Skip to main content

Free 30-min security demo Book Now

Offensive360 Offensive360
Tools & Comparisons

Fortify on Demand Pricing 2026: Real Cost, What's Included & Alternatives

Fortify on Demand pricing: $15K–$150K+/yr by app count. Full FoD breakdown — SAST vs DAST vs combined cost, what's excluded, hidden fees & cheaper alternatives.

Offensive360 Security Research Team — min read
Fortify on Demand pricing Fortify on Demand cost FoD pricing Fortify SaaS pricing OpenText Fortify SAST pricing application security tools cost Fortify pricing 2026 Fortify on Demand DAST pricing enterprise SAST cost fortify license cost fortify on demand

Fortify on Demand (FoD) is the cloud-hosted, SaaS delivery model for OpenText’s Fortify application security testing platform. Unlike Fortify Static Code Analyzer (SCA), which runs on your own infrastructure, Fortify on Demand sends your code or application to OpenText’s cloud for scanning — with results delivered through the FoD web portal.

For teams that want enterprise-grade SAST and DAST without managing on-premise scan engines and a Software Security Center (SSC) server, Fortify on Demand is the primary Fortify entry point. But pricing is opaque, what’s included varies significantly by tier, and the true total cost is frequently misunderstood at the point of purchase.

This guide breaks down Fortify on Demand pricing in 2026, what each tier includes, what it does not include, and how FoD compares to alternatives.


How Fortify on Demand Pricing Works

Fortify on Demand uses a per-application or per-scan pricing model. Unlike on-premise Fortify SCA (which is licensed per lines of code or application count with your own infrastructure), FoD pricing is structured around the number of applications you submit for scanning and the type of testing requested.

Pricing is not publicly listed by OpenText — all FoD contracts are delivered through direct sales engagement. The variables that drive FoD pricing are:

  • Number of applications — the primary driver; each application submitted for scanning is a separate unit of consumption
  • Scan type — Static Assessment (SAST), Dynamic Assessment (DAST), or both
  • Scan frequency — on-demand scans vs. continuous scanning subscriptions
  • Remediation consultancy — whether the contract includes OpenText remediation guidance services
  • Contract length — annual vs. multi-year commitments
  • Organization size — enterprise contracts get different rate structures than mid-market buyers

Fortify on Demand Pricing: Realistic Cost Ranges

Based on publicly available procurement records, G2 customer reviews, Gartner Peer Insights, and enterprise buyer conversations, here are realistic 2026 price ranges for Fortify on Demand:

SAST (Static Assessment) Only

Application CountEstimated Annual Cost
1–3 applications$15,000–$30,000/year
3–10 applications$30,000–$75,000/year
10–25 applications$75,000–$150,000/year
25+ applications$150,000–$400,000+/year

DAST (Dynamic Assessment) Only

Fortify on Demand DAST is also available as a standalone subscription — not bundled with SAST:

Application CountEstimated Annual Cost
1–3 applications$10,000–$25,000/year
3–10 applications$25,000–$60,000/year
10–25 applications$60,000–$120,000/year

SAST + DAST Combined

When purchasing both static and dynamic assessments through FoD, organizations typically see a 15–25% bundle discount versus purchasing separately:

Application CountEstimated Annual Cost
1–5 applications$20,000–$50,000/year
5–15 applications$50,000–$120,000/year
15–30 applications$120,000–$250,000+/year

What Fortify on Demand Includes

SAST Assessment

Each Fortify on Demand SAST assessment includes:

  • Code upload and scanning — source code is uploaded to OpenText’s cloud infrastructure (US or EU region, depending on contract)
  • Automated scan — the Fortify SCA engine analyzes the uploaded code
  • Results portal — findings delivered through the FoD web portal with severity ratings, CWE mappings, and code-level findings
  • OWASP Top 10 and CWE mapping — results categorized by standard security taxonomies
  • Remediation guidance — each finding includes fix advice
  • Developer integrations — optional IDE plugins for Visual Studio, IntelliJ, and Eclipse to view findings during development

DAST Assessment

Fortify on Demand DAST includes:

  • Automated crawl and scan — OpenText scans your running web application (requires URL access from OpenText’s scanning infrastructure)
  • Authenticated scanning — login credentials or authentication tokens can be configured for authenticated endpoint coverage
  • Results portal — findings with OWASP and CWE mapping, severity, and remediation guidance
  • Manual validation option — higher FoD tiers include optional manual validation of automated findings by OpenText security analysts

