Gartner® Checkmarx Named a Leader in the 2026 Gartner® Magic Quadrant™ for Software Supply Chain Security Get the Report
Outlook Report The Future of Application Security in the Era of AI Download Now
Webinar The AppSec Bottleneck Has Moved Downstream: Why visibility is no longer enough in the age of AI-generated code Watch Now
Latest Innovations
Checkmarx for Developers
Partners
Blog
Research

Checkmarx One for Government Achieves FedRAMP Moderate Certification

A new standard for secure-by-design in the public sector.

Checkmarx One for Goverment FedRAMP

Federal agencies have a new option for securing the software behind their most critical systems.

Checkmarx One for Government (CxG) has officially achieved FedRAMP Certified status at the Moderate Impact Level (Class C, Rev5), a milestone that gives U.S. government agencies streamlined, compliant access to the industry’s most comprehensive application security platform.

The certification comes as agencies face growing pressure to modernize their systems, secure increasingly complex software supply chains, adopt AI responsibly, and meet evolving federal requirements without adding operational burden.

Federal Systems Demand a Higher Standard

Federal information systems carry an outsized burden. They hold Controlled Unclassified Information, power services that citizens depend on, and increasingly serve as the connective tissue between agencies, contractors, and critical infrastructure.

A vulnerability introduced at the code level doesn’t stay contained; it propagates into production systems that the public relies on every day.

FedRAMP exists precisely because of that reality. The Moderate baseline requires roughly 323 security controls across 17 control families, covering everything from access control to system and communications protection. Achieving that bar isn’t a checkbox exercise; it’s a rigorous, independently assessed validation that a platform is built to protect the confidentiality, integrity, and availability of federal data.

For Checkmarx, that data integrity isn’t just a compliance requirement, it’s foundational. An AppSec platform is only as trustworthy as the assurances it can make about the code, dependencies, and infrastructure it scans.

Achieving its FedRAMP Moderate certification means Checkmarx One for Government has been independently vetted to meet that bar for the U.S. government’s most sensitive unclassified workloads. Checkmarx is also pursuing the FedRAMP High Impact Level for its most mission-critical use cases.

Where Modern Risk Actually Enters

Protecting the integrity of federal systems requires more than securing custom code. Agencies also depend on vast ecosystems of open-source libraries and third-party components, creating additional paths for malicious code to enter trusted software.

Malicious packages are legitimate-looking software components – often libraries or modules – that have been intentionally crafted to perform harmful actions when installed or executed. Checkmarx has collected the largest malicious package database in the industry, over 400,000, helping organizations stay ahead of cyber threats and safeguard agencies from malware, spyware, and other threats.

Bad actors also target organizations by exploiting vulnerabilities in their trusted vendors or suppliers. Malicious code that is unnoticed may inadvertently be included in packages or updates from outside developers. These attacks can spread rapidly, affecting numerous users and organizations that rely on the compromised software, resulting in widespread damage and disruption. Notable examples include SolarWinds, MOVEit, and 3CX Software, which involved the distribution of malicious code through legitimate software or updates.

AI Is Changing the Math

AI-assisted development is raising the stakes even further.

AI has rapidly reshaped how software is built, with 99% of development teams using it for code generation. Developers across government and industry are leaning on AI coding assistants to move faster, and the productivity gains are real.

But so is the risk: AI-generated code is being shipped at a pace that often outstrips organizations’ ability to review it, and a growing body of evidence shows that a large share of organizations using AI coding tools are shipping vulnerable code as a result.

That shift changes what agencies need from application security in two important ways.

First, the sheer volume of code being produced means scanning has to happen continuously and automatically – human-speed code review was never designed for AI-speed code generation.

Second, the kinds of risk introduced by AI-generated code aren’t always the same patterns that legacy static analysis engines were tuned to catch, which means the depth and currency of an AppSec vendor’s detection engines matters more than ever.

Federal agencies need security that can leverage AI to operate at the speed of modern development while also distinguishing meaningful, exploitable risk from noise.

Code to Cloud: The Need for Unified AppSec

These changes make fragmented application security increasingly difficult to sustain.

Agencies that stitch together disconnected scanners for code, dependencies, containers, and cloud infrastructure end up with fragmented risk visibility and duplicated effort.

The challenge is no longer simply finding vulnerabilities. It is understanding how risks relate to one another, determining which findings matter most, and helping teams act before those risks reach production.

