Fortify on Demand (FoD) is the cloud-hosted, SaaS delivery model for OpenText’s Fortify application security testing platform. Unlike Fortify Static Code Analyzer (SCA), which runs on your own infrastructure, Fortify on Demand sends your code or application to OpenText’s cloud for scanning — with results delivered through the FoD web portal.
For teams that want enterprise-grade SAST and DAST without managing on-premise scan engines and a Software Security Center (SSC) server, Fortify on Demand is the primary Fortify entry point. But pricing is opaque, what’s included varies significantly by tier, and the true total cost is frequently misunderstood at the point of purchase.
This guide breaks down Fortify on Demand pricing in 2026, what each tier includes, what it does not include, and how FoD compares to alternatives.
How Fortify on Demand Pricing Works
Fortify on Demand uses a per-application or per-scan pricing model. Unlike on-premise Fortify SCA (which is licensed per lines of code or application count with your own infrastructure), FoD pricing is structured around the number of applications you submit for scanning and the type of testing requested.
Pricing is not publicly listed by OpenText — all FoD contracts are delivered through direct sales engagement. The variables that drive FoD pricing are:
- Number of applications — the primary driver; each application submitted for scanning is a separate unit of consumption
- Scan type — Static Assessment (SAST), Dynamic Assessment (DAST), or both
- Scan frequency — on-demand scans vs. continuous scanning subscriptions
- Remediation consultancy — whether the contract includes OpenText remediation guidance services
- Contract length — annual vs. multi-year commitments
- Organization size — enterprise contracts get different rate structures than mid-market buyers
Fortify on Demand Pricing: Realistic Cost Ranges
Based on publicly available procurement records, G2 customer reviews, Gartner Peer Insights, and enterprise buyer conversations, here are realistic 2026 price ranges for Fortify on Demand:
SAST (Static Assessment) Only
| Application Count | Estimated Annual Cost |
|---|---|
| 1–3 applications | $15,000–$30,000/year |
| 3–10 applications | $30,000–$75,000/year |
| 10–25 applications | $75,000–$150,000/year |
| 25+ applications | $150,000–$400,000+/year |
DAST (Dynamic Assessment) Only
Fortify on Demand DAST is also available as a standalone subscription — not bundled with SAST:
| Application Count | Estimated Annual Cost |
|---|---|
| 1–3 applications | $10,000–$25,000/year |
| 3–10 applications | $25,000–$60,000/year |
| 10–25 applications | $60,000–$120,000/year |
SAST + DAST Combined
When purchasing both static and dynamic assessments through FoD, organizations typically see a 15–25% bundle discount versus purchasing separately:
| Application Count | Estimated Annual Cost |
|---|---|
| 1–5 applications | $20,000–$50,000/year |
| 5–15 applications | $50,000–$120,000/year |
| 15–30 applications | $120,000–$250,000+/year |
What Fortify on Demand Includes
SAST Assessment
Each Fortify on Demand SAST assessment includes:
- Code upload and scanning — source code is uploaded to OpenText’s cloud infrastructure (US or EU region, depending on contract)
- Automated scan — the Fortify SCA engine analyzes the uploaded code
- Results portal — findings delivered through the FoD web portal with severity ratings, CWE mappings, and code-level findings
- OWASP Top 10 and CWE mapping — results categorized by standard security taxonomies
- Remediation guidance — each finding includes fix advice
- Developer integrations — optional IDE plugins for Visual Studio, IntelliJ, and Eclipse to view findings during development
DAST Assessment
Fortify on Demand DAST includes:
- Automated crawl and scan — OpenText scans your running web application (requires URL access from OpenText’s scanning infrastructure)
- Authenticated scanning — login credentials or authentication tokens can be configured for authenticated endpoint coverage
- Results portal — findings with OWASP and CWE mapping, severity, and remediation guidance
- Manual validation option — higher FoD tiers include optional manual validation of automated findings by OpenText security analysts
What FoD Does NOT Include
Understanding the exclusions is as important as understanding what’s included:
- No on-premise scanning — FoD is cloud-only; your code is uploaded to OpenText’s infrastructure. Organizations with source code confidentiality requirements or air-gap mandates cannot use FoD.
