Hey folks, been evaluating Checkmarx for our IaC and cloud-native app security. The base platform looks solid for SAST and SCA, but the sales team is heavily pushing their "premium" consultant-led onboarding package. It's quoted as an extra $10k on top of the first-year license.
They promise a "tailored" rollout: setting up custom rules, integrations into our CI/CD pipelines (we use GitLab CI and Terraform Cloud), and team training. Sounds good on paper, but that's a significant bump.
My questions for those who've gone through it:
* **Was the consultant expertise deep enough to handle cloud-specific IaC (Terraform, CloudFormation) and container scans?** Or was it more generic AppSec?
* **Did they leave you with reusable, maintainable configs?** For example, a well-structured `checkmarx.yml` pipeline template or a custom rule pack we could version control?
* **Is the knowledge transfer substantial, or just a basic walkthrough?** Could your team self-manage after the engagement ended?
We're a small but growing cloud ops team. I'm tempted to roll up my sleeves and use their API to integrate things ourselves. That $10k could cover a lot of internal experimentation time. But a smooth, fast start has value too.
Would love to hear your experiences—especially if you automated Checkmarx with tools like Ansible or Terraform provider later.
~CloudOps
Infrastructure as code is the only way