APPSEC / Checkmarx

Checkmarx One

Checkmarx One is a commercial platform spanning application security testing and posture management. The vendor describes static and dynamic testing, composition analysis, infrastructure as code, containers, secrets, application programming interface checks, malicious-package detection, and ASPM analytics, with Developer Assist for the authoring loop.

Application security platformResearch reviewed

What you are evaluating

Source-upload versus air-gap deployment, Fusion or hybrid engine accuracy on the local stack, and whether ASPM can land analytics without locking to Checkmarx scanners are buyer tests. Documentation describes ASPM as a landing analytics surface rather than a replacement engine.

A useful evaluation context

A plausible evaluation context is a team that wants one commercial AppSec platform and must test air-gap constraints and whether ASPM remains useful with mixed scanners.

Documented capabilities

The vendor describes these capabilities in the linked sources. Availability depends on the product edition and supported environment.

  • Static, dynamic, composition, infrastructure-as-code, container, secrets, and application-programming-interface testing in one commercial platform.
  • Malicious-package detection alongside conventional composition analysis.
  • ASPM analytics and Developer Assist feedback in the authoring and review loop.

Where it fits in the work

  1. Connect repositories or an air-gapped upload path that the organization actually allows, then enable only the engines that match the languages in play.
  2. Use pull-request or developer feedback for new work, and land correlated results in ASPM for ownership without assuming scanners from other vendors disappear.
  3. Add non-production dynamic testing last, and record which findings originated in Checkmarx engines versus ingested tools.

APPLY THE IDEA / ILLUSTRATIVE EXERCISE

Make the outcome observable.

Point entitled Checkmarx One engines at a lab repository with a supported injection flaw, vulnerable dependency, and approved nonfunctional secret test pattern or configured synthetic rule. Use a deployment and data flow documented for the selected product and permitted by local policy.

Evidence to look for

Applicable engines report the supported test cases or document a coverage limitation. Secret-validity checks and unsupported patterns are distinguished from missed detections, and findings retain their originating engine and owner without production scanning.

Use synthetic data and an authorized test environment. Agree the scope and recovery steps before enabling enforcement.

Questions for your evaluation

  1. Can source stay in-region or air-gapped, and what must still be uploaded?
  2. How accurate are Fusion or hybrid engines on this stack compared with individual engines?
  3. Does ASPM accept non-Checkmarx scanners without forcing a rip-and-replace?

Names you may encounter: Checkmarx Developer Assist. Historical names do not establish current availability or feature equivalence.

Find your next idea.

Tip: press / to open search. Escape closes this window.