Platform overview
Checkmarx One
Agentic AI
Checkmarx One Assist
AI-powered Agentic AppSec agents preventing and remediating threats autonomously.
Developer Assist
Developer-first AI agent for instant vulnerability prevention and fix.
Posture
ASPM
Unified visibility, control and prioritization across your entire AppSec posture.
PARTNERSHIPS & INTEGRATIONS
Partner Programs
Building stronger AppSec ecosystems through trusted partnerships.
Find a Partner
Discover certified partners to accelerate your AppSec journey.
SOLUTIONS FOR
Code
Supply Chain
Cloud
Services
Developer assist
Developer-first Al agent preventing and remediating vulnerabilities instantly in IDE.
SAST
Market leading developer friendly statio application security testing and analysis
DAST
Developer tailored dynamic application scanning for efficient security issues remediation.
API Security
Enterprise scale API security scanning for early detection of critical vulnerabilities.
SCA
Identify, prioritize, and remediate open-source vulnerabilities, malicious code, and license risks.
Malicious Package Protection
Reveal and eliminate malicious open-source packages using industry’s largest database.
Repository Health
Enhance security with full visibility into code repository health.
Software Supply Chain Security
Protect your entire software supply chain with industry-leading security across legacy, open source, and Al-generated code.
Container Security
Secure containerized applications across SDLC, from code to cloud runtime.
laC Security
Secure cloud infrastructure via advanced scanning and vulnerability detection.
Premium Support
Enhance security outcomes and ROl with proactive, expert technical support.
Premium Services
Accelerate AppSec program success while maintaining seamless developer experience.
Maturity Assessment
Assess your AppSec maturity and unlock actionable improvement steps.
Why Checkmarx
Customer Stories
Awards
Industry Recognition
Integrations
COMPARE CHECKMARX
vs. Snyk
vs. GitHub
vs. Veracode
vs. Fortify
vs. Black Duck
vs. Semgrep
RESEARCH
Checkmarx Zero
Research Blog
Disclosed Vulnerabilities
Open-Source Tools
Resources
Analyst Reports
Product Demos
Solution Briefs
Videos
Webinars
Whitepapers
LEARN
Blog
Documentation
Glossary
Knowledge Hub
Customer Enablement
The 2025 Gartner® Magic Quadrant™ for Application Security Testing
Read more
IDC MarketScape for ASPM 2025
The Forrester SAST Wave 2025
Checkmarx One Solution Brief
COMPANY
About Us
Leadership
Press Releases
Newsroom
Events
Careers
PARTNERS
Partner Directory
Become a Partner
GET IN TOUCH
Support Portal
Contact Us
Version: 2023.02
Last Updated: 02.10.2023
Checkmarx SCA License Types and Restrictions
License Types:
A “Project” is defined as a single codebase which is maintained over time, and used to build a particular named software module or application.
A “Microservice” is defined as a single codebase up to twenty thousand (20,000) lines of code that is independently deployable with well-defined interfaces and operations, which is part of a suite of modular components or services and supports a specific task or a business goal.
Additional License Restrictions:
A user who either: (i) uses one of the Checkmarx SCA user interfaces (i.e., via its user interface, IDE plugin, etc.), or (ii) uses the output of the scans (via APIs, ticketing systems, PDF reports, or any other form that does not require direct access to Checkmarx SCA) for the purpose of tracking, resolving, or remediating vulnerabilities detected by Checkmarx SCA, must be provisioned as a Named User.
Customer may not: (1) provide access to Checkmarx SCA to any individual who does not hold a valid Named User License; or (2) distribute the output generated by Checkmarx SCA in violation of the Named User restrictions noted above; however the review of report summaries: (a) by Customer management personnel, or (b) for audit purposes, shall not be deemed to consume a Named User license where such users do not access Checkmarx SCA or use the report summaries to remediate vulnerabilities detected by Checkmarx SCA.
Named Transfer Rights:
Customer may transfer Named User licenses when an existing Named User resigns, is terminated or permanently no longer requires access to Checkmarx SCA. Such transfer is conditioned upon Customer promptly revoking the credentials of the individual who is no longer an authorized Named User and properly credentialing the individual who is the replacement authorized Named User.
Checkmarx SAST / Checkmarx One Migration Licenses
This license type applies to the extent Checkmarx has provided Customer with Checkmarx SCA migration licenses to enable Customer’s migration to the Checkmarx One platform. Checkmarx SCA migration licenses are temporary, for the sole purpose of facilitating Customer’s migration to the Checkmarx One platform and are provided for the license term set out in the Quote. Checkmarx SCA Migration licenses are only permitted to scan code contributed by developers who are licensed as a Contributing Developer under the Checkmarx One platform.