Try our new research platform with insights from 80,000+ expert users

Checkmarx One vs Fortify Software Security Center comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Oct 8, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Checkmarx One
Ranking in Static Application Security Testing (SAST)
3rd
Average Rating
7.6
Reviews Sentiment
6.9
Number of Reviews
70
Ranking in other categories
Application Security Tools (3rd), Vulnerability Management (21st), Static Code Analysis (2nd), API Security (2nd), DevSecOps (2nd), Risk-Based Vulnerability Management (7th)
Fortify Software Security C...
Ranking in Static Application Security Testing (SAST)
27th
Average Rating
7.8
Reviews Sentiment
8.3
Number of Reviews
5
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of February 2025, in the Static Application Security Testing (SAST) category, the mindshare of Checkmarx One is 11.5%, down from 13.8% compared to the previous year. The mindshare of Fortify Software Security Center is 0.4%, up from 0.2% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Static Application Security Testing (SAST)
 

Featured Reviews

Rohit Kesharwani - PeerSpot reviewer
Provides good security analysis and security identification within the source code
We integrate Checkmarx into our software development cycle using GitLab's CI/CD pipeline. Checkmark has been the most helpful for us in the development stage. The solution's incremental scanning feature has impacted our development speed. The solution's vulnerability detection is around 80% to 90% accurate. I would recommend Checkmarx to other users because it is one of the good tools for doing security analysis and security identification within the source code. Overall, I rate Checkmarx a nine out of ten.
Jonathan Steyn - PeerSpot reviewer
Comprehensive vulnerability analysis and customization features with decent pricing
Software Security Center is highly customizable and helps me test all vulnerability data against the latest conventions like OWASP Top Ten, CVE Top twenty-five, and several other legal compliances. WebInspect supports a number of APIs and web endpoints. I find its feature of macro recording allows for testing vulnerabilities during multi-factor authentication sessions very valuable. I appreciate the ability to further analyze data with tools like Audit Workbench.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"We use the solution to validate the source code and do SAST and security analysis."
"Apart from software scanning, software composition scanning is valuable."
"The administration in Checkmarx is very good."
"The user interface is modern and nice to use."
"We use the solution for dynamic application testing."
"The most valuable features of Checkmarx are its integration with multiple SCM solutions and CICD tools, its ability to scale according to user licenses, and the quick scanning process."
"The feature that I have found most valuable is that its number of false positives is less than the other security application platforms. Its ease of use is another good feature. It also supports most of the languages."
"The solution improved the efficiency of our code security reviews. It helps tremendously because it finds hundreds of potential problems sometimes."
"The reporting is very useful because you can always view an entire list of the issues that you have."
"You can easily download the tool's rule packs and update them."
"Software Security Center is highly customizable and helps me test all vulnerability data against the latest conventions like OWASP Top Ten, CVE Top twenty-five, and several other legal compliances."
"This is a stable solution at the end of the day."
"The overall rating for this tool is ten out of ten."
"Fortify Analytics' AI function helps scan and provides more detailed explanations and recommendations about vulnerabilities."
 

Cons

"The product can be improved by continuing to expand the application languages and frameworks that can be scanned for vulnerabilities. This includes expanded coverage for mobile applications as well as open-source development tools."
"I would like the product to include more debugging and developed tools. It needs to also add enhancements on the coding side."
"I would like to see the DAST solution in the future."
"The product's reporting feature could be better. The feature works well for developers, but reports generated to be shared with external parties are poor, it lacks the details one gets when viewing the results directly from the Checkmarx One platform."
"C, C++, VB and T-SQL are not supported by this product. Although, C and C++ were advertised as being supported."
"I can't create a business case with multiple-factor authentication."
"Micro-services need to be included in the next release."
"In terms of dashboarding, the solution could provide a little more flexibility in terms of creating more dashboards. It has some of its own dashboards that come out of the box. However, if I have to implement my own dashboards that are aligned to my organization's requirements, that dashboarding feature has limited capability right now."
"Improvements needed for Software Security Center include better aggregation views of datasets."
"Improvements needed for Software Security Center include better aggregation views of datasets."
"We are having issues with false positives that need to be resolved."
"This solution is difficult to implement, and it should be made more comfortable for the end-users."
"The product's overlap feature is restrictive and requires more customization efforts, which can be expensive."
"Fortify Software Security Center's setup is really painful."
 

Pricing and Cost Advice

"​Checkmarx is not a cheap scanning tool, but none of the security tools are cheap. Checkmarx is a powerful scanning tool, and it’s essential to have one of these products."
"We got a special offer for a 30% reduction for three years, after our first year. I think for a real source-code scanning tool, you have to add a lot of money for Open Source Analysis, and AppSec Coach (160 Euro per user per year)."
"We have a subscription license that is on a yearly basis, and it's a pretty competitive solution."
"The solution's price is high and you pay based on the number of users."
"The pricing is competitive and provides a lower TCO (total cost of ownership) for achieving application security."
"If you want more, you have to pay more. You have to pay for additional modules or functionalities."
"The license has a vague language around P1 issues and the associated support. Make sure to review these in order to align them with your organizational policies."
"I believe pricing is better compared to other commercial tools."
"The solution is priced fair."
"As a Fortify partner company providing technical support, I find the product expensive in our country, where local, inexpensive products are available."
"This is a costly solution that could be cheaper."
report
Use our free recommendation engine to learn which Static Application Security Testing (SAST) solutions are best for your needs.
838,713 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
21%
Computer Software Company
14%
Manufacturing Company
10%
Government
5%
Manufacturing Company
20%
Financial Services Firm
15%
Computer Software Company
10%
Educational Organization
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

What alternatives are there for Fortify WebInspect and Fortify SCA?
I would like to recommend Checkmarx. With Checkmarx, you are able to have an all in one solution for SAST and SCA as well. Veracode is only a cloud solution. Hope this helps.
What do you like most about Checkmarx?
Compared to the solutions we used previously, Checkmarx has reduced our workload by almost 75%.
What is your experience regarding pricing and costs for Checkmarx?
The pricing is relatively expensive due to the product's quality and performance, but it is worth it.
What do you like most about Micro Focus Software Security Center?
You can easily download the tool's rule packs and update them.
What is your experience regarding pricing and costs for Micro Focus Software Security Center?
The cost is comparative. It is slightly more expensive than some solutions, yet given the level of service offered, it is comparatively not that expensive. Costing is scalable and catered to specif...
What needs improvement with Micro Focus Software Security Center?
Improvements needed for Software Security Center include better aggregation views of datasets. I desire additional features like trend analysis or deeper views of vulnerability data based on analys...
 

Also Known As

No data available
Micro Focus Software Security Center, Application Security Center, HPE Application Security Center, WebInspect
 

Overview

 

Sample Customers

YIT, Salesforce, Coca-Cola, SAP, U.S. Army, Liveperson, Playtech Case Study: Liveperson Implements Innovative Secure SDLC
Neosecure, Acxiom, Skandinavisk Data Center A/S, Parkeon
Find out what your peers are saying about Checkmarx One vs. Fortify Software Security Center and other solutions. Updated: January 2025.
838,713 professionals have used our research since 2012.