Listing Thumbnail

    WIZ Cloud Infrastructure Security Platform

     Info
    Sold by: Wiz 
    Deployed on AWS
    Free Trial
    Vendor Insights
    AWS Free Tier
    Wiz provides an entirely new approach to cloud security that for the first time identifies the actual risks hidden in your cloud infrastructure.
    4.7

    Overview

    Wiz performs a deep assessment of your entire cloud and then correlates a vast number of security signals to trace the real infiltration vectors that attackers can use to break in. Wiz also gives you the tools to bring your DevOps and development teams into the process to fix these risks, creating a culture of security in your cloud operations that results in a stronger, more secure cloud. For more information visit: https://www.wiz.io 

    *Wiz provides custom pricing for customers via Private Offer. Please contact marketplace@wiz.io  for a better understanding of our pricing model and products.

    Highlights

    • Covers every resource across your full cloud stack, multi-cloud environment using a 100% API approach that deploys in minutes.
    • Models overlapping cloud policies, configurations, and compensating controls that interact in ways that are often unpredictable to calculate their end result.
    • Maps all of the issues in your cloud together in a single graph database, revealing which of them combined pose the greatest risk.

    Details

    Sold by

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Trust Center

    Trust Center
    Access real-time vendor security and compliance information through their Trust Center powered by Drata. Review certifications and security standards before purchase.

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Vendor Insights

     Info
    Skip the manual risk assessment. Get verified and regularly updated security info on this product with Vendor Insights.
    Security credentials achieved
    (7)

    Pricing

    Free trial

    Try this product free according to the free trial terms set by the vendor.

    WIZ Cloud Infrastructure Security Platform

     Info
    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (5)

     Info
    Dimension
    Description
    Cost/12 months
    Wiz Essential
    Protect 100 cloud workloads
    $24,000.00
    Wiz Advanced
    Protect 100 cloud workloads
    $38,000.00
    Wiz Sensor
    100 Wiz Sensors. Add-on for Wiz Advanced
    $28,000.00
    Wiz Code
    100 Wiz Code Licenses. Add-on for Wiz Cloud
    $58,500.00
    Wiz Defend
    Ingest 300 GBs of logs per month. Add-on for Wiz Advanced
    $18,000.00

    Vendor refund policy

    Please contact us at info@wiz.io 

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    We'd like to hear your feedback and ideas on how to improve this page.
    We'd like to hear your feedback and ideas on how to improve this page.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    Vendor support

    Wiz provides custom pricing for customers via Private Offer. Please contact marketplace@wiz.io  for a better understanding of our pricing model and products. tel:+01-240.823.5670

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    10
    In Application Development, Continuous Integration and Continuous Delivery, Security
    Top
    10
    In Vulnerability and Patch Management, Data Governance
    Top
    25
    In Observability, Software Development

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Cloud Infrastructure Scanning
    "Performs comprehensive assessment across entire cloud infrastructure using 100% API-based approach with rapid deployment"
    Risk Correlation Mechanism
    "Correlates multiple security signals to trace potential infiltration vectors and identify complex attack paths"
    Multi-Cloud Support
    "Provides unified security coverage across diverse cloud environments and resource types"
    Policy Interaction Modeling
    "Analyzes overlapping cloud policies, configurations, and compensating controls to predict complex security interactions"
    Graph-Based Visualization
    "Generates comprehensive cloud security mapping using graph database to reveal interconnected security issues and risk relationships"
    Attack Surface Management
    Aggregates comprehensive attack surface visibility across hybrid environments with external attack surface scans to build a dynamic, 360-degree view
    Cloud Security
    Provides code-to-cloud protection for cloud-native applications with seamless CI/CD pipeline integration and real-time, agentless risk assessment
    Threat Intelligence
    Delivers high-fidelity, actionable threat intelligence sourced from proprietary threat and vulnerability research with community-driven tools
    Vulnerability Management
    Offers complete visibility across on-premise and remote endpoints to identify, communicate, and remediate vulnerabilities and misconfigurations
    Security Automation
    Enables acceleration and streamlining of time-intensive processes through customizable workflows and plugins without requiring coding expertise
    Cloud Security Posture Management
    Agentless CNAPP with comprehensive asset inventory, graph explorer, and security configuration scanning
    Threat Detection Engine
    AI-powered real-time protection for cloud workloads, servers, VMs, and containers across multi-cloud environments
    Infrastructure as Code Scanning
    Automated scanning of infrastructure configurations for security vulnerabilities and misconfigurations
    Cloud Object Storage Protection
    AI-powered malware detection for cloud storage platforms with millisecond scanning and automated remediation actions
    AI Model Security
    Security monitoring and protection for AI models and pipelines deployed on cloud AI services with advanced threat detection capabilities

    Security credentials

     Info
    Validated by AWS Marketplace
    FedRAMP
    GDPR
    HIPAA
    ISO/IEC 27001
    PCI DSS
    SOC 2 Type 2
    No security profile
    No security profile

    Contract

     Info
    Standard contract
    No
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4.7
    761 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    56%
    41%
    3%
    0%
    0%
    11 AWS reviews
    |
    750 external reviews
    External reviews are from G2  and PeerSpot .
    Madhav Shyam Lakhera

    Cloud risk posture has improved and custom dashboards and graph views provide deeper insights

    Reviewed on Dec 05, 2025
    Review provided by PeerSpot

    What is our primary use case?