- No Software Security Center (SSC) — FoD has its own results portal, but it does not include the full on-premise SSC platform. Teams needing advanced workflow, audit trails, custom dashboards, and enterprise policy management must use on-premise Fortify SCA + SSC.
- No CI/CD native integration at entry tiers — FoD integrations with GitHub Actions, Azure DevOps, and GitLab CI are available but require additional configuration; they are not as seamless as SAST tools built natively for CI/CD.
- No IaC scanning — Fortify on Demand does not include Infrastructure-as-Code scanning for Terraform, Helm charts, or Kubernetes manifests.
- No SCA (Software Composition Analysis) — Fortify on Demand does not include NuGet, Maven, npm, or PyPI dependency scanning for known CVEs. SCA is a separate OpenText product (Debricked).
- Remediation services are extra — dedicated security analyst review of results and remediation guidance sessions are billed separately at professional services rates.
The True Total Cost of Fortify on Demand
The base FoD subscription is just the starting point. Realistic total annual cost for a mid-size organization (10 applications):
| Component | Annual Cost |
|---|---|
| FoD SAST subscription (10 apps) | $75,000–$120,000 |
| FoD DAST subscription (10 apps) — if purchased separately | $50,000–$80,000 |
| SCA add-on (if needed) — separate OpenText product | $15,000–$40,000 |
| Premium support (15–20% of license) | $15,000–$30,000 |
| Professional services (onboarding, CI/CD setup) | $10,000–$25,000 (one-time) |
| Total Year 1 (SAST + DAST + support) | $165,000–$295,000+ |
| Ongoing (Year 2+) | $155,000–$270,000+/year |
This is consistent with how Fortify on Demand is positioned as enterprise tooling — budget expectations should start at $100,000+ annually for any meaningful SAST + DAST coverage across 10+ applications.
Fortify on Demand vs. Fortify SCA On-Premise: Which Is Right?
Teams choosing between FoD and on-premise SCA typically make the decision based on three factors:
Choose Fortify on Demand If:
- No infrastructure to manage — you don’t want to provision and maintain scan servers, SSC databases, and update pipelines
- Fewer applications — FoD’s per-application pricing is most economical at lower application counts (under 10–15 apps)
- No source code confidentiality requirement — you are comfortable uploading source code to OpenText’s cloud
- Faster deployment — FoD can be active within days; on-premise SCA takes weeks to deploy
Choose Fortify SCA On-Premise If:
- Source code cannot leave your network — for classified systems, regulated financial data, or proprietary algorithms
- Air-gapped operation required — on-premise deployment can operate with no outbound internet connectivity
- More than 20+ applications — at scale, on-premise SCA typically becomes more economical than per-application FoD pricing
- Full SSC required — the Software Security Center’s advanced policy management, audit workflows, and enterprise reporting are only available on-premise
- Scan speed matters — on-premise scanning does not have upload/transfer overhead
Fortify on Demand vs. Alternatives
Fortify on Demand vs. Checkmarx One
Checkmarx One is Fortify on Demand’s most direct competitor — a SaaS SAST platform with cloud-based scanning.
| Criterion | Fortify on Demand | Checkmarx One |
|---|---|---|
| Pricing model | Per-application | Per-developer seat |
| DAST included | ✅ Separate subscription | ❌ Add-on purchase |
| SCA included | ❌ Separate product | ✅ Add-on |
| On-premise option | ❌ (FoD is SaaS only) | ⚠️ CxSAST only |
| CI/CD integration | ⚠️ Available but complex | ✅ Strong |
| Estimated SAST cost (10 apps) | $75K–$120K/year | $60K–$100K/year |
Checkmarx One tends to have stronger native CI/CD integrations and slightly lower SAST-only pricing at small-to-medium application counts. Fortify on Demand has a stronger audit trail and compliance reporting reputation in government-adjacent markets.
Fortify on Demand vs. Veracode
Veracode is another SaaS application security platform using cloud-based binary analysis:
| Criterion | Fortify on Demand | Veracode |
|---|---|---|
| Analysis approach | Source code | Compiled binary |
| DAST included | ✅ Separate | ✅ Separate |
| SCA included | ❌ | ✅ Included |
| Pricing model | Per-application | Per-seat |
| On-premise option | ❌ | ❌ |
| Estimated annual (10 apps) | $75K–$150K | $50K–$100K |
Veracode analyzes compiled artifacts rather than source code — this means you don’t need to upload source, but analysis is less precise for complex data-flow vulnerabilities. Fortify on Demand provides source-level analysis with more precise taint tracking.