That requires a unified platform spanning the full software development lifecycle, from the first line of code through deployment. It must continuously update as threats evolve, apply consistent security policies across environments, and give developers and security teams a shared view of risk.

Why SaaS Delivery Is Now an Economic Necessity

Agencies must meet these requirements while operating under growing fiscal and staffing constraints. Agencies are being asked to do more – modernize legacy systems, meet Zero Trust mandates, comply with executive orders on secure software development – without adding more operational burden. In that environment, SaaS delivery isn’t just a convenience; it’s an economic necessity.

A FedRAMP-certified SaaS platform eliminates the need for agencies to stand up and maintain their own security infrastructure, reduces the redundant, agency-by-agency assessment cycles that FedRAMP was designed to eliminate in the first place, and shifts the burden of patching, scaling, and continuous monitoring to the vendor. That “do once, use many times” model is estimated to save significant time, cost, and staff effort across government.

For AppSec specifically, this matters. The tooling must evolve continuously alongside new development practices, vulnerabilities, attack techniques, and software ecosystems. Delivering those capabilities as an updated service is often more sustainable than maintaining a static, self-hosted deployment – freeing agency teams to focus on reducing risk, not managing infrastructure.

The Breadth Federal Agencies Need

Checkmarx One for Government is built for this environment. The platform brings application security capabilities together across the full development lifecycle, helping agencies reduce tool sprawl and manage risk through one consistent, FedRAMP-certified environment. Its capabilities include:

  • SAST (Static Application Security Testing): identifying vulnerabilities directly in custom source code
  • SCA (Software Composition Analysis): securing open-source dependencies and managing license risk
  • Malicious Package Detection: flagging compromised or intentionally malicious open-source packages before they reach production
  • IaC Security: scanning Infrastructure as Code templates for misconfigurations before they’re deployed
  • Container Security: securing container images and runtime environments
  • ASPM (Application Security Posture Management): correlating findings across all of the above into a unified, risk-prioritized view
  • DAST (Dynamic Application Security Testing): coming soon to the platform, extending coverage to runtime behavior and closing the loop from code to cloud.

Together, they give federal agencies consistent visibility and control across custom code, open-source software, infrastructure, containers, and deployed applications.

Find Vulnerabilities Before They Happen

But visibility alone does not reduce risk. Agencies also need a practical way to understand which findings matter and help development teams address them before they reach production.

That is where Application Security Posture Management (ASPM) becomes especially important. ASPM brings findings from across the application lifecycle into one unified, risk-prioritized view, helping security teams understand which vulnerabilities matter most, identify coverage gaps, track remediation progress, and maintain a clearer picture of their overall security posture.

Rather than treating every finding as equally urgent, agencies can use that context to direct limited resources toward the vulnerabilities most likely to create meaningful exposure. This supports more proactive vulnerability management, stronger compliance, and better coordination between security and development teams.

ASPM also helps translate that intelligence into prioritized tasks within the tools developers already use, allowing them to address issues closer to the moment code is created without repeatedly leaving their workflows to interpret disconnected security reports.

For federal agencies, that matters. Security teams can apply consistent policies from development through deployment, reduce the number of vendors and consoles they manage, and turn fragmented findings into coordinated remediation.

This code-to-cloud approach connects broad security coverage with the context and workflows teams need to act on it.

What This Means for Federal Agencies

A FedRAMP-certified platform strengthens cybersecurity by standardizing environments, enabling continuous monitoring, and automating processes, freeing resources and helping security teams stay ahead of evolving threats.

With Checkmarx’s FedRAMP Moderate certification established, federal agencies now have a faster, lower-friction path to deploying Checkmarx One for Government: a single, comprehensive, cloud-native AppSec platform, independently assessed against a rigorous federal security baseline, covering the full software development lifecycle.

They can secure applications from code to cloud while reducing infrastructure overhead, consolidating disconnected tools, and giving development and security teams a shared view of risk.

The platform is also backed by more than two decades of application security experience. Checkmarx helped define the SAST category and pioneered developer-centric approaches to finding and fixing vulnerabilities in custom code.

That history matters in a federal environment. Agencies need confidence that the vendor securing their software supply chain can adapt to changing compliance frameworks, development models, threat patterns, and mission requirements.

As agencies continue to navigate secure software development mandates, Zero Trust requirements, and constrained budgets, that combination of breadth, maturity, and compliance is becoming less of a nice-to-have and more of a baseline expectation – and Checkmarx One for Government is built to meet it.

Tags:

Agentic AI

AI generated code

AppSec

Federal Government

US Government