
Checkmarx
Security and trust center evidence
Summary
Checkmarx has 2 registry-verified rows in the CertReports index, last verified 17 Sep 2026. The strongest row is FedRAMP: FedRAMP Authorized. This page is independent of the vendor’s own trust centre: dates, sources and caveats come from CertReports captures.
Reviewer brief
As of 17 Sep 2026, Checkmarx is listed in the FedRAMP registry as FedRAMP Authorized, with authorization issued 12 Jun 2026 and audited by Schellman Compliance, LLC. As of 17 Sep 2026, Checkmarx is listed in the CSA STAR registry at STAR Level 1 self-assessment (CAIQ), with the self-assessment dated 19 Jun 2020. As of 17 Sep 2026, no public evidence found for SOC 2 for Checkmarx. As of 17 Sep 2026, no public evidence found for HIPAA for Checkmarx. As of 17 Sep 2026, no subprocessor information was found in the evidence provided for Checkmarx.
- FedRAMP: listed in FedRAMP registry as FedRAMP Authorized, issued 12 Jun 2026, audited by Schellman Compliance, LLC (as of 17 Sep 2026)
- CSA STAR: listed in CSA STAR registry at STAR Level 1 self-assessment (CAIQ), dated 19 Jun 2020 (as of 17 Sep 2026)
- SOC 2 and HIPAA: no public evidence found for Checkmarx (as of 17 Sep 2026)
Facts only, each dated; nothing here is inferred, scored or advised. Brief generated 17 Sep 2026; it is regenerated whenever a row changes.
Among devops and observability vendors
2verified rows
Category median 1, across 90 indexed devops and observability vendors. Checkmarx has more verified rows than 88 percent of them.
application-securityci-cd-securitysastsca
Compare with similar vendors
Pick your own comparisonCompliance grid
Legal artefacts
No DPA, BAA or subprocessor list has been captured from a public page yet. Registry rows above do not depend on this.
Subprocessors
No subprocessor list captured yet.
Similar vendors with evidence
Related by product tags and the DevOps and observability category, ranked by shared tags, description similarity and overlapping evidence. Never by popularity.