DevSecOps Evolution 2025 Research Report - Checkmarx
background image

Research Report

DevSecOps
Evolution 2025

The progress made, the challenges that still await

hero_image

Many are undertaking the journey to DevSecOps. But many are still struggling to make the final push to a place where security teams reduce friction at scale to match the pace of DevOps.

The first edition of this report independently surveyed 1500 Heads of Development, Platform Engineers and Software Engineers. The purpose was to learn what DevOps teams think of AppSec and establish where they stand on the road to DevSecOps maturity, to provide a thorough and insightful look into the current state of DevSecOps.

We uncovered how organizations are tackling five key requirements for DevSecOps success. Our findings include the answers to: 

  • What do developers think about their security skills over time?
  • How does security impact developer workflow?
  • How do most developers perceive the intentions of AppSec teams?
  • What is keeping AppSec and DevOps from having a truly collaborative partnership?

 

The report also contains recommendations, proven in the real world, on how to achieve the cultural shift needed to make DevSecOps effective for business and efficient for developers, resulting in secure, high-performing code.

Start your evolution
Get your copy of this comprehensive report to access fascinating insights and expert advice, backed by research, that will help progress your journey towards DevSecOps.

Start Your Evolution Now

What Our Customers Say About Us

See why enterprises trust our approach to
AppSec to secure their business-critical applications.

“Checkmarx One definitely checks all my boxes from a security standpoint and has a great interface that’s engaging and easy to use. Some of the solutions we considered were more complicated. With Checkmarx One, it’s easy to get right to the problem with little to no learning curve.”

“Incorporating Checkmarx’s technology has revolutionized our development culture. It’s more than just technology; it serves as the foundation of our security strategy, ensuring that our applications are secure by design.”

“The success of our AppSec program can be directly attributed to the tooling, processes and support provided by Checkmarx managed services. Our mission revolves around providing secure and compliant lottery and gaming applications and services to our clients around the globe, and with Checkmarx SAST, SCA and associated components enhanced by their stellar service support, we deliver on this promise with confidence and certainty.”

“After nearly nine years of using Checkmarx’s SAST, CGI’s journey has been one of seamless integration and consistent satisfaction. The last three years have been particularly smooth, reflecting the solution’s reliability and our successful partnership.”

“After reviewing the Checkmarx platform, I’m not sure how Veracode is able to exist while being at a similar price point.”

“Checkmarx’s execution is impressive; it’s brought all the products under one cloud platform.”

“By Far The Best AppSec Tooling Decision We Have Made!!”

“We were thrilled to find Checkmarx, which helped us improve the SLA for identifying and remediating risk, reduce risk and the number of vulnerabilities, and eliminate high- and medium-risk issues.”

“Checkmarx made security team and developers life easier.”

Market & Technology Leadership

40%

of Fortune 100

1800+

Customers in 70 countries

75+

Languages & 100+ frameworks

6X

Leader at Gartner® Magic Quadrant™ for Application Security Testing

Industry Recognition

01_forrester
Gartner badge
03_cyber_security_
04_crn