CHECKMARX ONE 3.50 IS ABOUT CONTROL, NOT JUST MORE FINDINGS
Checkmarx One 3.50 is not a volume driven release. It is designed to help large enterprises control how security data flows through their delivery, governance, and reporting systems.
Across SAST, SCA, DAST, IaC, container security, and analytics, the focus is consistent: improve accuracy, reduce operational friction, and align security workflows with how enterprises actually manage risk.
For security and quality leaders running regulated, multi team DevSecOps programs, this release strengthens posture without slowing delivery.
SECURE AND STANDARDIZED CONNECTIVITY WITH ZROK V1
CxLink has been upgraded to Zrok v1, updating the underlying connectivity and security stack.
Enterprise impact:
- Reduced exposure for hybrid and internal applications scanned from cloud hosted platforms
- Easier justification during vendor risk, zero trust, and architecture reviews
- Alignment with supported and current connectivity standards
Team impact:
- Fewer scan failures caused by unstable tunnels
- Faster onboarding for new teams without repeated security exceptions
This reduces operational risk in environments where connectivity itself is scrutinized.
USER CONTROLLED INCREMENTAL SAST SCANS FOR BRANCHES
Incremental branch scanning is now fully configurable in the UI.
Enterprise impact:
- Faster pipelines for large codebases without removing SAST gates
- Clear policy alignment by branch type, such as full scans for releases and incremental scans for features
Team impact:
- Faster feedback in pull requests
- Less pressure to bypass security due to performance concerns
This enables security at speed instead of security as a bottleneck.
FLEXIBLE GROUPING OF RESULTS FOR REAL OWNERSHIP MODELS
Results metadata grouping is now directly available in the UI.
Enterprise impact:
- Executive and board reporting that reflects business ownership
- Accurate SLA tracking aligned to real team responsibilities
Team impact:
- Cleaner triage views by product, service, or repository
- Less noise from unrelated applications
Grouping now matches how work is actually assigned.
STRONGER DAST COVERAGE FOR AUTHENTICATED APIS
Manual bearer token entry is now supported for API DAST scans.
Enterprise impact:
- Coverage of protected APIs critical to payments, identity, and internal services
- Stronger audit evidence that authenticated paths are tested
Team impact:
- Faster resolution of failed scans
- Environment specific testing without rewriting specifications
This closes a long standing gap in enterprise API testing.
STANDARDIZED DAST CONFIGURATIONS AT SCALE
Predefined DAST scan configurations are now available through the UI.
Enterprise impact:
- Consistent security policies across teams and applications
- Lower risk of misconfigured scans
Team impact:
- Faster onboarding
- Repeatable CI pipelines with predictable behavior
DAST becomes scalable instead of bespoke.
RICHER AND PERSISTENT SAST RESULTS VIEWS
All SAST fields are now visible in the UI with persistent column management.
Enterprise impact:
- Stronger governance and traceability during audits
- Better collaboration across security, QA, and development
Team impact:
- Personalized views that persist across sessions
- Reduced dependency on CSV exports
This improves efficiency without changing processes.
CUSTOM STATES FOR CONTAINER SECURITY
Container findings now support custom states.
Enterprise impact:
- Alignment with formal risk acceptance and mitigation frameworks
- Clear lifecycle tracking for container vulnerabilities
Team impact:
- Less ambiguity in backlogs
- Dashboards focused on actionable risk
This brings container security into enterprise governance models.
LARGER ARTIFACT SUPPORT AND BETTER DATA EXPORTS
The UI upload limit increases to 6 GB, and CSV exports are available for SCA, IaC, and containers.
Enterprise impact:
- Coverage for large legacy and packaged systems
- Integration with BI, GRC, and data platforms
Team impact:
- Fewer ingestion workarounds
- Easier collaboration with non technical stakeholders
Security data becomes easier to operationalize.
SOFTWARE SUPPLY CHAIN AND CLOUD POSTURE IMPROVEMENTS
Key enhancements include packages.lock.json support, SCA global inventory bulk triage, private registry APIs, and improved IaC accuracy.
Enterprise impact:
- More accurate dependency and license governance
- Scalable onboarding of registries and cloud checks
- Cleaner compliance evidence
Team impact:
- Faster response to supply chain advisories
- Less noise from false positives
- More actionable cloud feedback
These changes strengthen preventive controls across the SDLC.
WHY THIS RELEASE MATTERS FOR ENTERPRISE LEADERS
Checkmarx One 3.50 improves outcomes in three ways:
- More reliable risk data for leadership decisions
- Clear alignment between findings and governance processes
- Lower operational cost of security through better workflows
Security becomes easier to manage, not harder to justify.
HOW MERITO HELPS ENTERPRISES MAXIMIZE CHECKMARX ONE 3.50
Merito helps organizations translate platform features into measurable results.
We support enterprises by:
- Mapping custom states, analytics filters, and exports into GRC and reporting frameworks
- Designing CI and release pipelines that use incremental scans and standardized DAST profiles
- Enabling change management so teams adopt, not bypass, new workflows
This ensures Checkmarx One delivers enterprise scale value.