Press Release

Checkmarx One Surpasses $150M ARR and Expands Global Leadership in AI-Powered Application Security

Company pioneers new AI Coding Security Assistant category with Developer Assist and delivers groundbreaking research as platform adoption accelerates worldwide


PARAMUS, N.J. & SINGAPORE–(BUSINESS WIRE)–Checkmarx, the global leader in agentic-AI powered application security testing, today announced exceptional growth for its flagship platform, Checkmarx One, achieving over $150 million in annual recurring revenue (ARR) in just three years. This milestone underscores the platform’s rapid adoption by enterprises worldwide, driven by continuous innovation and visionary leadership.

The announcement coincides with new research from Checkmarx Zero highlighting the escalating security risks of AI-generated code and the growing global demand for preventive application security.

Exceptional Growth and Global Adoption

Checkmarx One has become the preferred platform for securing modern applications, now protecting more than 860 of the world’s largest enterprises. The company continues to post strong momentum, with over 30% ARR growth and 20% customer growth year-to-date (as of Sept. 30, 2025).

Under the leadership of CEO Sandeep Johri, who joined in 2023, Checkmarx has maintained double-digit global growth while expanding its presence in Asia Pacific and the Middle East, where demand for secure software development is accelerating in sectors such as financial services, government, and telecommunications.

Each month, Checkmarx One analyzes over 800 billion lines of code, performs four million scans, secures more than three million open-source packages, and inspects nearly one million container images—identifying approximately half a million malicious packages before they can impact organizations.

Proven Business Impact

With a prevention-first approach and measurable results, Checkmarx One helps enterprises reduce vulnerabilities per project by more than 50% within the first year and cut the average cost per fix by over 60%.

  • Cebu Pacific, the largest airline in the Philippines, reduced vulnerability density by 50% using Checkmarx One.
  • Construction leader PCL onboarded Checkmarx One within hours and now scans over four million lines of code weekly, reducing supply chain risk and accelerating remediation.

Recognition and Regulatory Leadership

Checkmarx has been recognized as a Leader in the 2025 GartnerĀ® Magic Quadrantā„¢ for Application Security Testing (AST), a Leader in The Forrester Waveā„¢ for Static Application Security Testing (SAST), and a Leader in the IDC MarketScape: Worldwide Application Security Posture Management (ASPM) 2025 Vendor Assessment.

The company also achieved FedRAMP Ready status at the High Impact Level for its Checkmarx One for Government platform—the first AppSec solution to reach this milestone with full SDLC coverage.

Checkmarx Zero Research: Intelligence Powering Secure Development

At the core of Checkmarx innovation lies Checkmarx Zero Research, a dedicated team that uncovers and mitigates the building blocks of modern software risk—from open-source supply chain threats to emerging LLM security challenges.

The group continuously fuels the intelligence layer of Checkmarx One and supports the global security ecosystem through open-source projects such as KICS, 2MS, and ZAP, advancing infrastructure-as-code, secret protection, and application scanning for organizations everywhere.

AI and the Future of Secure Development

The Checkmarx ā€œFuture of Application Security in the Era of AIā€ report—based on a survey of 1,500+ global security and development leaders—reveals a dramatic shift in coding practices:

  • 34% of organizations report that over 60% of their code is machine-generated.
  • Nearly 1 in 10 say 80–100% of their codebase is AI-written.
  • Only 18% have AI governance policies in place, and 98% experienced a breach tied to vulnerable code in the past year.

ā€œThe velocity of AI-assisted development makes a holistic, prevention-first security approach more critical than ever,ā€ said Sandeep Johri, CEO of Checkmarx. ā€œOrganizations embracing AI for productivity gains must equally invest in securing the code it produces. Checkmarx One delivers the AI-powered security intelligence modern enterprises need to stay protected from the moment code is created.ā€

Pioneering AI Code Security Assistants

In response to this new era of AI-driven development, Checkmarx introduced Developer Assist, the first in a new category of AI Coding Security Assistants. Now generally available, Developer Assist provides developers with real-time, context-aware guidance as they code—reducing remediation time from days to minutes.

Integrated with leading AI-native environments such as Windsurf by Cognition, Cursor, and GitHub Copilot, Developer Assist empowers teams to prevent vulnerabilities before production, combining the agility of AI with the security rigor of Checkmarx.

ā€œAcross Asia Pacific, the Middle East, and Africa, we’re seeing organizations embrace AI-driven innovation to transform how software is developed,ā€ said Nitin Dang, VP for APAC, Middle East, and Africa at Checkmarx. ā€œCheckmarx One empowers developers and security teams to harness AI responsibly – helping governments and enterprises protect their applications while achieving faster time to market.ā€

1 GartnerĀ®, Magic Quadrantā„¢ for Application Security Testing, By Jason Gross, Mark Horvath, Giles Williams, Shailendra Upadhyay, Dionisio Zumerle, Aaron Lord, October 6, 2025

Gartner Disclaimer

Gartner does not endorse any vendor, product or service depicted in its research publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner’s research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.

GARTNER is a registered trademark and service mark, and MAGIC QUADRANT is a registered trademark of Gartner, Inc. and/or its affiliates in the U.S. and internationally and are used herein with permission. All rights reserved.

2 The Forrester Waveā„¢: Static Application Security Testing Solutions, Q3 2025, Forrester Research, Inc., September 9, 2025

Forrester does not endorse any company, product, brand, or service included in its research publications and does not advise any person to select the products or services of any company or brand based on the ratings included in such publications. Information is based on the best available resources. Opinions reflect judgment at the time and are subject to change. For more information, read about Forrester’s objectivity here.

3 IDC MarketScape: Worldwide Application Security Posture Management Platforms 2025 Vendor Assessment, Doc # US53001925, September 2025

IDC MarketScape vendor assessment model is designed to provide an overview of the competitive fitness of technology and service suppliers in a given market. The research utilizes a rigorous scoring methodology based on both qualitative and quantitative criteria that results in a single graphical illustration of each supplier’s position within a given market. IDC MarketScape provides a clear framework in which the product and service offerings, capabilities and strategies, and current and future market success factors of technology suppliers can be meaningfully compared. The framework also provides technology buyers with a 360-degree assessment of the strengths and weaknesses of current and prospective suppliers.

About Checkmarx

Checkmarx is the leader in cloud-native, agentic application security, delivering enterprise-grade protection while lowering engineering costs and accelerating development velocity. The Checkmarx One platform scans trillions of lines of code each year for companies, cutting vulnerability density by more than half. Its autonomous security agents detect and counter AI-driven threats across the SDLC, providing prevention-first protection for legacy, modern, and AI-generated code at enterprise scale. Follow Checkmarx on LinkedIn, YouTube, and X.

Contacts

For more information, contact:

Vivien Lim

[email protected]

Author

Related Articles

Back to top button