Fortify on Demand vs. Offensive360
For teams evaluating Fortify on Demand who need comparable or deeper security analysis with on-premise operation and significantly lower total cost:
| Criterion | Fortify on Demand | Offensive360 |
|---|---|---|
| Deployment | SaaS (code to cloud) | On-premise OVA |
| Source code privacy | ❌ Uploaded to OpenText | ✅ Never leaves your network |
| SAST | ✅ Yes | ✅ Yes |
| DAST | ✅ Separate subscription | ✅ Included |
| SCA | ❌ Separate product | ✅ Included |
| IaC scanning | ❌ No | ✅ Included |
| Air-gap support | ❌ No | ✅ Yes |
| Pricing model | Per-application | Flat annual rate |
| Second-order injection detection | ✅ Yes | ✅ Yes |
| Language coverage | 27+ | 60+ |
| Estimated annual (10 apps) | $75K–$150K+ | Significantly lower flat rate |
The most significant structural difference: Offensive360 includes SAST, DAST, SCA, and IaC scanning in a single flat-rate on-premise license — with source code never leaving your network. Fortify on Demand requires DAST and SCA as separate purchases, sends source code to OpenText’s cloud, and has no on-premise option in FoD.
For organizations in regulated industries or with source code confidentiality requirements, Offensive360’s on-premise OVA with air-gap support is the primary structural advantage over any SaaS-based alternative including Fortify on Demand.
Hidden Costs of Fortify on Demand
Beyond the subscription fee, FoD buyers frequently encounter unexpected costs:
1. Application Definition Complexity
Counting “applications” for FoD licensing is less straightforward than it sounds. Microservices architectures (where a single “application” may consist of 20–50 independent services) can expand licensed application counts dramatically. Clarify at contract time how OpenText defines “application” for your architecture.
2. Scan Frequency Limitations
Entry-tier FoD contracts limit the number of scans per application per period. Continuous CI/CD scanning (one scan per pull request) typically requires a higher-tier subscription. Teams expecting per-PR SAST scanning should verify scan frequency limits before signing.
3. Large Codebase Scan Times
Even with cloud-based scanning, Fortify SCA’s analysis can take hours for large codebases. Teams with multi-million LOC monorepos may find FoD’s scan times incompatible with CI/CD feedback loop expectations.
4. DAST Target Accessibility
Fortify on Demand DAST scans your running application from OpenText’s scanning infrastructure. This requires your application to be accessible from the public internet (or through a VPN/agent setup). Internal-only applications require additional networking setup, which is often not accounted for at contract signing.
5. Data Residency
FoD offers US and EU data residency options, but customers in other regions (APAC, LATAM) should verify compliance with local data sovereignty requirements before uploading code.
Who Should Use Fortify on Demand
FoD makes sense in specific scenarios:
Organizations with Fortify mandates in compliance frameworks: Some US government-adjacent and defense supply chain organizations have Fortify referenced in compliance documentation. FoD provides the Fortify SCA analysis engine in a simpler deployment model while maintaining compliance.
Teams with budget for SaaS SAST at 5–15 application scale: FoD’s per-application model works reasonably well at this scale before on-premise SCA becomes more economical.
Organizations without on-premise infrastructure capacity: Teams that cannot provision and maintain scan servers benefit from FoD’s SaaS model, provided source code confidentiality is not a constraint.
Who Should Look Beyond Fortify on Demand
Source code confidentiality required: Any organization where source code cannot leave the internal network cannot use FoD. On-premise alternatives with air-gap support (Offensive360, Fortify SCA on-premise) are the correct approach.
SAST + DAST + SCA needed in one platform: FoD requires separate subscriptions or product purchases for each capability. Teams wanting a unified platform will find FoD’s fragmented product structure adds significant cost and operational complexity.
Rapidly growing application portfolios: FoD’s per-application pricing scales linearly with application count. Organizations whose application portfolio is growing quickly will find flat-rate alternatives increasingly attractive as they scale.
