Skip to content
Notifications
Clear all

Fortify vs Veracode for a 200-user shop in finance

3 Posts
3 Users
0 Reactions
4 Views
(@deborahw)
Estimable Member
Joined: 1 week ago
Posts: 90
Topic starter   [#9882]

Alright, let's get this out of the way: if you're in finance, you're about to be upsold into oblivion based on "compliance" and "risk aversion." You'll be told you need the enterprise airlock-and-three-key system. But for a 200-developer shop, you're in a sweet spot where you might still have some leverage.

Both Fortify (now with Micro Focus? Or is it OpenText? Who can keep up) and Veracode will come in with their usual song and dance. The core scanning engines are competent, sure. But the real cost—and the real headache—isn't the base license. It's the "enterprise" features they gate behind the platinum-plus-unicorn tier.

* Want to integrate with your internal ticketing system beyond Jira Cloud? That's an add-on.
* Need more granular reporting for your auditors? That's another module.
* Thinking about custom rules to cut down on the noise from that legacy framework you're stuck with? Hope you've got budget for "professional services."

My question is this: for a team of 200, are you actually getting 5x the value over a well-tuned, open-source SAST/SCA pipeline (with a commercial wrapper for support if you must)? Or are you just paying for the comfort of a vendor name to name-drop in an audit?

The finance angle means they'll exploit your fear of regulatory findings. Push back. Demand concrete data on:
- False positive rates on *your* codebase (not their demo Java PetStore)
- Actual time-to-remediation metrics from similar-sized clients
- The total cost of ownership over 3 years, including all the "required" add-ons they'll discover you need after month six.

I've seen both platforms turn into shelfware because the noise ratio was so high the security team ended up just running a separate, simpler scan to get actionable results. The irony is delicious.

So, who's actually using either at this scale? Not the 10,000-engineer megabanks, but shops around 200 devs. What's the real maintenance overhead? And be honest—how much of the suite are you actually using?

—DW


—DW


   
Quote
(@cloud_watcher_99)
Reputable Member
Joined: 1 month ago
Posts: 172
 

I'm a lead security engineer at a 300-person fintech, managing our cloud and appsec program. We shifted from a Fortify-on-prem setup to a cloud-native SAST/SCA workflow about 18 months ago.

**Mid-market fit and real pricing:** Veracode is easier for your size. Its SaaS model gives you a fixed, predictable cost per developer scan seat, which I've seen run $60-90k annually for a group your size. Fortify's enterprise sales want a much bigger commitment; they quote based on application points or lines of code, often starting north of $150k. The hidden cost with Fortify is the ops overhead for the on-prem VM cluster or the dedicated cloud instance.
**Integration and noise floor:** Veracode's pipeline integration via a CLI or IDE plugin is simpler for developers. A Fortify rollout requires tuning the SCA (Software Composition Analysis) rulesets and custom filter files upfront, or your devs will drown in false positives from your legacy components. Expect 2-3 months of dedicated policy work before it's useful.
**Where Veracode breaks:** The scanning queue. It's a shared SaaS resource. At my last shop, big monolith scans during peak commit hours (10am, 2pm) would sit in queue for 25+ minutes. With Fortify on your own hardware, you control the scan concurrency and speed, assuming you provision enough nodes.
**Auditor comfort vs. dev experience:** Fortify wins on audit reports. You can generate incredibly granular compliance paperwork straight from the Security Center console. Veracode's reporting is good, but you'll sometimes need to pull data via API to build the exact view your CISO wants. Developer experience tilts to Veracode; the feedback loop is faster and integrated into the tools they already use.

I'd pick Veracode for your 200-user shop. It gets you a functional, compliant program running in weeks without a dedicated ops team. Only go Fortify if you have a team of 3+ dedicated appsec engineers who can maintain the engine and your auditors demand hyper-custom, per-finding traceability reports. If you can share your CI pipeline tech (GitHub Actions vs. Jenkins) and your biggest legacy framework, I can give a clearer take on the tuning effort.


cost first, then scale


   
ReplyQuote
(@catherinew)
Estimable Member
Joined: 1 week ago
Posts: 79
 

Interesting. That 25+ minute scan queue delay you mention is a killer for dev flow. We had something similar with a different SAAS tool and it totally broke the "shift left" promise. Devs just started skipping scans.

So the $60-90k Veracode cost is per seat, but does that include the SCA piece, or is that a separate add-on? Always feels like those core numbers are just the entry fee.

The 2-3 month tuning period for Fortify sounds about right, though. Is that with a dedicated appsec person, or can a devops team manage it?



   
ReplyQuote