Checkmarx SCA September 2026: Govern OWASP and LLM Security Training Evidence
Checkmarx SCA September 2026 introduces Codebashing courses for OWASP Top 10:2025 and OWASP LLM vulnerabilities. It also adds APIs to list earned certificates with role-based access and download selected certificate records by ID. The release supports governed security-training evidence for audits, release readiness, and AI application risk programs.
The September 2026 release adds Codebashing courses for OWASP Top 10:2025 and OWASP LLM vulnerabilities, giving release owners current learning content they can use to set security-readiness expectations. It also introduces certificate APIs that make completion evidence easier to retrieve while retaining role-based access controls.
What changed
This release contains two related areas of capability:
A course covering the OWASP Top 10:2025, including attack scenarios and remediation exercises.
A course focused on vulnerabilities in LLM-powered applications, based on the OWASP Top 10 for LLM Applications.
A GET certificate endpoint that lists earned certificates available to the requesting user's role.
A POST certificate endpoint that attempts to download selected certificates by ID and reports certificates that cannot be found or accessed.
The release notes describe learning and certificate-management updates in Checkmarx Codebashing. They do not announce changes to SCA dependency scanning, vulnerability data, license analysis, or policy enforcement.
Current OWASP training supports more defensible release decisions
The OWASP Top 10 remains a practical common language between engineering, security, risk, and audit teams. Updating learning material to the 2025 edition helps organizations keep internal development expectations aligned with the current framework.
For a release owner, the value is not simply course availability. The value is being able to show that teams responsible for application changes have been assigned relevant security learning and that completion can be evidenced when required.
Use the course as part of a defined control, for example:
Require it for developers working on internet-facing applications.
Include completion in onboarding for application architects and QA leads.
Set refresh expectations for teams supporting high-risk services.
Link training status to release-readiness reviews where policy requires it.
Training should not replace code review, testing, or SCA policy checks. It can reduce preventable security defects by improving how teams recognize common risk patterns before deployment.
LLM security becomes a governed engineering concern
Applications that call, embed, or orchestrate large language models introduce risks that conventional application-security training may not sufficiently cover. The new LLM-focused course addresses security issues specific to AI-powered applications and provides real-world defensive context.
This matters to leaders funding AI delivery programs. Security accountability needs to extend beyond the model provider and include the application teams that manage prompts, data flows, tool access, user interactions, and operational behavior.
A practical governance approach is to identify teams that:
Build customer-facing LLM features.
Connect models to internal data or business systems.
Operate retrieval-augmented generation workloads.
Approve AI architecture or production releases.
Those groups can be assigned the LLM curriculum based on their role and system exposure. The relevant evidence are then available for architecture reviews, internal controls testing, and customer assurance discussions.
Certificate APIs improve evidence collection without broad access
Manual collection of training certificates is slow and often produces incomplete evidence. The new APIs provide a more controlled approach to retrieving records.
The GET endpoint returns earned certificates subject to role-based filtering. This limits visibility to certificates the requesting user is permitted to see, which is important when training records are part of personnel or compliance data.
The POST endpoint accepts a set of certificate IDs for download. Its response distinguishes fulfilled requests from certificates that were not found or were not accessible to the requester. That response behavior matters operationally: an evidence workflow can identify gaps instead of treating every request as successful.
Teams should establish clear controls before automating certificate retrieval:
Use service identities and least-privilege access where supported by the surrounding platform.
Limit downloads to approved audit, compliance, or learning-administration purposes.
Record who requested evidence, for which control, and when.
Define retention and disposal requirements for downloaded certificates.
Test handling for inaccessible or missing certificate IDs.
Workflow impact for DevSecOps and audit teams
Security training is most useful when it is managed as part of the software delivery system rather than an isolated annual task. This update allows organizations to connect learning requirements with existing delivery governance, without claiming that training completion alone proves an application is secure.
DevSecOps leaders can use certificate data to support periodic control reporting. QA and engineering managers can identify whether required learning is complete before teams take on sensitive application areas. Audit teams gain a more repeatable method for requesting and checking evidence.
The strongest operating model keeps accountability explicit:
Security defines learning standards and high-risk populations.
Engineering leadership owns assignment and timely completion.
Platform or learning administrators manage access and certificate retrieval.
Release owners confirm that required control evidence is available when a release is subject to review.
Internal audit validates that evidence collection and access practices match policy.
Implementation considerations
Start with a limited rollout focused on one regulated product line, AI program, or high-risk engineering group. Validate course assignment rules, certificate-access roles, and evidence retention before extending the approach across the portfolio.
Avoid creating a release gate that teams cannot satisfy due to unclear ownership or inaccessible records. The API's unavailable and unauthorized responses should be treated as workflow states with defined escalation paths, not as administrative exceptions left for individual teams to resolve.
How Merito helps
Merito helps enterprises translate release capabilities into usable delivery controls. We can map OWASP and LLM learning requirements to engineering roles, define certificate-evidence workflows, review access and retention controls, and align the process with existing SCA, CI/CD, QA, and audit practices.
The aim is practical governance: clear ownership, evidence that can be retrieved when needed, and security learning tied to the applications and risks teams actually manage.
Merito is an authorized Checkmarx reseller and services partner. Our Checkmarx SCA team can scope licensing, sizing, and rollout for September 2026, and our enterprise upgrade services help you plan and validate the upgrade with minimal disruption to release schedules.
About Checkmarx products
Checkmarx licenses, renewals, upgrades and implementation are available through Merito, an authorized Checkmarx reseller and services partner.
The published notes describe Codebashing learning content and certificate APIs, not changes to SCA scanning engines, dependency intelligence, or policy evaluation. Organizations should treat this as a security enablement and evidence-management update. Merito can help separate training-control requirements from software composition analysis controls in the operating model.
The GET endpoint returns earned certificates, applying role-based filtering so users only see records their role permits. The POST endpoint attempts to download selected certificates by ID and identifies records that were unavailable or inaccessible. This gives teams a defined path for collecting completion evidence without broad record exposure.
The courses can support role-based learning plans for developers, architects, QA engineers, and teams building LLM-powered applications. They cover risk recognition, attack scenarios, and remediation exercises. Merito can help map course completion to engineering roles, release gates, and security awareness obligations.
Define which roles may view or download certificates, what business purpose justifies access, and how exported records are retained. Teams should also test unavailable and unauthorized certificate responses in their evidence-collection workflow. Merito can help define ownership, access reviews, audit evidence standards, and reporting procedures.
Checkmarx One 3.62 expands audit coverage for SAST triage and reporting while introducing unified Risk Orchestration and generally available AI Triage & Remediation. The release also extends AI supply-chain scanning, improves SCA policy precision, and gives administrators better visibility into AI credit use and identity data.
Checkmarx One 3.60 adds AI Supply Chain Security, native MCP Server workflows, more precise policy controls, and stronger evidence for audit reporting. The release also improves dependency, container, DAST, accessibility, and operational reporting workflows.