What FoD Does NOT Include

Understanding the exclusions is as important as understanding what’s included:

  • No on-premise scanning — FoD is cloud-only; your code is uploaded to OpenText’s infrastructure. Organizations with source code confidentiality requirements or air-gap mandates cannot use FoD.
  • No Software Security Center (SSC) — FoD has its own results portal, but it does not include the full on-premise SSC platform. Teams needing advanced workflow, audit trails, custom dashboards, and enterprise policy management must use on-premise Fortify SCA + SSC.
  • No CI/CD native integration at entry tiers — FoD integrations with GitHub Actions, Azure DevOps, and GitLab CI are available but require additional configuration; they are not as seamless as SAST tools built natively for CI/CD.
  • No IaC scanning — Fortify on Demand does not include Infrastructure-as-Code scanning for Terraform, Helm charts, or Kubernetes manifests.
  • No SCA (Software Composition Analysis) — Fortify on Demand does not include NuGet, Maven, npm, or PyPI dependency scanning for known CVEs. SCA is a separate OpenText product (Debricked).
  • Remediation services are extra — dedicated security analyst review of results and remediation guidance sessions are billed separately at professional services rates.

The True Total Cost of Fortify on Demand

The base FoD subscription is just the starting point. Realistic total annual cost for a mid-size organization (10 applications):

ComponentAnnual Cost
FoD SAST subscription (10 apps)$75,000–$120,000
FoD DAST subscription (10 apps) — if purchased separately$50,000–$80,000
SCA add-on (if needed) — separate OpenText product$15,000–$40,000
Premium support (15–20% of license)$15,000–$30,000
Professional services (onboarding, CI/CD setup)$10,000–$25,000 (one-time)
Total Year 1 (SAST + DAST + support)$165,000–$295,000+
Ongoing (Year 2+)$155,000–$270,000+/year

This is consistent with how Fortify on Demand is positioned as enterprise tooling — budget expectations should start at $100,000+ annually for any meaningful SAST + DAST coverage across 10+ applications.


Fortify on Demand vs. Fortify SCA On-Premise: Which Is Right?

Teams choosing between FoD and on-premise SCA typically make the decision based on three factors:

Choose Fortify on Demand If:

  • No infrastructure to manage — you don’t want to provision and maintain scan servers, SSC databases, and update pipelines
  • Fewer applications — FoD’s per-application pricing is most economical at lower application counts (under 10–15 apps)
  • No source code confidentiality requirement — you are comfortable uploading source code to OpenText’s cloud
  • Faster deployment — FoD can be active within days; on-premise SCA takes weeks to deploy

Choose Fortify SCA On-Premise If:

  • Source code cannot leave your network — for classified systems, regulated financial data, or proprietary algorithms
  • Air-gapped operation required — on-premise deployment can operate with no outbound internet connectivity
  • More than 20+ applications — at scale, on-premise SCA typically becomes more economical than per-application FoD pricing
  • Full SSC required — the Software Security Center’s advanced policy management, audit workflows, and enterprise reporting are only available on-premise
  • Scan speed matters — on-premise scanning does not have upload/transfer overhead

Fortify on Demand vs. Alternatives

Fortify on Demand vs. Checkmarx One

Checkmarx One is Fortify on Demand’s most direct competitor — a SaaS SAST platform with cloud-based scanning.

CriterionFortify on DemandCheckmarx One
Pricing modelPer-applicationPer-developer seat
DAST included✅ Separate subscription❌ Add-on purchase
SCA included❌ Separate product✅ Add-on
On-premise option❌ (FoD is SaaS only)⚠️ CxSAST only
CI/CD integration⚠️ Available but complex✅ Strong
Estimated SAST cost (10 apps)$75K–$120K/year$60K–$100K/year

Checkmarx One tends to have stronger native CI/CD integrations and slightly lower SAST-only pricing at small-to-medium application counts. Fortify on Demand has a stronger audit trail and compliance reporting reputation in government-adjacent markets.

