Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Checkmarx Application Security Posture Management (ASPM) and Cloud Insights are capabilities in Checkmarx One that bring application-security findings and cloud runtime context together. The goal is to help teams prioritize remediation using signals such as whether vulnerable code is running in production or exposed to the internet—not to guarantee that vulnerabilities will be prevented or eliminated.

What Checkmarx ASPM and Cloud Insights do

ASPM is a management and correlation layer, not a single vulnerability scanner. Checkmarx describes Application Risk Management as consolidating findings from its SAST, Software Composition Analysis (SCA), and Infrastructure as Code (IaC) Security scanners, correlation-engine results, and findings imported through Bring Your Own Results (BYOR). That gives security teams a consolidated view across supported sources rather than requiring them to assess each scanner’s output in isolation.

Cloud Insights adds context from cloud and Cloud-Native Application Protection Platform (CNAPP) environments. Checkmarx says it retrieves runtime and exposure metadata, then matches container images to Checkmarx One projects and their source repositories. That link can help a team determine whether a finding relates to code deployed in a running workload or an internet-facing service.

Checkmarx introduced ASPM and Cloud Insights on the Checkmarx One AppSec platform in June 2024. Its announcement framed the capabilities as a way to correlate, prioritize, and triage findings with code-to-cloud information. Checkmarx’s launch announcement also claimed a reduction of more than 80% in security noise. The release does not describe a study design or independent validation, so treat that figure as a vendor claim rather than an established outcome for enterprise deployments.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How Cloud Insights connects code to runtime

The documented workflow starts with a connection to a supported cloud or CNAPP provider. Cloud Insights retrieves metadata and attempts to associate container images with projects and source repositories in Checkmarx One. Checkmarx documents runtime information from Wiz, AWS, and other supported CNAPP providers; the metadata and functions available depend on the integration.

For its Wiz integration, Checkmarx describes collecting information such as clusters, pods, containers, and network exposures. Cloud Insights provides Inventory, Attack Paths, and Enrichment Logs views. Those views can help teams inspect discovered assets, understand relationships and exposure, and review enrichment activity. The practical value depends on whether the returned metadata can be matched reliably to the right image, project, and repository.

That mapping is an important operational dependency. If image names, project records, or repository identities are inconsistent, runtime context may fail to enrich a finding or may be associated incorrectly. During an evaluation, check how the product handles naming conventions, image tags, multiple repositories, and changes in deployment metadata, and determine what ongoing maintenance the mapping requires.

Does Checkmarx prioritize findings by runtime use and exposure?

Yes. Checkmarx documents runtime use and public exposure as inputs to its risk score. Its example adds 0.5 for runtime usage and 1 for public, internet-facing exposure before normalizing the result. In the example, a base score of 9 becomes 10.5 after those adjustments, then normalizes to 9.13 against a maximum of 11.5. These are Checkmarx scoring mechanics, not a universal measure of exploit likelihood or a guarantee that a finding is exploitable.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Runtime and exposure context can help distinguish a vulnerability present in code from one associated with a running, exposed workload. It should inform triage alongside severity, exploitability evidence, business impact, and the organization’s own policies. Ask which score inputs are visible and whether the prioritization can be tuned to match your team’s risk model.

Which findings and integrations are covered?

Checkmarx documents support across both security data sources and the development toolchain. Its integration catalog includes examples such as GitHub, GitLab, Bitbucket, Azure DevOps, Jenkins, GitHub Actions, VS Code, JetBrains, Jira, Slack, registries, AWS, and Azure. Repository webhooks can trigger scans on pushes or pull requests. The catalog displayed 40 integrations when accessed in 2026, but its contents and count can change; neither should be treated as a guarantee that a particular feature is available for every listed connection.

Confirm support for the exact products, configurations, and capabilities your workflow requires. In particular, distinguish a connection that imports findings or metadata from one that supports the specific scan trigger, runtime enrichment, or workflow action your team expects.

  • Security inputs: Confirm which SAST, SCA, IaC Security, correlation, and BYOR results are included and how their provenance is represented.
  • Cloud and runtime context: Verify that your CNAPP provider and required metadata—such as workload identity and exposure—are supported.
  • Identity mapping: Test how container images map to Checkmarx projects and repositories, including how the mapping is maintained as deployments change.
  • Developer workflow: Check the precise SCM, CI/CD, IDE, ticketing, and feedback integrations needed to route findings to the people who can act on them.

Licensing and deployment questions

Checkmarx documentation says Cloud Insights is included in the Essential, Professional, and Enterprise license bundles. Enterprise entitlements can vary by contract, feature, and date, so confirm current access and any prerequisites directly with Checkmarx before planning a rollout.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In addition to entitlement, assess operational effort: connecting providers, granting access to relevant metadata, maintaining identity mappings, and deciding how teams will use enriched findings. The product descriptions establish a vendor-documented workflow, but do not by themselves demonstrate the accuracy or ongoing cost of operating it in a particular environment.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to evaluate Checkmarx for your environment

  1. Inventory your sources. List the scanners and third-party results you want in one view, then verify coverage for each source and how imported findings retain provenance.
  2. Validate the cloud connection. Confirm your CNAPP provider and required runtime or exposure signals are supported for the intended use case.
  3. Test representative mappings. Use real image, project, and repository naming patterns to see whether findings receive the correct runtime context, including when assets are renamed or redeployed.
  4. Review prioritization behavior. Examine the score inputs, including runtime use and public exposure, and decide whether the resulting ranking reflects your remediation policy.
  5. Follow the finding through the workflow. Check that scans, notifications, tickets, and developer feedback reach the right teams through the integrations you intend to use.
  6. Confirm commercial and access details. Ask Checkmarx to verify current license entitlement, access requirements, and feature availability for your account.

Checkmarx’s materials describe how the platform is intended to work, but the sources do not provide an independent effectiveness study or neutral comparative benchmark. Treat claims about reduced noise as vendor-reported, and judge fit through coverage, mapping quality, scoring transparency, workflow support, and the effort required to keep context accurate.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.