Checkmarx SAST and legacy product licensing covers the Checkmarx products that are licensed separately from the Checkmarx One Contributing Developer model. The main one is Checkmarx SAST (CxSAST), the on-premises static analysis server, sold with CxOSA open-source analysis. The others are the standalone Checkmarx SCA (CxSCA) service, Checkmarx IAST (CxIAST), the Codebashing secure-coding training service and the Supply Chain Security (SCS) Threat API. Each has its own License Types and Restrictions page, and the Checkmarx Terms of Service incorporate them by reference.[10] Checkmarx now positions a Checkmarx One “Start with SAST” package as ideal for existing on-prem customers.[12] For the overview, see Checkmarx licensing.
Editions
The Checkmarx SAST licence types page (version 2023.02) lists these SKUs:[1]
| SKU | Licence type |
|---|---|
| Cx-User (under Cx-Volume Users); Cx-SG-User; Cx-SDLC-User | Named User |
| Cx-Server (also called CxManager) | Node Locked |
| Cx-ConcurrentScans | Concurrent Engine Unit |
| Cx-Project | Project Based |
| Cx-Auditor | Named User |
| Cx-Integration | Integration License |
CxSAST licences come in two editions, SDLC and Security Gate. The License Details screen shows which one a licence is.[7] The other product families are licensed as follows:
| Product | SKUs and licence types |
|---|---|
| Checkmarx SCA (CxSCA) | Cx-User (Named User); Cx-ScannedUnit (Scanned Unit Based)[2] |
| CxIAST | Cx-IAST (Application Based); server component Node Locked[3] |
| Codebashing | Named User[4] |
| CxSCS Threat API | Cx-SCS (Package)[5] |
Metrics
Named User. A licence tied to a specific individual, which only that individual may use.[1] Catalog: Named User.
Node Locked. The Software is licensed to install, run and use on a single computer.[1] Catalog: Node Locked server.
Concurrent Engine Unit. The number of scans the Software can execute in parallel at any point in time.[1]
Project Based. A licence to scan a single named Project during the licence term. A Project is a single codebase maintained over time and used to build a particular named software module or application.[1] Catalog: Project; A Project Based licence covers one named codebase.
Integration License. A purchased integration may be used during the term of any active Software licence.[1]
Scanned Unit (CxSCA). Either 1 Project or 10 Microservices. A Microservice is an independently deployable codebase of up to 20,000 lines of code that supports a specific task or business goal.[2] Catalog: Scanned Unit; A Checkmarx SCA Scanned Unit is 1 Project or 10 Microservices; A Microservice is a codebase of up to 20,000 lines.
Application (CxIAST). A single executable component of a software application. Identical copies of one executable on different instances, and multiple versions of the same Application, count as one.[3] Catalog: Identical copies and versions of an executable count as one IAST Application.
Package (CxSCS). A collection of software components identified by name, package manager and version. Customers buy a monthly quantity of Packages to check through the Threat API.[5]
Counting / floors
Indirect use needs a Named User. Two kinds of user must be provisioned as a Named User: anyone who uses a CxSAST interface, including IDE plug-ins, and anyone who uses scan output through APIs, ticketing systems, PDF reports or any other form to track, resolve or remediate vulnerabilities. Report summaries reviewed by management, or for audit purposes, do not consume a licence, provided those people neither access the Software nor use the summaries to remediate.[1] CxSCA has the same rule.[2] This works like an indirect-access clause. Developers who fix findings from a Jira ticket fed by CxSAST need licences. Catalog: Anyone using Checkmarx SAST output to remediate must be a Named User; Management and audit review of report summaries does not consume a Named User.
Auditor permission. In CxSAST’s role model, the use-cxaudit permission (login to CxAudit) “is counted against the license”.[8] The Capacity panel of the License Details screen shows users, auditors, projects and concurrent scans available and in use.[7] Catalog: The CxAudit login permission counts against the licence.
Licence file limits. By default a CxSAST licence is valid for one version, for up to 12 months and for up to 10,000,000 lines of code. When any of the three limits is reached, the licence expires and must be replaced.[6] The License Details screen shows the edition, expiration date, the lines of code the licence was bought for and the HID.[7] Because a default licence covers one version, moving to a new CxSAST version can require a new licence file. Catalog: Lines of code; CxSAST licence files expire at one version, 12 months or 10 million lines.
Consumption of SCS Packages. A Package is consumed as soon as its name, package manager and version are sent to the API, whatever the result. Unused Packages expire at month end and do not roll over.[5] Catalog: SCS Threat API Packages are consumed when sent and expire monthly.
Floors. None are published.
Transfers
- Named Users (CxSAST, CxSCA). A licence can be moved when a Named User resigns, is terminated or permanently no longer needs access. The old credentials must be revoked promptly.[1][2] Catalog: Checkmarx SAST Named User licences transfer when a user leaves.
- Codebashing. Named User licences may not be transferred from one individual to another.[4] Catalog: Codebashing Named User licences cannot be transferred.
- Node Locked servers. A licence can be moved to a different machine a reasonable number of times. The customer sends a written request, obtains a new HID-based licence key and promptly deletes the old installation. Checkmarx may limit transfers it considers excessive.[1] The CxIAST server component follows the same rule.[3] Catalog: Node Locked server licences move to a new machine with a new HID key.
Virtualization & partitioning
CxSAST is Node Locked through its hardware ID. To obtain a licence, the administrator generates the HID on the server and sends it to Checkmarx. Importing a licence that does not match the current HID produces a warning.[6] In distributed or high-availability installations, the licence must be updated on each CxManager.[6] Moving the server to different hardware is a licence transfer under the rules above. The Terms of Service allow installation on one customer-controlled server, or the number of servers in the Quote, plus an inactive backup copy.[10] See virtualization and partitioning.
Cloud / BYOL
CxSAST and CxIAST are installed by the customer. Checkmarx can also host licensed on-premises software as a separately purchased Hosting Service.[10] CxOSA depends on CxSAST, and its licence is updated as part of the CxSAST licence.[9] Customers moving to Checkmarx One can receive temporary SAST or SCA migration licences for the term in the Quote. These may only scan code from developers licensed as Contributing Developers.[1][2]
Support
On-premises support covers the current version and the most recent previous version. Some fixes may require updating to the current version.[11] Catalog: On-premises support covers the current and previous version.
Audits and compliance
CxSAST can email the administrator weekly from 90 days before the licence expires.[7] The Capacity panel is the in-product record of Named Users, auditors, projects and concurrent scans in use.[7] The main exposure for a licence manager is the indirect-use rule. Count people who work from exported findings, not only those with CxSAST logins. See named user licensing and software license audit.
Out of scope
- CxSAST engine pack and version support schedules.
- Prices, which Checkmarx does not publish.
- Older License Types versions for these products that are not on checkmarx.com.