Hi everyone, I've been lurking for a bit and finally have a reason to post. 😅 I'm helping with a project at a smaller community bank, and we're trying to get our web applications (mostly customer portals) properly set up for PCI DSS compliance scanning.
The security team has basically narrowed it down to two options: Checkmarx or Fortify. I know these are the big names, but I feel a bit lost trying to figure out which one is a better fit for our specific situation.
We don't have a huge team of dedicated security developers. Most of us are from the web dev side, just trying to make sure we're secure. I've read a lot of feature lists, but I'm really hoping for some real-world advice.
What I'm curious about is the day-to-day experience. For a bank focused on PCI compliance, which tool:
* Has a less steep learning curve for developers who aren't full-time security experts?
* Generates reports that are actually actionable and clear for auditors?
* Plays nicer with typical web app stacks (like .NET and Java) and CI/CD pipelines?
I've heard Fortify can be very powerful but also complex, and that Checkmarx might be more developer-friendly. Is that true in practice, especially in a regulated environment like ours? Any gotchas we should watch out for with either?
Sorry if these are basic questions! Just trying to wrap my head around it all.