Aggressive CI/CD feedback loops: Per-PR SAST requires higher FoD tiers and may still not match the feedback speed of tools built natively for CI/CD workflows.
How to Get Fortify on Demand Pricing
Since OpenText does not publish FoD pricing:
- Contact OpenText sales via the Fortify product page or request a trial through the FoD portal
- Define your scope — list your applications, languages, and whether you need SAST, DAST, or both
- Request a proof-of-concept — OpenText will typically scan a representative application during the evaluation
- Get itemized pricing for SAST and DAST separately, so you can compare each component against alternatives
- Ask about multi-year discounts — 2–3 year commitments typically unlock 15–25% savings
- Clarify scan limits — confirm how many scans per application are included at your tier
Before engaging OpenText sales, establish a baseline by running your code through a competing platform. A concrete vulnerability baseline — including taint-analysis results for injection, authentication, and access control vulnerabilities — gives you a comparison point when evaluating FoD’s proof-of-concept results.
Book a demo with Offensive360 to get a baseline SAST scan of your codebase. Source code stays on your server, results in 48 hours — with a full DAST and SCA report included at no additional cost.
Frequently Asked Questions
How much does Fortify on Demand cost per application per year?
Fortify on Demand pricing is not publicly listed. Based on customer reports, SAST-only pricing for a single application ranges from approximately $5,000–$15,000 per application per year, depending on application size and contract terms. The per-application cost decreases at higher application counts with volume discounts. Total contracts for 10+ applications typically run $75,000–$150,000+/year for SAST alone.
Does Fortify on Demand include DAST?
DAST is available in Fortify on Demand but requires a separate subscription — it is not bundled with SAST. Dynamic Application Security Testing in FoD scans your running web application via OpenText’s scanning infrastructure. The combined SAST + DAST FoD cost for a mid-size portfolio is typically $150,000–$250,000+/year.
Can Fortify on Demand scan internal applications not accessible from the internet?
Fortify on Demand DAST requires the application to be accessible from OpenText’s scanning infrastructure. For internal applications, this typically requires either a VPN connection, an agent-based configuration, or temporarily exposing the application externally during the scan window. SAST (source code upload) does not have this requirement.
Is there a free trial of Fortify on Demand?
OpenText offers limited trial access to Fortify on Demand for qualified prospects through their sales team. There is no self-serve free trial. The evaluation process involves direct engagement with OpenText sales and typically includes a proof-of-concept scan of a representative application.
What languages does Fortify on Demand support?
Fortify on Demand supports over 27 languages and frameworks through the underlying Fortify SCA engine, including Java, C/C++, C#/.NET, JavaScript/TypeScript, Python, PHP, Ruby, Go, Swift, Objective-C, Kotlin, Scala, COBOL, PL/SQL, Apex (Salesforce), and more. Language depth varies — Java/.NET have the deepest rule coverage; newer languages like Go and Rust have lighter rule sets.
What is the difference between Fortify on Demand and Fortify SCA?
Fortify SCA is the on-premise scan engine — you install it on your own servers, upload source locally, and manage results in the Fortify Software Security Center (SSC). Fortify on Demand is the cloud delivery model where source code is uploaded to OpenText’s infrastructure for scanning. FoD is simpler to deploy but requires external code upload, has fewer SSC features, and costs more at high application counts. See our Fortify SCA pricing guide for the full on-premise cost breakdown.
Summary
Fortify on Demand is OpenText’s SaaS SAST and DAST platform — the simplest entry point into the Fortify ecosystem without on-premise infrastructure. But the pricing reality is:
- SAST-only for 10 applications: $75,000–$150,000+/year
- SAST + DAST for 10 applications: $150,000–$250,000+/year
- Source code is uploaded to OpenText’s cloud — not suitable for air-gapped or confidential-code environments
- DAST, SCA, and IaC scanning are separate products or subscriptions
- No on-premise option within FoD — teams needing on-premise must use Fortify SCA
For organizations that need equivalent SAST + DAST + SCA coverage with source code that never leaves the network, on-premise OVA deployment, and a flat annual rate that doesn’t scale per-application, Offensive360 is worth evaluating before committing to a Fortify on Demand contract.
Related: Fortify Static Code Analyzer pricing and total cost | Checkmarx pricing and hidden costs | Offensive360 vs. Fortify comparison