Checkmarx CxONE 3.64: Centralize Scan Policy Without Losing Project Control
Checkmarx CxONE 3.64 gives administrators organization-level control of scanner and integration settings for connected source-control organizations, including explicit project override rules. It also improves enterprise risk governance through AI usage disablement, API Security audit events, state-based policy exemptions, and inclusion of BYOR data in platform summaries and reports. SCA, DAST, MCP, SBOM, and AI Supply Chain updates broaden coverage and improve evidence for delivery, compliance, and audit teams.
Organization-level configuration for Code Repository Integrations lets release owners apply scanner and integration defaults across an entire connected SCM organization, reducing setup variance before code reaches delivery pipelines.
For enterprises operating hundreds or thousands of repositories, this is a meaningful control-plane change. CxONE 3.64 moves more policy decisions from repeated project administration into accountable, centrally managed configuration.
Central policy with deliberate local exceptions
A new Organizations tab in Account Settings shows each connected SCM organization and its current configuration. From Organization Settings, account administrators can enable or disable individual scanners and features for all associated Code Repository Integration projects.
Each setting can be configured with an Allow Override decision:
Lock the setting when a common enterprise policy must apply everywhere.
Permit project-level edits when teams have a valid technical or regulatory need.
Show locked controls as unavailable in Project Settings, with an explanation that account-level policy governs them.
This model matters because consistency is not the same as removing all team autonomy. Release governance works best when the default is centrally enforced and exceptions are explicit, reviewable, and limited to the settings that genuinely require local ownership.
CxONE also adds allowedLevel and unableToBlockOverride attributes to settings metadata. These controls restrict where a setting can be managed and enforce override behavior when an override cannot be blocked. The result is a more predictable hierarchy across tenant, organization, and project contexts. It helps prevent accidental policy drift in complex operating models.
August 31, 2026By Chris CarpenterAppSecDevSecOpsSASTDAST
More complete risk reporting and evidence
CxONE 3.64 includes Bring Your Own Results (BYOR) data in platform risk summaries, application views, analytics, and reports. Imported results now contribute to totals by vulnerability count, scanner type, state, and related summary fields.
This closes a reporting gap for organizations that combine Checkmarx findings with results imported from other security tools or assessment processes. Security leaders can base portfolio decisions on a fuller picture of application risk, while audit and compliance teams avoid manually reconciling separate data sets.
Additional reporting improvements include:
CSV export for the Fixed Vulnerabilities drill-down table in Analytics.
Comment support when triaging imported BYOR findings.
Custom triage state output for API Security findings through /api/results.
A unified reporting pipeline for AI-BOM exports from Global Inventory.
The operating question is now less about whether data exists and more about whether it has a defined owner, consistent state model, and evidence trail. Those basics still matter.
Governance controls for AI, policy, and API Security
A new global AI Usage toggle can disable all AI-driven functionality across Checkmarx One. The control applies to user-facing and backend AI features, and also governs future AI capabilities. A confirmation prompt is required before the setting takes effect.
For organizations with changing legal, data-handling, or model-risk requirements, this creates a single enforcement point rather than a per-feature administrative exercise. Security and platform leaders should define who may change this control, how the decision is approved, and how its status is evidenced during audits.
CxONE 3.64 also adds API Security triage events to the Audit Trail. Recorded details include:
The user who changed a result.
The timestamp of the action.
Previous and new state or severity values.
Whether the action was individual or bulk.
Whether Similarity or Attack Vector ID logic triggered the action.
These events are available through the Audit Trail API, supporting evidence collection and investigation workflows.
Policy Management now supports state-based exemption rules. Findings in approved exempt states are excluded from build-break evaluation but remain visible and tracked. All other findings continue through normal enforcement in pull requests, builds, and CI/CD pipelines.
This is preferable to disabling a policy or changing a vulnerability classification simply to permit a release. Teams can honor approved exception states while preserving the integrity of the enforcement model.
More reliable triage and scan outcomes
Scan consistency improvements prevent vulnerabilities from being incorrectly marked fixed merely because scan configuration changed, testing did not occur, or a finding is newly introduced. This gives developers and release managers more dependable feedback between runs.
SCA adds an important correction to exploitability-driven triage. If a risk marked Not Exploitable later receives a newly detected Exploitable Path, CxONE automatically changes its state to To Verify. The risk history records why the state changed.
That behavior reduces the chance that a previously accepted finding remains outside review after the technical evidence changes. Teams should confirm that their routing, merge-blocking, and remediation processes respond appropriately to the To Verify state.
