Conga CPQ empowers sales, partners, and customers to efficiently configure complex products and services offerings, and provide personalized prices and quotes, utilizing codified product and pricing information - to drive higher win rates and a more pleasurable buying experience. Conga CPQ also helps to maintain a single price book, discounting structure, and quoting structure across all channels. With an API-first approach, configuration, pricing, or quoting…
$35
per month per user
Veracode
Score8.5 out of 10
Mid-Size Companies (51-1,000 employees)
Veracode provides advanced application security solutions, trusted by enterprises to develop and maintain secure software. Its platform identifies exploitable risks, speeds up vulnerability remediation, and reduces security debt at scale using a proprietary AI-assisted remediation engine.
It is well suited to providing quick pricing recommendations, allowing those who are quoting to get our agreements out efficiently. Where I find there may be some limitations is around the details that it uses to establish recommendations and the overrides. For example it would be nice to have a way to set overrides for those criteria like length of agreement, etc. and have it apply across the board
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
Veracode helped us our team's developers in saving time significantly. For instance, if I take a library and assume it's going to work until it reaches QA or UAT, where we find out there's a vulnerability, that can require extensive effort for code refactoring or redesigning; Veracode helps prevent that before the pull request is merged.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
The perceived power strength is that it is supposed to contain CPQ, Contract Management, Document generation and template manipulation, and cash/invoice process all in one wrapped package.
It was developed on the Force.com platform.
They provide multiple releases of their product per year.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
It is good at recommending fixing issues with third-party dependencies used in application code with detailed version information and knowing which version fixes what.
It has a very nice interface for triaging flaws. One can sort the vulnerabilities found in code from Very Likely to be exploited to least likely to be exploited.
There is a collections feature that allows us to group together groups of application profiles belonging to the same suite of applications.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
Our number one complaint with Conga CPQ has been speed. In my experience, Conga CPQ is extremely slow, especially for large orders.
In my opinion, the configuration methods of Conga CPQ are outdated and error-prone. One literally puts configurations into string-based custom settings, including the API field names. This often leads to deployment issues and run-time configuration errors.
In my experience, Conga CPQ is everything but simple to develop. You need things like a 12-step pricing callback to support custom pricing.
In my experience, Conga CPQ support is not responsive.
When it comes time to lock in a renewal contract for Conga CPQ, in my experience, they delay engagement, so you are truly behind the 8 ball when it comes time to decide if you are going to continue with Conga CPQ.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
The rating is based on several things: 1) Ongoing support requirements being able to be addressed by cross training existing Salesforce administrators 2) Apttus superior corporate vision for the quote to cash space 3) Apttus execution of the corporate vision with automated agents (Max), and Artificial Intelligence/Machine Learning offerings to leverage the investment in Configure Price Quote 4) Apttus corporate health and investment in the product line
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
At this time, and we just renewed a month ago, I dont see any products out there overall that can offer what Veracode does. Yes, its not cheap by any means, but for the money its the best application security scanning tool out there.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
Conga CPQ is a great tool but lacks good support and [a] very limited knowledge base which doesn't include day to day errors which users face, thus leading us to support and take more time in turn. Also cart performance can be improved drastically which will enhance the user experience as the user doesn't have to wait for the pricing.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
- Almost no setup required and easy to configure - Very easy to use, intuitive UI with integrated analytics and learning portals. - Seamless to review the results, triage them, generate reports. - Security progression of the product/application is tracked via successive scans. - Privileges/Roles nicely fine grained and tightly controlled to let teams "view" only their products.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
Tier1/tier 2 support can only handle native functionality. Customizations have to be escalated to developers which aren’t included in the support program.
I go ahead and copy the people I directly worked with on implementation for assistance. I would rate them an 8 for support assistance.
Overall, Veracode support is helpful, community support is great, and documentation is available for self-service. Our Customer Success Manager is very helpful and reaches out regularly to see if we need assistance. We have not utilized many of the other resources offered by Veracode, however, in the future we would like to leverage secure coding training for our Development teams.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
Be iterative. Take the opportunity to build a catalog based on how Apttus works well. Learn the tool yourself or use an SI. Take the time to build a configuration / pricing migration tool with X-Author for Excel or roll your own. Stick with OOTB Apttus as any customization will cost you every time a new version is released
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
We use it as a SAS service, so really just getting our teams to mold the use of Veracode into their SDLC has been a process of years in the making. It comes down to what your teams are ready and willing to accept and change. Management is key in getting their groups on board with using it regularly. If it doesnt have management backing, your security teams have little to no influence in getting this process off the ground fully.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
We selected Apttus CPQ over SteelBrick due to the simplicity of SteelBrick's out of the box pricing and ability to customize quoted products. As a global organization with selling a highly configurable products, we felt the ability of Apttus to handle our requirements as standard functionalty rather than a customization was a material difference between the platforms.
Veracode is slower with scan results however the flaws discovered and sites crawled are almost the same. Rapid7 InsightAppSec only does dynamic scans. Veracode did find more links on a site crawl. Rapid7 InsightAppSec has more out of the box reports than Veracode. Both integration to DevOps tools were striaghtforward.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
The ability to generate engineered configurations that is right by construction has reduced the cycle time of the customer engagement. The fact that we are able to guide the process and end up with a validated bill of material reduces the iterations with the customers.
As long as the validations rules are correct the generated bill of material is accurate. We are now looking at using Apttus to perform quality checks in our product rules since the tool is able to test different configurations quickly and efficiently.
Configuration that use to take weeks and consumed valuable engineering resources has been transformed to become a customer facing application that is simple enough for customer to self-service.
Positive: Scanning all our applications on Veracode provides us an overview of our cyber security posture for the organization as a whole.
Positive: Performing the SAST, SCA and DAST scanning for all the applications at the early stages of the SDLC helps us identify and mitigate security vulnerabilities early, reducing the risk of data breaches and cyber-attacks.
Negative: Sometimes Veracode SAST scanner closed and reopens some findings, leading to reliability issues on the scanner itself.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info