Skip to content
Notifications
Clear all

What does Veracode actually cost after the sign up?

3 Posts
3 Users
0 Reactions
1 Views
(@devops_not_grunt)
Honorable Member
Joined: 7 months ago
Posts: 506
Topic starter   [#28512]

The advertised "contact sales" pricing is the first red flag. You're not buying a toaster. The initial quote they give you is for the bare bones, air-gapped, "we only scan on Tuesdays" package. Then reality hits.

The real cost comes from the integrations they don't tell you about until your security team tries to enforce the policy. Want that fancy IDE plugin for your developers? That's another module. Want to actually block a build in your CI/CD pipeline instead of just generating a PDF nobody reads? That's a separate SKU, and it's priced per pipeline agent, not per scan. Suddenly your "per scan" cost has a multiplier attached to your entire deployment infrastructure.

And then there's the resource tax. Their SCA (software composition analysis) agent, by default, tries to download the entire universe on every run. I've seen build times balloon by 15 minutes because their scanner decides it needs a fresh copy of every library from the Stone Age. You end up paying for that in engineering time and cloud compute, which never shows up on Veracode's invoice. You'll spend a week tuning the `.veracode` config to stop it from analyzing `node_modules/leftpad` for the thousandth time.

```xml

```

The support tier you need to get anything fixed is the one above "Standard," which they casually mention after your first critical false positive sits in a queue for a week. The true total cost is the license fee, plus the FTE you'll need to dedicate to managing the platform, arguing with their support over misclassified vulnerabilities, and cleaning up the resource exhaustion incidents in your build farm. It's platform-as-a-service with a side of platform-engineering-for-you.



   
Quote
(@emilyt)
Reputable Member
Joined: 3 months ago
Posts: 354
 

Oh, the build time tax is so real. We saw something similar. That "resource tax" you mentioned didn't just hit our CI, it also showed up in developer friction when we tried to add the IDE scan.

The quote we got was just for the core scanning, but getting those findings *into* the developer's workflow felt like buying the car and then paying extra for the steering wheel. It's that hidden cost of adoption - if the tool slows people down, they just won't use it, and then the whole investment is wasted.


Always testing.


   
ReplyQuote
(@code_reviewer_anna_v2)
Honorable Member
Joined: 6 months ago
Posts: 422
 

Totally. The config tuning overhead is a massive hidden cost they never quote. You'll spend more engineering hours fighting their defaults than you will on the actual security reviews.

We ended up writing custom wrapper scripts just to manage their agent's behavior, which became its own maintenance burden. Something like:

```python
# This wasn't in the sales deck either.
def throttle_veracode_scan():
if is_first_monday_of_month():
run_full_scan() # Makes the compliance report look good
else:
run_diff_scan() # Actually useful for devs
```

And the per-pipeline-agent pricing for blocking builds is brutal if you have a microservices architecture. That's when the "per scan" model really falls apart.


Clean code, happy life


   
ReplyQuote