LICENSEWARE

Checkmarx SAST and legacy product licensing

This article covers the licence types of Checkmarx's separately licensed products, mainly on-premises Checkmarx SAST (CxSAST) with CxOSA, plus Checkmarx SCA (CxSCA), CxIAST, Codebashing and the Supply Chain Security Threat API. For Checkmarx One, see Checkmarx One Contributing Developer licensing.

On This Page

Checkmarx SAST and legacy product licensing covers the Checkmarx products that are licensed separately from the Checkmarx One Contributing Developer model. The main one is Checkmarx SAST (CxSAST), the on-premises static analysis server, sold with CxOSA open-source analysis. The others are the standalone Checkmarx SCA (CxSCA) service, Checkmarx IAST (CxIAST), the Codebashing secure-coding training service and the Supply Chain Security (SCS) Threat API. Each has its own License Types and Restrictions page, and the Checkmarx Terms of Service incorporate them by reference.[10] Checkmarx now positions a Checkmarx One “Start with SAST” package as ideal for existing on-prem customers.[12] For the overview, see Checkmarx licensing.

Editions

The Checkmarx SAST licence types page (version 2023.02) lists these SKUs:[1]

SKU Licence type 
Cx-User (under Cx-Volume Users); Cx-SG-User; Cx-SDLC-User Named User 
Cx-Server (also called CxManager) Node Locked 
Cx-ConcurrentScans Concurrent Engine Unit 
Cx-Project Project Based 
Cx-Auditor Named User 
Cx-Integration Integration License 

CxSAST licences come in two editions, SDLC and Security Gate. The License Details screen shows which one a licence is.[7] The other product families are licensed as follows:

Product SKUs and licence types 
Checkmarx SCA (CxSCA) Cx-User (Named User); Cx-ScannedUnit (Scanned Unit Based)[2] 
CxIAST Cx-IAST (Application Based); server component Node Locked[3] 
Codebashing Named User[4] 
CxSCS Threat API Cx-SCS (Package)[5] 

Metrics

Named User. A licence tied to a specific individual, which only that individual may use.[1] Catalog: Named User.

Node Locked. The Software is licensed to install, run and use on a single computer.[1] Catalog: Node Locked server.

Concurrent Engine Unit. The number of scans the Software can execute in parallel at any point in time.[1]

Project Based. A licence to scan a single named Project during the licence term. A Project is a single codebase maintained over time and used to build a particular named software module or application.[1] Catalog: Project; A Project Based licence covers one named codebase.

Integration License. A purchased integration may be used during the term of any active Software licence.[1]

Scanned Unit (CxSCA). Either 1 Project or 10 Microservices. A Microservice is an independently deployable codebase of up to 20,000 lines of code that supports a specific task or business goal.[2] Catalog: Scanned Unit; A Checkmarx SCA Scanned Unit is 1 Project or 10 Microservices; A Microservice is a codebase of up to 20,000 lines.

Application (CxIAST). A single executable component of a software application. Identical copies of one executable on different instances, and multiple versions of the same Application, count as one.[3] Catalog: Identical copies and versions of an executable count as one IAST Application.

Package (CxSCS). A collection of software components identified by name, package manager and version. Customers buy a monthly quantity of Packages to check through the Threat API.[5]

Counting / floors

Indirect use needs a Named User. Two kinds of user must be provisioned as a Named User: anyone who uses a CxSAST interface, including IDE plug-ins, and anyone who uses scan output through APIs, ticketing systems, PDF reports or any other form to track, resolve or remediate vulnerabilities. Report summaries reviewed by management, or for audit purposes, do not consume a licence, provided those people neither access the Software nor use the summaries to remediate.[1] CxSCA has the same rule.[2] This works like an indirect-access clause. Developers who fix findings from a Jira ticket fed by CxSAST need licences. Catalog: Anyone using Checkmarx SAST output to remediate must be a Named User; Management and audit review of report summaries does not consume a Named User.

Auditor permission. In CxSAST’s role model, the use-cxaudit permission (login to CxAudit) “is counted against the license”.[8] The Capacity panel of the License Details screen shows users, auditors, projects and concurrent scans available and in use.[7] Catalog: The CxAudit login permission counts against the licence.

