Developers Acknowledge App Security but Face Time Challenges, Checkmarx Report Finds

Checkmarx has released its global research report, “DevSecOps Evolution: from DevEx to DevSecOps,” which examines the current state of development, security, and operations (DevSecOps) within large enterprises. The study reveals that while development and security teams are advancing toward mature DevSecOps practices, they are still working to align workflows and metrics effectively.

“The rapid expansion of development teams and DevOps pipelines highlights the importance of fostering a shared culture between DevOps and security teams,” said Martin Lindsay, Vice President of Regional Marketing at Checkmarx. “To deliver high-performing, secure code, improving the developer experience with application security is just the first step. Security must also keep pace with agile development.”

Key Findings: Developers’ Growing Confidence in Security

The report highlights increased confidence among developers regarding security training and a significant time investment in security-related tasks:

  • 21% of developers state that security is their top priority when coding.
  • 99.6% of developers have access to security training.
  • Of those trained, 90% rate the training effectiveness as medium or high.
  • 41.53% of developers understand vulnerability tickets and how vulnerabilities manifest during runtime 41-60% of the time.
  • 72% of developers spend more than 17 hours per week on security-related tasks, with 25% dedicating over 25 hours.

Tracking DevSecOps Maturity

The Checkmarx DevSecOps Maturity Model outlines four key stages of progress:

  • Stage 0 – Reactive Security: Security is applied as an afterthought, creating deployment bottlenecks.
  • Stage 1 – Security-Focused: Security teams detect vulnerabilities but provide developers with little guidance for remediation.
  • Stage 2 – DevEx-Focused: Security tools are integrated into the development environment (IDE), enabling developers to address vulnerabilities seamlessly.
  • Stage 3 – Mature DevSecOps: A strong security culture is in place, with clear policies, collaboration between teams, and embedded training within the IDE.

Progress and Gaps in DevSecOps Adoption

The study indicates that organizations are committed to evolving their DevSecOps practices:

  • 30% have progressed beyond developer experience improvements to implementing sophisticated processes.
  • 28.3% track mean time to remediate vulnerabilities.
  • 45% measure code security as a key metric.
  • 46.27% track their ability to meet development deadlines.

Despite this progress, the study highlights that best practices for DevSecOps operations and measurement are not yet universally adopted. While significant strides have been made, organizations still have work to do to achieve full maturity in security integration.

Research Methodology

The study surveyed 1,500 heads of development, platform engineers, and software engineers from large enterprises with annual revenues exceeding $750 million. Participants were from North America (USA), Europe (UK, France, Germany, Austria, Switzerland), and APAC (Australia, New Zealand, Singapore). The research was conducted by Censuswide in December 2024, adhering to ESOMAR market research principles.