
|---|---|
| Small Business | 32 |
| Midsize Enterprise | 9 |
| Large Enterprise | 46 |
| Company Size | Count |
|---|---|
| Small Business | 4 |
| Midsize Enterprise | 1 |
| Large Enterprise | 11 |
Checkmarx One is an enterprise cloud-native application security platform focused on providing cross-tool, correlated results to help AppSec and developer teams prioritize where to focus time and resources.
Checkmarx One offers comprehensive application scanning across the SDLC:
Checkmarx One provides everything you need to secure application development from the first line of code through deployment and runtime in the cloud. With an ever-evolving set of AppSec engines, correlation and prioritization features, and AI capabilities, Checkmarx One helps consolidate expanding lists of AppSec tools and make better sense of results. Its capabilities are designed to provide an improved developer experience to build trust with development teams and ensure the success of your AppSec program investment.
The Claroty Platform is tailored for monitoring and securing industrial control systems. It offers deep visibility into OT networks, enabling effective anomaly detection and vulnerability assessments. Its user-friendly interface and robust reporting tools facilitate easy management and compliance, enhancing organizational efficiency and cybersecurity posture in industrial environments.
We monitor all Vulnerability Management reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.