Back to all tools

Tool Comparison

Micro Focus Fortify

Micro Focus Fortify

Enterprise-grade static and dynamic application security testing.

Licensed
VS
Checkmarx

Checkmarx

Find and fix security vulnerabilities in source code early in development.

Licensed
Share:XLinkedInWhatsApp

At a Glance

AttributeMicro Focus FortifyCheckmarx
License / PricingLicensedLicensed
TypeDevOpsDevOps
GitHub Stars
Rating4.2/54.3/5
Key Features6 listed6 listed
Integrations4 listed5 listed
Categories
SecurityStatic Application Security Testing (SAST)
SecuritySAST

Key Features

Micro Focus Fortify

  • SAST for 27+ programming languages with deep taint analysis
  • Fortify Software Security Center (SSC) for centralised issue management
  • ScanCentral for distributed, scalable scan execution
  • IDE plugins for Visual Studio, Eclipse, and IntelliJ IDEA
  • On-Demand DAST via Fortify on Demand
  • Issue correlation and deduplication across multiple scan types

Checkmarx

  • SAST for 30+ languages with low false-positive rates
  • Software Composition Analysis (SCA) for open source vulnerability detection
  • KICS (Keeping Infrastructure as Code Secure) for IaC misconfiguration scanning
  • IDE plugins for developer-first feedback before code is committed
  • Pull request integration with inline comments on security findings
  • Codebashing: in-context developer security training

Real-World Use Cases

Micro Focus Fortify

Enterprise secure SDLC integration

Integrate the Fortify Jenkins plugin to trigger scans on every build

Checkmarx

DevSecOps pipeline integration

Integrate Checkmarx SAST scan into the CI pipeline on every PR

Integrations

Micro Focus Fortify

jenkinsazure-devopsgithub-actionssonarqube

Checkmarx

jenkinsgithub-actionsgitlab-ci-cdazure-devopssonarqube

🏆 Which should you choose?

Choose Micro Focus Fortify if…

  • you're already in the Security ecosystem and prefer Micro Focus Fortify's workflow
Full Micro Focus Fortify guide →

Choose Checkmarx if…

  • you're already in the Security ecosystem and prefer Checkmarx's workflow
Full Checkmarx guide →