Fortify on Demand vs. Veracode

Veracode is another SaaS application security platform using cloud-based binary analysis:

CriterionFortify on DemandVeracode
Analysis approachSource codeCompiled binary
DAST included✅ Separate✅ Separate
SCA included✅ Included
Pricing modelPer-applicationPer-seat
On-premise option
Estimated annual (10 apps)$75K–$150K$50K–$100K

Veracode analyzes compiled artifacts rather than source code — this means you don’t need to upload source, but analysis is less precise for complex data-flow vulnerabilities. Fortify on Demand provides source-level analysis with more precise taint tracking.

Fortify on Demand vs. Offensive360

For teams evaluating Fortify on Demand who need comparable or deeper security analysis with on-premise operation and significantly lower total cost:

CriterionFortify on DemandOffensive360
DeploymentSaaS (code to cloud)On-premise OVA
Source code privacy❌ Uploaded to OpenText✅ Never leaves your network
SAST✅ Yes✅ Yes
DAST✅ Separate subscription✅ Included
SCA❌ Separate product✅ Included
IaC scanning❌ No✅ Included
Air-gap support❌ No✅ Yes
Pricing modelPer-applicationFlat annual rate
Second-order injection detection✅ Yes✅ Yes
Language coverage27+60+
Estimated annual (10 apps)$75K–$150K+Significantly lower flat rate

The most significant structural difference: Offensive360 includes SAST, DAST, SCA, and IaC scanning in a single flat-rate on-premise license — with source code never leaving your network. Fortify on Demand requires DAST and SCA as separate purchases, sends source code to OpenText’s cloud, and has no on-premise option in FoD.

For organizations in regulated industries or with source code confidentiality requirements, Offensive360’s on-premise OVA with air-gap support is the primary structural advantage over any SaaS-based alternative including Fortify on Demand.


Hidden Costs of Fortify on Demand

Beyond the subscription fee, FoD buyers frequently encounter unexpected costs:

1. Application Definition Complexity

Counting “applications” for FoD licensing is less straightforward than it sounds. Microservices architectures (where a single “application” may consist of 20–50 independent services) can expand licensed application counts dramatically. Clarify at contract time how OpenText defines “application” for your architecture.

2. Scan Frequency Limitations

Entry-tier FoD contracts limit the number of scans per application per period. Continuous CI/CD scanning (one scan per pull request) typically requires a higher-tier subscription. Teams expecting per-PR SAST scanning should verify scan frequency limits before signing.

3. Large Codebase Scan Times

Even with cloud-based scanning, Fortify SCA’s analysis can take hours for large codebases. Teams with multi-million LOC monorepos may find FoD’s scan times incompatible with CI/CD feedback loop expectations.

4. DAST Target Accessibility

Fortify on Demand DAST scans your running application from OpenText’s scanning infrastructure. This requires your application to be accessible from the public internet (or through a VPN/agent setup). Internal-only applications require additional networking setup, which is often not accounted for at contract signing.

5. Data Residency

FoD offers US and EU data residency options, but customers in other regions (APAC, LATAM) should verify compliance with local data sovereignty requirements before uploading code.


Who Should Use Fortify on Demand

FoD makes sense in specific scenarios:

Organizations with Fortify mandates in compliance frameworks: Some US government-adjacent and defense supply chain organizations have Fortify referenced in compliance documentation. FoD provides the Fortify SCA analysis engine in a simpler deployment model while maintaining compliance.

Teams with budget for SaaS SAST at 5–15 application scale: FoD’s per-application model works reasonably well at this scale before on-premise SCA becomes more economical.

Organizations without on-premise infrastructure capacity: Teams that cannot provision and maintain scan servers benefit from FoD’s SaaS model, provided source code confidentiality is not a constraint.

Who Should Look Beyond Fortify on Demand

Source code confidentiality required: Any organization where source code cannot leave the internal network cannot use FoD. On-premise alternatives with air-gap support (Offensive360, Fortify SCA on-premise) are the correct approach.

SAST + DAST + SCA needed in one platform: FoD requires separate subscriptions or product purchases for each capability. Teams wanting a unified platform will find FoD’s fragmented product structure adds significant cost and operational complexity.

Rapidly growing application portfolios: FoD’s per-application pricing scales linearly with application count. Organizations whose application portfolio is growing quickly will find flat-rate alternatives increasingly attractive as they scale.

Aggressive CI/CD feedback loops: Per-PR SAST requires higher FoD tiers and may still not match the feedback speed of tools built natively for CI/CD workflows.


