Checkmarx
Unified 'Checkmarx One' application security platform spanning code, software supply chain, and cloud infrastructure scanning with SecOps integrations.
Visit Website ↗Overview
Checkmarx was founded in Israel in 2006 and built its early reputation on enterprise static application security testing (SAST). It now sells as a consolidated platform, Checkmarx One, spanning code scanning, software supply chain, and cloud infrastructure, integrated with SecOps tools such as Wiz, CrowdStrike, and Sysdig.
Hellman & Friedman acquired Checkmarx from Insight Partners in 2020 for roughly $1.15-1.2 billion. In December 2025 it acquired Tromzo to add ASPM capability to the platform.
Checkmarx was named a Leader in the 2025 Gartner Magic Quadrant for Application Security Testing for the seventh time. A published Best Buy case study credits the platform with an 80% reduction in security alert noise.
Innovation Matrix Assessment
Platform consolidation (Checkmarx One) plus the December 2025 Tromzo acquisition for ASPM shows active roadmap expansion into adjacent categories.
The Best Buy case study's reported 80% alert-noise reduction is a concrete, named operational efficiency claim, unusual for this category.
PE-owned since 2020 with a 2022 workforce reduction; still holds Gartner Leader status seven years running.
Platform consolidation across code/supply chain/cloud is a meaningful breadth play but not a fundamentally new delivery or business model.
Named Best Buy case study plus sustained Gartner Peer Insights Customers' Choice recognition.
Tromzo acquisition for ASPM and continued platform breadth keep it aligned with where enterprise AppSec buying is heading.
Why CISOs Should Care
A single platform covering code, supply chain, and cloud scanning with documented alert-noise reduction helps stretched AppSec teams triage faster without adding headcount.
What Makes It Different
Built around platform consolidation and SecOps interoperability rather than being a best-of-breed point scanner.
The Matrix Verdict
67/100 — INCREMENTAL INNOVATOR
Incremental Innovator (~67/100). A mature, PE-owned Gartner Leader with credible customer evidence of operational value, but not a category disruptor.
Editorial Note: Claims vs. Verified Findings
Gartner Leader status and the Tromzo/H&F ownership history are independently reported. The 80% alert-noise-reduction figure comes from a Checkmarx-published case study.
Sources
Alternatives to Checkmarx
Endor Labs
Reachability-based software composition analysis that filters open-source dependency risk down to what code paths are actually exploitable.
JFrog
Public software supply chain security platform (Xray plus Advanced Security) that scans binaries and artifacts end-to-end from the…
Snyk
Developer-first application security platform combining SAST, SCA, container, IaC, and API/DAST scanning inside the developer workflow.
Apiiro
Builds a continuous 'code risk graph' that maps code, developers, and cloud deployment to prioritize AppSec findings by…
ArmorCode
Tool-agnostic ASPM layer that correlates findings from 300+ existing security tools into one prioritized backlog, without running its…
Contrast Security
Instruments applications from within using IAST and RASP to find and block vulnerabilities as code actually executes, rather…