No results found. Try different keywords.
Enter at least 3 characters to search...
Home » Security License » Checkmarx
Activate and scale your Checkmarx application security capabilities, including SAST, SCA, IaC scanning, and pipeline integrations, so your teams can find and fix code risk faster across all SDLC workflows.
A Checkmarx license activates your application security capabilities and defines how your organization uses the platform across projects, teams, and development workflows.
Your entitlement determines which modules are enabled. This might include Static Application Security Testing (SAST) for custom code analysis, Software Composition Analysis (SCA) for open-source dependency risk, or coverage for infrastructure-as-code and containers. The license also governs how we measure your usage, typically based on the number of applications, projects, repositories, developers, scan volume, or CI/CD integration scope.
Licensing is delivered via a 1-, 3-, or 5-year subscription. Maintaining an active term ensures you receive continuous updates for new vulnerabilities, rules, and secure coding patterns. Cloud deployments generally provision a tenant with your assigned entitlements, while on-prem deployments use an administrative activation workflow to enable modules.
Because AppSec programs vary drastically, from monorepos to multi-repo setups, and from centralized AppSec to developer-led security, you must align your entitlements to your actual SDLC requirements. Accurate sizing upfront prevents coverage gaps, avoids overspending, and keeps renewals predictable as your engineering teams scale.
Most buyers get stuck deciding which modules they actually need and what drives the pricing metric. Here is how it breaks down:
Plan / Edition
Best For
Key Inclusions
What Affects Price
SAST-Focused
Code-first AppSec
Code scanning, rules, remediation guidance
Apps/projects, dev teams, term
SCA / Open-Source
Dependency risk
OSS inventory, vulnerability & license risk
Repos, scan volume, term
Full AppSec Bundle
Broad coverage
SAST + SCA + IaC + CI/CD integrations
Scope/modules, users, term
Add-ons & Services
Faster rollout
Implementation, policy design, training
Scope & complexity
Compatibility & Requirements
Quote Checklist
To get an accurate quote, please provide:
Checkmarx pricing depends directly on your coverage scope and required modules.
The biggest drivers are the specific capabilities you enable (code scanning, open-source risk, IaC, integrations) and the size of your environment (apps, projects, or repositories). The number of teams running pipeline or scheduled scans will also influence the cost.
Longer subscription terms (3 or 5 years) typically improve your annualized pricing. Finally, your deployment approach (cloud vs. on-prem) and any required implementation support, such as onboarding, policy tuning, or governance reporting, will shape the final quote. The most accurate pricing comes from quoting against your actual SDLC scope, ensuring your entitlement perfectly matches your rollout plan.
Usually the enabled modules (SAST/SCA/IaC), the number of apps/projects or repos, and the subscription term.
Many teams start with SAST for code risk and add SCA to manage open-source exposure as pipelines mature.
Yes—pipeline integrations are a common requirement for automated security checks.
Cloud is often faster to deploy; on-prem can fit regulated environments. The best choice depends on policy and infrastructure constraints.
Modules, apps/projects or repos, team size/scan frequency, deployment preference, and term length.