Checkmarx

42 stats4 reports

All Statistics

Within one year, the share of organizations knowingly shipping vulnerable code decreases from 81% to 75%.

Application SecurityVulnerable Code

96% of developers acknowledge having AI tooling integrated in their IDEs.

Application SecurityDeveloper ToolsAI Tooling

Companies with 81–100% AI-generated production code ship software with known security vulnerabilities at a 47% rate compared with 14% for companies with 1–20% AI-generated production code, making them nearly three times more likely.

Application SecurityAI CodeSoftware Vulnerabilities

Fewer than half of the CISOs, AppSec managers and developers report deploying foundational security tools like dynamic application security testing (DAST) or infrastructure-as-code scanning.

AIDASTInfrastrucutre-as-code scanning

Just 51% of North American organisations report adopting DevSecOps

AIDevSecOps

Only half of organisations surveyed actively use core DevSecOps tools.

AIDevSecOps

In North America, only 8% of respondents report security is “always” a factor in purchasing decisions.

Application security

In the Asia Pacific region, 33% of respondents report security is “always” a factor in purchasing decisions.

Application security

Only 39% of business operations run on secured applications, according to CISOs.

Application security

72% of developers spend more than 17 hours each week on security-related tasks.

CheckmarxDevSecOps Evolution 2025·1y ago
Developers

45% of organisations are measuring code security.

CheckmarxDevSecOps Evolution 2025·1y ago
Coding

99.6% of developers have access to security training.

CheckmarxDevSecOps Evolution 2025·1y ago
DevelopersTraining

18% of developers apply security continuously as they write code.

Application SecurityDeveloper PracticesSecure Coding

95% of CISOs feel pressure to suppress or delay compliance-related security issues when business deadlines are at stake.

Application SecurityGovernanceExecutive RiskCompliance

75% of organizations knowingly deploy vulnerable code at some point.

Application SecurityVulnerable CodeRisk Management

Within one year, the proportion of companies with formal AI governance policies increases from 18% to 22%.

AI GovernanceApplication Security

93% of organizations acknowledge a recent breach tied to their own applications.

Application SecurityData BreachIncident Response

73% of organizations describe their security posture as 'advanced' or 'highly mature'.

Application SecuritySecurity PostureRisk Perception

78% of organizations lack formal AI governance policies.

AI Governance

More than 80% of developers do not apply application security continuously as code is written.

Application SecurityDeveloper PracticesSecure Coding

34% of CISOs, AppSec managers and developers admit that more than 60% of their code is AI-generated.

AIAI coding assistant

98% of organisations experienced a breach stemming from vulnerable code in the past year.

AIVulnerable codeBreach

Within the next 12 to 18 months, nearly a third (32%) of CISOs, AppSec managers and developers expect Application Programming Interface (API) breaches via shadow APIs or business logic attacks.

AIAPIShadow APIsBusiness logic attackBreach

Only 18% of organisations have policies governing AI use.

AIAI policy

81% of organisations knowingly ship vulnerable code.

AIVulnerable code

Up to 60% of code is being generated by organisations using AI coding assistants.

AIAI coding assistant

Half of CISOs, AppSec managers and developers already use AI security code assistants.

AIAI coding assistant

81% of organisations knowingly ship vulnerable code.

AIVulnerable code

20% of organisations still forbid the use of AI coding assistants.

AIAI coding assistant

In nearly half of software-based product companies, security oversight has moved outside the CISO’s office entirely.

Application security

49% of CISOs say that buyers now factor application security (AppSec) into purchasing decisions.

Application security

In Europe, 58% of respondents report that security is “always” a factor in purchasing decisions.

Application security

24% of respondents indicated that application security is “always” a factor in purchasing decisions.

Application security

56% of organisations say that most of their development teams are fully integrated with AppSec programmes.

Application security

In organisations developing software-based products, responsibility is split: 50% of organisations assign security responsibility to CISOs, while 43% move security oversight to development teams.

Application security

62% of CISOs report AppSec metrics to their board.

Application security

90% of developers rank the effectiveness of the training they receive as medium or high.

CheckmarxDevSecOps Evolution 2025·1y ago
DevelopersTraining

One in four developers spends more than 25 hours each week on security-related tasks.

CheckmarxDevSecOps Evolution 2025·1y ago
Developers

21% of developers surveyed say that security is their top priority when coding.

CheckmarxDevSecOps Evolution 2025·1y ago
DevelopersCoding

28.3% of organisations are tracking mean time to remediate as a metric.

CheckmarxDevSecOps Evolution 2025·1y ago
DevelopersRemediation

46.27% of organisations are tracking ability to meet deadlines

CheckmarxDevSecOps Evolution 2025·1y ago
Developers

41.53% of responding developers reported that they understand the vulnerability tickets they receive, as well as how the vulnerability manifests during runtime, from 41-60% of the time.

CheckmarxDevSecOps Evolution 2025·1y ago
DevelopersVulnerability tickets