    My experience with Wiz  varies on a case-by-case basis because I don't work on it daily; I engage with it when we need to research something that isn't fully implemented in the organization. Some elements are implemented, but they were done on a POC basis. I have hands-on experience where I've explored the environment extensively, checked vulnerabilities, and shared different findings with team members. So while I've worked with all that, I wouldn't classify it as part of my everyday BAU work, but I've been introduced to it in the last one or two years, max.

    We have multiple subscriptions linked to Wiz , and we monitor various aspects including cloud security posture management findings. Compliance is another area we've focused on, where we've created our own compliance framework within Wiz. One feature I particularly appreciate about Wiz is that, similar to other cloud-native security tools like Microsoft's Defender for Cloud, it allows you to define policies as code and deploy them through a version control system with a continuous deployment pipeline. This functionality is also present in Wiz, where their Terraform  provider enables complete documentation on controlling aspects directly in the Wiz environment. The major things we've worked on include deploying policies based on CSPM findings detected in Wiz, setting up our own framework and rules within those categories, and we've also worked with inventory management, as Wiz provides an AI-driven inventory that gives visibility into all cloud deployments. Wiz also helps manage vulnerabilities in various environments, such as Kubernetes  clusters or Azure  container apps.

    In different organizational contexts, whether product-based or service-based, the customization of dashboards is highly beneficial. For instance, if I'm a startup or a large company using Wiz for multiple applications, custom dashboards allow me to categorize data from various feeds. Dashboarding becomes effective after managing categorization; I can define a project and add relevant resources or subscriptions under that project. Moving forward in the dashboarding section, I can set up custom widgets to view high-severity CSPM findings or risks, thus visualizing data based on specific filters and categories.

    What is most valuable?

    One feature I appreciate about Wiz is the graph controls, which allow for the correlation of multiple findings. For example, if a virtual machine has a critical CVE and is exposed to the internet, this links multiple vulnerabilities such as initial access types. Wiz attempts to categorize these different types of findings, such as CWPP  and CSPM, and offers customization through graph controls where we can create our own contextual risk assessments in the cloud environment. Additionally, Wiz allows you to deploy aspects in the tool similarly to the GitHub  model, which I appreciate. Its UI is also very smooth and categorized, making it easy to navigate and search through resources efficiently. You can create custom reports and dashboards in your own way, which are some of the major aspects I value in Wiz.

    What needs improvement?

    There is definitely room for improvement with Wiz. Given the scope of CNAP technology, which covers the entire SDLC from deployment to monitoring and APIs, it would be beneficial to enhance data integration capabilities. Wiz could partner with leaders in the market, such as Checkmarx, for example; while it currently supports Checkmarx in preview, there still needs to be significant enhancement in contextually mapping risks from pre-deployment scans, such as SAS, SCA , and DAST scanning results. Including these results would elevate contextual risk assessments to a higher level.

    Wiz does encounter some glitches similar to other tools in the market. I remember facing certain challenges, such as problems scanning encrypted disks or discrepancies in the findings from already remediated vulnerabilities not reflecting accurately in the tool. These issues are not indicative of an overarching systemic failure but are worth noting as areas that could be improved upon.

    Currently, Wiz doesn't consolidate tools effectively. Though it is starting to move in that direction with Checkmarx integration in preview, it lacks the maturity to fully replace other mature open-source tools. Wiz does offer some capability in SCA  via CLI, but it falls short compared to its market counterparts and would benefit from further development in tool consolidation and correlation.

    For how long have I used the solution?

    I started using Wiz around two years ago.

    What do I think about the stability of the solution?

    During the POC, there were indeed a lot of alerts generated by Wiz. It's important to note that alerts vary in type; there are different classifications for vulnerability alerts, CSPM alerts, and contextual risk alerts. Each category has its own significance, meaning that while there may be a high volume of alerts, they can be beneficial and informative based on the context.

    Wiz does encounter some glitches similar to other tools in the market. I remember facing certain challenges, such as problems scanning encrypted disks or discrepancies in the findings from already remediated vulnerabilities not reflecting accurately in the tool. These issues are not indicative of an overarching systemic failure but are worth noting as areas that could be improved upon.

    What do I think about the scalability of the solution?