How to Get Fortify on Demand Pricing

Since OpenText does not publish FoD pricing:

  1. Contact OpenText sales via the Fortify product page or request a trial through the FoD portal
  2. Define your scope — list your applications, languages, and whether you need SAST, DAST, or both
  3. Request a proof-of-concept — OpenText will typically scan a representative application during the evaluation
  4. Get itemized pricing for SAST and DAST separately, so you can compare each component against alternatives
  5. Ask about multi-year discounts — 2–3 year commitments typically unlock 15–25% savings
  6. Clarify scan limits — confirm how many scans per application are included at your tier

Before engaging OpenText sales, establish a baseline by running your code through a competing platform. A concrete vulnerability baseline — including taint-analysis results for injection, authentication, and access control vulnerabilities — gives you a comparison point when evaluating FoD’s proof-of-concept results.

Book a demo with Offensive360 to get a baseline SAST scan of your codebase. Source code stays on your server, results in 48 hours — with a full DAST and SCA report included at no additional cost.


Frequently Asked Questions

How much does Fortify on Demand cost per application per year?

Fortify on Demand pricing is not publicly listed. Based on customer reports, SAST-only pricing for a single application ranges from approximately $5,000–$15,000 per application per year, depending on application size and contract terms. The per-application cost decreases at higher application counts with volume discounts. Total contracts for 10+ applications typically run $75,000–$150,000+/year for SAST alone.

Does Fortify on Demand include DAST?

DAST is available in Fortify on Demand but requires a separate subscription — it is not bundled with SAST. Dynamic Application Security Testing in FoD scans your running web application via OpenText’s scanning infrastructure. The combined SAST + DAST FoD cost for a mid-size portfolio is typically $150,000–$250,000+/year.

Can Fortify on Demand scan internal applications not accessible from the internet?

Fortify on Demand DAST requires the application to be accessible from OpenText’s scanning infrastructure. For internal applications, this typically requires either a VPN connection, an agent-based configuration, or temporarily exposing the application externally during the scan window. SAST (source code upload) does not have this requirement.

Is there a free trial of Fortify on Demand?

OpenText offers limited trial access to Fortify on Demand for qualified prospects through their sales team. There is no self-serve free trial. The evaluation process involves direct engagement with OpenText sales and typically includes a proof-of-concept scan of a representative application.

What languages does Fortify on Demand support?

Fortify on Demand supports over 27 languages and frameworks through the underlying Fortify SCA engine, including Java, C/C++, C#/.NET, JavaScript/TypeScript, Python, PHP, Ruby, Go, Swift, Objective-C, Kotlin, Scala, COBOL, PL/SQL, Apex (Salesforce), and more. Language depth varies — Java/.NET have the deepest rule coverage; newer languages like Go and Rust have lighter rule sets.

What is the difference between Fortify on Demand and Fortify SCA?

Fortify SCA is the on-premise scan engine — you install it on your own servers, upload source locally, and manage results in the Fortify Software Security Center (SSC). Fortify on Demand is the cloud delivery model where source code is uploaded to OpenText’s infrastructure for scanning. FoD is simpler to deploy but requires external code upload, has fewer SSC features, and costs more at high application counts. See our Fortify SCA pricing guide for the full on-premise cost breakdown.


Summary

Fortify on Demand is OpenText’s SaaS SAST and DAST platform — the simplest entry point into the Fortify ecosystem without on-premise infrastructure. But the pricing reality is:

  • SAST-only for 10 applications: $75,000–$150,000+/year
  • SAST + DAST for 10 applications: $150,000–$250,000+/year
  • Source code is uploaded to OpenText’s cloud — not suitable for air-gapped or confidential-code environments
  • DAST, SCA, and IaC scanning are separate products or subscriptions
  • No on-premise option within FoD — teams needing on-premise must use Fortify SCA

For organizations that need equivalent SAST + DAST + SCA coverage with source code that never leaves the network, on-premise OVA deployment, and a flat annual rate that doesn’t scale per-application, Offensive360 is worth evaluating before committing to a Fortify on Demand contract.


Related: Fortify Static Code Analyzer pricing and total cost | Checkmarx pricing and hidden costs | Offensive360 vs. Fortify comparison

Offensive360 Security Research Team

Application Security Research

Find vulnerabilities before attackers do

Run Offensive360 SAST and DAST against your applications and get a full vulnerability report in minutes.