Risk Orchestration now supports saved column management across SAST, SCA, IaC, DAST, Containers, and Secrets. Users can show, hide, reorder, sort, and filter columns while retaining engine-specific context. This is a workflow improvement, but it should not replace standard team views for operational reporting.
SCA coverage and SBOM evidence improve
The release expands dependency analysis across several ecosystems:
pnpm-lock.yaml is now used as the authoritative dependency source for PNPM projects.
Archive unpacking adds tgz, rpm, and whl support in cloud scans and the SCA Resolver CLI.
C/C++ package detection now includes vcpkg alongside existing Conan fingerprint analysis.
SCA Global Inventory has faster initial result loading.
These additions reduce blind spots for teams using PNPM, Linux and Red Hat packaging, Python wheels, and vcpkg-managed C/C++ dependencies. No project configuration change is required for the newly supported archive types.
CycloneDX SBOM exports are upgraded to version 1.7. Components now include provenance and detection evidence, including the project file path and whether identification came from manifest analysis, hash comparison, or both. This evidence is available in SBOMs generated through the UI, API, and CI integration.
For software supply chain governance, the provenance detail is especially useful. It helps teams explain not only which component was found, but where it was detected and how that determination was made.
MCP, AI Supply Chain, and DAST workflow updates
The Checkmarx One MCP Server now supports Container Security scanning alongside SAST, SCA, IaC, and Secrets. It also supports manual SAST and SCA risk triage, allowing authorized users to change risk state, add comments, and review triage history from an AI assistant workflow. Access remains subject to applicable licensing and role-based permissions.
AI Supply Chain updates add AI asset counters to the Scan Summary API and CLI output. Global Inventory now displays code snippets and file paths for detected AI assets, including each evidence location where an asset appears.
DAST adds several practical delivery capabilities:
Choose Chrome or Firefox for DAST CLI browser-based scans.
Use the Client Spider crawler for stronger single-page application coverage.
Review recording errors and their effect on guided scan coverage.
Add attributes to uploaded API scan files, including Postman variables, OpenAPI target URLs, and GraphQL endpoints.
Customize and pin columns in the Environments table.
Together, these updates improve applicability for modern web applications and APIs, especially where client-side routing, relative paths, or environment-specific endpoints affect scan completeness.
Actions for release and security leaders
Before broad rollout, teams should review the release against their operating model:
Identify organization-level scanner settings that should be locked across repositories.
Define the approval and review process for project-level overrides.
Reconcile BYOR findings with existing application and executive reporting metrics.
Update policy exception procedures to use state-based exemptions where appropriate.
Test SCA coverage for PNPM, vcpkg, and packaged dependency formats used in your portfolio.
Confirm AI Usage toggle ownership, change control, and audit evidence expectations.
Validate MCP role permissions before enabling scan or triage actions through AI assistant workflows.
How Merito helps
Merito helps enterprises implement CxONE 3.64 as a governed delivery capability rather than a collection of enabled features. We can assess repository and project configuration, define policy inheritance and exception rules, align BYOR reporting with executive risk metrics, and validate audit evidence for AI usage, triage, and enforcement decisions.
For teams adopting the expanded SCA, DAST, and MCP capabilities, Merito can also establish rollout criteria, CI/CD controls, role models, and measurable operating procedures.
Merito is a Checkmarx partner. Our Checkmarx CxONE team can scope licensing, sizing, and rollout for 3.64, and our enterprise upgrade services help you plan and validate the upgrade with minimal disruption to release schedules.
Account administrators can define scanner and integration defaults for every Code Repository Integration project in a connected SCM organization. They can allow a project-level override where local requirements justify it, or lock the setting to prevent deviation. Merito can help define which controls belong centrally and which need an approved exception path.
Yes. A global AI Usage toggle can disable all current and future AI-driven capabilities across the platform, while API Security triage changes are now recorded in the Audit Trail with actor, timestamp, before-and-after values, and bulk-action context. Merito can map these controls and records to internal AI governance and evidence-retention requirements.
BYOR findings now contribute to platform risk summaries, application views, analytics, and generated reports. Teams get more accurate totals across imported and native findings rather than managing separate reporting baselines. Merito can help normalize reporting ownership, triage rules, and executive metrics across these sources.
For SCA risks, a finding marked Not Exploitable automatically returns to To Verify when a later scan identifies a new Exploitable Path. The reason is recorded in risk history, helping teams reassess merge controls and remediation priority using current evidence.
Keep Reading
Related Product Release Updates
Explore a few more Merito release updates that align with the themes in this article.