Licence file limits. By default a CxSAST licence is valid for one version, for up to 12 months and for up to 10,000,000 lines of code. When any of the three limits is reached, the licence expires and must be replaced.[6] The License Details screen shows the edition, expiration date, the lines of code the licence was bought for and the HID.[7] Because a default licence covers one version, moving to a new CxSAST version can require a new licence file. Catalog: Lines of code; CxSAST licence files expire at one version, 12 months or 10 million lines.

Consumption of SCS Packages. A Package is consumed as soon as its name, package manager and version are sent to the API, whatever the result. Unused Packages expire at month end and do not roll over.[5] Catalog: SCS Threat API Packages are consumed when sent and expire monthly.

Floors. None are published.

Transfers

Virtualization & partitioning

CxSAST is Node Locked through its hardware ID. To obtain a licence, the administrator generates the HID on the server and sends it to Checkmarx. Importing a licence that does not match the current HID produces a warning.[6] In distributed or high-availability installations, the licence must be updated on each CxManager.[6] Moving the server to different hardware is a licence transfer under the rules above. The Terms of Service allow installation on one customer-controlled server, or the number of servers in the Quote, plus an inactive backup copy.[10] See virtualization and partitioning.

Cloud / BYOL

CxSAST and CxIAST are installed by the customer. Checkmarx can also host licensed on-premises software as a separately purchased Hosting Service.[10] CxOSA depends on CxSAST, and its licence is updated as part of the CxSAST licence.[9] Customers moving to Checkmarx One can receive temporary SAST or SCA migration licences for the term in the Quote. These may only scan code from developers licensed as Contributing Developers.[1][2]

Support

On-premises support covers the current version and the most recent previous version. Some fixes may require updating to the current version.[11] Catalog: On-premises support covers the current and previous version.

Audits and compliance

CxSAST can email the administrator weekly from 90 days before the licence expires.[7] The Capacity panel is the in-product record of Named Users, auditors, projects and concurrent scans in use.[7] The main exposure for a licence manager is the indirect-use rule. Count people who work from exported findings, not only those with CxSAST logins. See named user licensing and software license audit.

Out of scope

  • CxSAST engine pack and version support schedules.
  • Prices, which Checkmarx does not publish.
  • Older License Types versions for these products that are not on checkmarx.com.

References

  1. Checkmarx SAST License Types and Restrictions (version 2023.02)Page states 'Last Updated: 02.10.2023' (day/month order ambiguous). Catalog: Checkmarx SAST License Types and Restrictions (2023.02)Retrieved 2026-10-07.
  2. Checkmarx SCA License Types and Restrictions (version 2023.02)Catalog: Checkmarx SCA License Types and Restrictions (2023.02)Retrieved 2026-10-07.
  3. CxIAST License Types and Restrictions (version 2020.05)Catalog: Checkmarx IAST License Types and Restrictions (2020.05)Effective 2020-05-14. Retrieved 2026-10-07.
  4. Codebashing License Types and Restrictions (version 2020.05)Catalog: Codebashing License Types and Restrictions (2020.05)Effective 2020-05-14. Retrieved 2026-10-07.
  5. CxSCS License Types and Restrictions (version 2023.02)Catalog: Checkmarx SCS Threat API License Types and Restrictions (2023.02)Effective 2023-02-21. Retrieved 2026-10-07.
  6. Updating the CxSAST LicenseLast modified July 10, 2022. Catalog: Updating the CxSAST LicenseEffective 2022-07-10. Retrieved 2026-10-07.
  7. Application Settings (CxSAST License Details)Last modified July 24, 2022. Catalog: CxSAST Application Settings (License Details)Effective 2022-07-24. Retrieved 2026-10-07.
  8. CxSAST / CxOSA Roles and PermissionsLast modified January 29, 2023. Catalog: CxSAST / CxOSA Roles and PermissionsEffective 2023-01-29. Retrieved 2026-10-07.
  9. Updating the CxOSA LicenseLast modified July 24, 2022. Catalog: Updating the CxOSA LicenseEffective 2022-07-24. Retrieved 2026-10-07.
  10. Checkmarx Terms of ServiceOn Premises installation rights. Catalog: Checkmarx Terms of ServiceRetrieved 2026-10-07.
  11. Software SLACatalog: Checkmarx Software SLA (maintenance and support)Retrieved 2026-10-07.
  12. Checkmarx One Pricing & PackagesStart with SAST package. Catalog: Checkmarx One Pricing & PackagesRetrieved 2026-10-07.

See also

Catalog Rows Cited

13SKUs8Metrics13Rules2Programs

Esc