Checkmarx - Experts & Thought Leaders

Latest Checkmarx news & announcements

Checkmarx partners with Carahsoft for public sector security

Checkmarx and Carahsoft Technology Corp., The Trusted Government IT Solutions Provider®, today announced a partnership. Under the agreement, Carahsoft will serve as Checkmarx’s Master Government Aggregator®, making the company’s application security solutions available to the Public Sector through Carahsoft’s reseller partners and NASA Solutions for Enterprise-Wide Procurement (SEWP) V, E&I Cooperative Services Contract and The Quilt contracts. “Partnering with Carahsoft enables us to expand access to our application security platform across the Public Sector,” said Jonathan Kozimor, VP of Channel Americas at Checkmarx. “Carahsoft’s deep expertise in Government procurement and its extensive reseller ecosystem make the company an ideal partner to help agencies strengthen their application security posture. Together, we can empower organisations to integrate security seamlessly into modern development environments, reduce risk across the software lifecycle and accelerate the delivery of secure, mission-critical applications.” Slowing development velocity Checkmarx delivers a unified, AI-native application security platform designed to secure modern software development across the agentic development lifecycle (ADLC)—from code creation through runtime. The platform consolidates multiple security capabilities, including static and dynamic application security testing (SAST and DAST), software composition analysis (SCA), API security, container and infrastructure-as-code security and application security posture management (ASPM), into a single, integrated solution. By correlating risk signals across the ADLC, Checkmarx provides real-time visibility into vulnerabilities and prioritises the most critical risks. Its agentic AI-driven capabilities embed security directly into developer workflows, enabling continuous detection, automated remediation guidance and policy enforcement without slowing development velocity. Complex application environments Built to address the increasing complexity of AI-driven and cloud-native environments, the platform helps organisations eliminate fragmented tooling and replace it with a centralised, always-on security layer. This unified approach enables teams to reduce noise, focus on exploitable risks and remediate issues earlier in the development process, minimising rework and improving overall software resilience. With seamless integration into existing DevOps ecosystems and real-time governance dashboards, Checkmarx supports secure, scalable innovation while ensuring continuous compliance, visibility and control across even the most complex application environments. Mission-critical applications “We are pleased to partner with Checkmarx to bring its innovative application security platform to the Public Sector,” said Brian O’Donnell, Vice President of Cybersecurity Solutions at Carahsoft. “As agencies continue to modernise their development environments, it is critical they have access to solutions that embed security throughout the software lifecycle. Together with our reseller partners, we are enabling Government organisations to adopt a proactive, integrated approach to application security—helping them reduce risk, protect sensitive data and accelerate the delivery of secure, mission-critical applications.” Checkmarx’s application security solutions are available through Carahsoft’s SEWP V contracts NNG15SC03B and NNG15SC27B, E&I Contract #EI00063~2021MA and The Quilt Master Service Agreement Number MSA05012019-F.

Checkmarx One embeds AI security in app development

Checkmarx, the pioneer in agentic application security, unveils a new Checkmarx One platform built for the new era in AI development. As AI accelerates software creation beyond human speed and scale, traditional application security models are fundamentally misaligned. The new platform embeds agentic, AI-driven security across code, open-source dependencies, AI assets, and runtime, enabling organisations to innovate at machine speed with security built in from the start. Reducing manual remediation At the core of the reimagined Checkmarx One platform is a new architecture powered by agentic security agents and AI-native intelligence across the software and AI supply chain. Key innovations include: Triage Assist, an autonomous AI agent that prioritises vulnerabilities in source control based on real-world exploitability and contextual risk, enabling teams to focus on what truly matters rather than static severity scores. Remediation Assist, generates review-ready fixes for validated vulnerabilities before code merges, accelerating secure delivery and reducing manual remediation overhead. AI Supply Chain Security, a centralised governance and visibility layer for AI components embedded in modern applications. It discovers hidden AI assets, including models, agents, datasets, prompts, and AI-BOM elements, detects model-loading and execution risks, and enforces policy within existing development workflows. AI SAST, a hybrid LLM-powered and query-based analysis engine that expands detection across emerging, unsupported, and AI-generated programming languages, extending security beyond traditional rules-based scanning. DAST for AI, a next-generation dynamic analysis engine that strengthens runtime protection across CI/CD and production environments, supporting flexible testing strategies for AI-accelerated applications. AI-driven software development Together, these innovations shift application security from reactive review to agentic governance, aligned with the speed and complexity of AI-driven software development. “The AI era has fundamentally disrupted the balance between software creation and assurance,” said Sandeep Johri, CEO of Checkmarx. “Code is now produced at machine speed, but successful security in this environment requires more than speed alone. It requires independent oversight, full visibility across the AI software supply chain, and unified governance that spans code, dependencies, AI assets, and runtime. Agentic application security brings those capabilities together, helping enterprises close the risk gap without slowing innovation.” AI-generated applications “AI has compressed the software development lifecycle from months to minutes,” said Jonathan Rende, Chief Product Officer at Checkmarx. “When applications move that fast, risk compounds just as quickly. Our redesigned agentic platform allows development organisations to innovate at machine speed while securing AI generated applications to protect the business.” The new capabilities announced today are all available as part of the Checkmarx One Enterprise Edition, or as add-ons to the Essentials or Professional Edition. Checkmarx will demonstrate these capabilities at RSA Conference 2026.

Checkmarx IDE support for Kiro: AI security insights

Checkmarx, the pioneer in agentic application security, announces IDE-native support for Kiro through Checkmarx Developer Assist, extending real-time, AI-powered application security directly into the developer environment. The integration allows developers to identify and address security issues as code is written, without leaving the IDE or relying on downstream CI/CD scans. As development accelerates, security risks surface earlier and more frequently. Developer Assist meets this challenge by embedding security analysis directly into the Kiro workflow, ensuring that speed and security advance together. Additional development workflows “With AI-driven development environments like Kiro, security must operate at developer speed,” said Jonathan Rende, chief product officer at Checkmarx. “Developer Assist brings agentic, policy-driven security insight directly into the IDE, helping developers understand real risk in real time while giving AppSec teams centralised visibility and control through Checkmarx One. With the Kiro agent powered by Checkmarx, developers can eliminate up to 90% of security rework before code is committed.” Using the official Checkmarx IDE extension, developers can activate Developer Assist inside Kiro with minimal setup (with support for additional development workflows including command-line interfaces planned). Once authenticated, Developer Assist analyses source code and dependencies in the active workspace, applying existing Checkmarx One policies automatically. No Kiro-specific configuration, proprietary APIs, or experimental integrations are required. AI-assisted development Security findings surface directly in the IDE with contextual detail, helping developers remediate issues early in the software lifecycle. At the same time, results are reflected in the Checkmarx One platform, providing AppSec and engineering leaders with a unified view of risk across projects and teams. By extending IDE-native application security into Kiro, Checkmarx enables organisations to adopt AI-assisted development with confidence, embedding security from the first line of code while maintaining enterprise-grade governance.