-

Nearly Half of Development Teams Now “Own” Application Security, Checkmarx Global Survey Finds

Improving DevSecOps maturity remains a priority, yet CISOs report only 39% of business operations run on secured applications

PARAMUS, N.J.--(BUSINESS WIRE)--Checkmarx, the industry leader in cloud-native application security for the enterprise, has published its annual research report, “A CISO’s Guide to Steering AppSec in the Age of DevSecOps.” Based on a survey of 200 chief information security officers (CISOs) from across diverse industries and regions, the global study uncovered key factors driving the trend for closer collaboration between development and security teams. One key finding is that 49% of CISOs say buyers now factor application security (AppSec) into purchasing decisions. In fact, in nearly half of software-based product companies, security oversight has moved outside the CISO’s office entirely.

“As security responsibility migrates toward development teams, so does the funding. That’s why CISOs today need to lead with influence, creating guardrails, not roadblocks.” --Jonathan Rende, Checkmarx CPO

Share

As application complexity and scale grow — driven by AI, microservices and hybrid application architectures — engineering teams are increasingly accountable for ensuring secure, scalable delivery. With faster release cycles and expanding code bases, AppSec decisions and budgets are shifting toward development teams to embed security earlier and more efficiently in the development process.

“We’re witnessing a pivotal change: AppSec is now a competitive differentiator, a budget priority and a boardroom issue,” said Checkmarx Chief Product Officer Jonathan Rende. “As development teams take greater ownership, CISOs must focus on governance, strategy and collaboration to keep security outcomes on track.”

Key Finding: Application Security is Crucial to Purchasing Decisions

CISOs responding from industries including banking and finance, media, insurance, software, manufacturing and the public sector revealed that robust AppSec programs and practices remain a strong differentiator in their customers’ buying decisions. Key data points include:

  • 49% of respondents report that buyers regularly consider application security in purchasing decisions
  • 24% indicated that application security is “always” a factor in those decisions
  • This trend is most pronounced in Europe, where 58% of respondents report that security is “always” a factor, compared to 33% in the Asia Pacific region and only 8% in North America

The Checkmarx study also found that decision-making is becoming increasingly decentralized, with development teams more often influencing security practices and even owning budget authority. The study revealed that:

  • In organizations developing software-based products responsibility is split, 50% of organizations assign security responsibility to CISOs while 43% move security oversight to development teams
  • 56% of organizations say that most of their development teams are fully integrated with AppSec programs

Rende added, “As security responsibility migrates toward development teams, so does the funding. That’s why CISOs today need to lead with influence, creating guardrails, not roadblocks.”

Security’s Role in the Boardroom Remains Inconsistent

The study report highlights a persistent gap in how security is communicated at the executive level. While 62% of CISOs report AppSec metrics to their board, most focus solely on vulnerability counts, with only 25% tying those risks to business outcomes like brand reputation or regulatory exposure. This disconnect underscores the urgency for CISOs to frame security in terms of business risk — a prerequisite for securing sustained buy-in at the executive level.

To download the full report, visit this page.

Methodology

Performed in collaboration with Global Surveyz, researchers surveyed CISOs at organizations with annual revenues exceeding $750 million and development teams of at least 180 developers. Participants represented key sectors including banking and finance, insurance, software, technology, engineering, media, manufacturing, industrials and the public sector, spanning the United States, Canada, Western Europe and the APAC region.

About Checkmarx

Checkmarx helps the world’s largest enterprises get ahead of application risk without slowing down development. More applications, faster pipelines and growing threats are all contributing to skyrocketing risk. Checkmarx helps end the guesswork in identifying the most critical issues to fix. Giving AppSec the tools they need while letting developers work the way they want, from DevOps pipelines to developer experience, Checkmarx helps security and development teams work better together – all on a unified application security platform. That’s why so many enterprises rely on Checkmarx to scan over one trillion lines of code each year, see 2X ROI, and improve developer productivity on security tasks by 50%. Checkmarx. Always Ready to Run.

Follow Checkmarx on LinkedIn, YouTube and X.

Contacts

Media Contact
Katie Brookes
Merritt Group for Checkmarx
brookes@merrittgrp.com

Checkmarx

Details
Headquarters: Paramus, NJ
CEO: Sandeep Johri
Employees: 800
Organization: PRI

Release Summary
Checkmarx has published its annual research report, “A CISO’s Guide to Steering AppSec in the Age of DevSecOps" based on a global survey of 200 CISOs.
Release Versions

Contacts

Media Contact
Katie Brookes
Merritt Group for Checkmarx
brookes@merrittgrp.com

Social Media Profiles
More News From Checkmarx

Checkmarx Acquires Tromzo to Launch New Era of Agentic Application Security

PARAMUS, N.J.--(BUSINESS WIRE)--Checkmarx, the global leader in agentic application security, today announced its acquisition of Tromzo, a pioneer in AI-native autonomous security agents. The deal marks a major leap forward in autonomous AppSec, accelerating the delivery of AI agents that understand real enterprise risk, reason across complex software ecosystems, and remediate continuously with precision. Tromzo’s technology and world-class engineering team will enhance the Checkmarx One platfo...

Checkmarx One Achieves ACN Level 2 Certification, Setting a New Standard for Software Security and Digital Sovereignty in Italy

MILAN--(BUSINESS WIRE)--Checkmarx, the leader in cloud-native, agentic application security for enterprises, has officially achieved Level 2 certification from the Agenzia per la Cybersicurezza Nazionale (ACN), Italy’s National Cybersecurity Agency. This milestone confirms that Checkmarx’s application development and operational practices adhere to the agency’s highest standards for cybersecurity, governance, and risk management. As one of the industry’s first ACN Level 2–certified vendors, Che...

Checkmarx Appoints Kevin Hayes as Director of Federal Sales to Accelerate U.S. Federal Market Growth

PARAMUS, N.J.--(BUSINESS WIRE)--Checkmarx, the leader in agentic AI-powered application security testing, today announced the appointment of Kevin Hayes as Director of Federal Sales, strengthening the company’s commitment to serving the U.S. Federal Government’s cybersecurity needs. Hayes will lead Checkmarx’s federal growth strategy with a focus on the Department of Defense (DoD), Civilian Agencies, and FedRAMP-authorized opportunities. A proven and decorated leader with more than 25 years of...
Back to Newsroom