DAST - Checkmarx

Please See our April 26, 2026 Security Update

Read more
SAST Hero Icon
Checkmarx DAST Scanner

Dynamic Application
Security Testing

For teams that ship both fast and secure, Checkmarx DAST scanner makes dynamic security testing as agile as AI-driven development.

DAST engine cover image

DAST for the AI-Driven Era

As AI and agentic AppSec reshape development, DAST ensures your live apps are tested
as rigorously as the code that built them.

Onboarding apps take days P

Onboarding apps take days, leading
to missed coverage

Get started in minutes with built-in tunnelling for internal apps, ready-to-use scan templates, and zero complex network setup.

Onboarding apps take days S
DAST only runs at release P

DAST only runs at release, not throughout development

Plug DAST into your CI/CD pipeline to run security tests on every commit and catch vulnerabilities before they hit production.

DAST only runs at release S
Complex auth flows P

Complex auth flows leave apps without full test coverage

Support any auth flow with browser-recorded logins, 2FA, and instant verification to achieve full coverage and detailed reporting.

Complex auth flows S

What Is AI-Driven DAST?

Discover how teams ship secure AI-driven apps faster than ever.

solar_hourglass-bold-duotone 3 min.
solar_hourglass-bold-duotone 3 min.

DAST Scanner Built for How Modern Development Teams Work

From scanning to remediation, Checkmarx DAST tool gives enterprise teams the accuracy, coverage, and AI-powered intelligence to secure code without slowing down how they build it.

Seamless Integration Within the SDLC_3x
Fast and Simple Onboarding_3x
Authentication Made Simple_3x
Enhance Compliance_3x
Complete API Security_3x
Zoom Items Purple 3D

Seamless Integration
Within the SDLC

Connect DAST to your existing CI/CD tooling in minutes. Tests run automatically on every build across dev and pre-production environments, with results surfaced directly in your pipeline so nothing reaches production untested.

Packages Purple 3D

Fast and Simple Onboarding

Scan internal apps without firewall exceptions or network reconfigurations. Built-in tunnelling connects to your environment securely, and pre-built scan templates mean any team member can get a new environment up and running in minutes.

Puzzle Purple 3D icon

Authentication Made Simple

Record login flows directly in the browser to handle complex authentication sequences. Built-in 2FA support and instant verification ensure full coverage across your real application surfaces, with granular reporting on every scan result.

List Purple 3D

Enhanced Compliance

Map every finding directly to the compliance framework it affects. Get a clear view of which applications are introducing regulatory risk, so your team can prioritize remediation around what matters most for audit readiness.

Shield Purple 3D

Complete API Security

Test REST, SOAP, and gRPC endpoints in live environments to surface vulnerabilities that static testing misses. All SAST and DAST API findings are centralized in a single inventory, giving your team one place to manage and prioritize API risk.

Why the World’s Top Teams Choose Checkmarx

“We’ve seen an 80% noise reduction—our engineers now focus on the high-quality risks that matter.”

“By far the best AppSec tooling decision we have made”

“Checkmarx gave us a 90% reduction in vulnerabilities in just a few months.”

“Unifying our AppSec tools with Checkmarx gave us a single source of truth.”

“With 2.1B lines of code scanned monthly, Checkmarx gives us the scale and speed we need.”

“Checkmarx fits seamlessly into our DevOps pipelines—it’s a truly scalable solution.”

“From a buyer perspective, Checkmarx’s approach offers a structured and role-aware entry point into agentic security. ”

“Incorporating Checkmarx’s technology has revolutionized our development culture ”

“Checkmarx One made our security team and developers life easier.”

“The success of our AppSec program can be directly attributed to the tooling, processes and support provided by the Checkmarx managed services.”

“Bringing ASPM context directly into the IDE reflects a forward-looking approach to prioritizing security efforts based on risk earlier in the development process.”

Request a Demo

Agentic AppSec Platform That Protects from Code to Runtime

See how Checkmarx One DAST helps secure your live applications and APIs.

Request a Demo

FAQ

What other solutions does Checkmarx have in addition to DAST?

  • Checkmarx DAST is part of the Checkmarx One application security platform. This allows a complete AppSec program to be run on a single platform, reducing total cost of ownership and allowing for correlation and better actionable insights.The Checkmarx One platform includes:
    • Code
      • SAST
      • API Security
      • IaC Security
      • Secrets Detection
    • Software Supply Chain
      • SCA
      • Malicious Package Protection
      • Container Security
      • Repository Health
    • Runtime

    DAST

Why should I have a DAST tool on a unified platform?

By maintaining a unified cloud-native AppSec platform such as Checkmarx One, organizations can consolidate their AppSec tooling. This lowers TCO, and reduces learning curves among the team and allows for a unified view of your entire application security posture. It’s easier to analyze and prioritize vulnerabilities across multiple solutions, such as SAST, DAST, and API Security

What is the cost? How can I learn more about pricing?

Every organization has unique needs and sizes. For a price quote, please get in touch. See our packaging here.

DAST is available as an add-on within Checkmarx One Professional or higher. It is not sold as a standalone product. If you are a current Checkmarx customer, please reach out to your account manager or contact us here.

Where can I explore DAST documentation?

You can explore all Checkmarx’s documentation here

Want to See DAST in Action?

Find out how Checkmarx DAST helps organizations find vulnerabilities in live applications.

Tag Icon Personalized Demo

See For Yourself

Scan internal apps easily with tunneling – no complex network setup or security exceptions needed.

Democratize DAST onboarding with scan configuration environments so any team member can get an environment up & running.

Integrate DAST into your CI/CD pipeline for continuous testing in development and pre-production.

Scan real world apps behind multi-factor authentication – no matter how complex your login process is.