    I rate Wiz's scalability a perfect 10 out of 10. During our POC, we successfully linked many subscriptions and could manage them effectively without encountering any scalability issues.

    How are customer service and support?

    I would rate the vendor's technical support as a nine out of ten. They respond swiftly and provide support when needed; for instance, when we experienced some initial trouble figuring out how to configure CCRs and validate results, the vendor was readily available to assist us over calls, clarifying both technical aspects and theoretical insights.

    How would you rate customer service and support?

    Positive

    How was the initial setup?

    I didn't handle the initial installation of Wiz directly; that task fell to the operations team responsible for deploying security tools. However, from what I gather, integrating Wiz into the environment is not complex. It primarily requires the creation of a service account with sufficient permissions for Wiz to access necessary resources, making the overall integration process straightforward. Challenges might arise from organizational dynamics when persuading stakeholders, but technically, the setup doesn't appear to be cumbersome.

    What about the implementation team?

    Many people participated in the POC phase with Wiz, involving different teams such as the operational team for deployment and others handling various security dimensions. Many teams contributed during the POC phase., focusing primarily on the security specialists without including end users.

    What was our ROI?

    I would have appreciated providing a more specific return on investment metric for Wiz, but since my experience with it is based on a POC without full implementation, I cannot precisely track its impact on time or resource savings. It hasn't been operationalized fully yet in our organization.

    What other advice do I have?

    My understanding of Wiz's pricing suggests it's not cheap. While I may not have direct involvement in pricing discussions due to different teams managing purchasing decisions, feedback indicates that Wiz is among the most expensive tools available. Though there's likely room for adjustment in pricing, it should be noted that, compared to tools such as Microsoft Defender for Cloud , which scales according to subscriptions, Wiz's pricing can be significantly higher when supporting multiple products within larger organizations.

    Wiz was implemented as a POC, and while there were many subscriptions linked, I can share examples of its usage. For instance, when Log4j vulnerabilities emerged several years ago, we managed to quickly create a report through the Wiz dashboard, enabling us to identify all workloads impacted by a critical CVE. With resource tagging for ownership, this helped us reach out to the relevant individuals responsible. Although Wiz offers an option for service integrations such as Jira  for issue creation if implemented fully, our approach was manual report generation, where we exported findings and alerted personnel to maintain a zero-issues status.

    I would rate this review a 9 out of 10 overall.

    Marcel Velica

    Unified cloud visibility has transformed our risk prioritization and reduced alert fatigue while improving collaboration across security and DevSecOps teams

    Reviewed on Nov 29, 2025
    Review from a verified AWS customer

    What is our primary use case?

    My main use case for Wiz  includes utilizing Wiz Code , Wiz Defend , and Wiz  Cloud Security Posture Management.

    A quick specific example of how I use Wiz Cloud Security Posture Management in my day-to-day work is analyzing all the issues we see within the cloud and infrastructure as a code over our SOC team and security engineering.

    I have been using Wiz during these years and think it is a great product; I can review in depth when the need is being requested, and I have been doing POCs of other vendors out there compared with Wiz.

    I did create a custom dashboard in Wiz, and my experience with it is that it works well, has a flexible widget system, good query-based customization, and easy cloning for multi-team environments, but it could work better with limited visualization types.

    Wiz runtime sensor has helped in identifying active threats more effectively compared to previous solutions by providing increased visibility and accuracy, especially when correlating runtime behavior with cloud posture; it offers better context around runtime activity, faster detection of critical threats, improved detection accuracy, increased visibility across assets we previously missed, and stronger support for incident response, with the overall impact rated 10 out of 10.

    Before adopting Wiz, we relied on multiple disconnected tools for CSPM, vulnerability scanning, and infrastructure as a code review, which each provided partial visibility; Wiz replaced most of these functions with one unified security graph that brings together configuration, risk, identity, workload vulnerability, data sensitivity, and exposure path in one way.

    What is most valuable?

    The standout features of Wiz that make it valuable for me include good multi-cloud environment support, data governance, shadow IT detection, DevSecOps  governance, automation, level reporting, threat detection, and good infrastructure detection.

    Wiz has positively impacted my organization by implementing zero trust authorization, providing good reporting that shows the top attack path, critical assets, overall risk posture, and demonstrating AI and ML workload capabilities towards my team, as well as good infrastructure detection and vulnerability detection accuracy with security posture management at massive scale and identity exposure. There is a massive reduction in risk exposure, immediate visibility across the entire cloud estate, reduced noise and better prioritization, stronger DevSecOps  collaboration, continuous compliance instead of ad hoc panic, faster incident response with real context, significant cost savings through tool consolidation, and stronger AI and data governance.

    What needs improvement?

    Wiz can be improved with better maturity in code scanning and developer workflows, expanding secret detection to full lifecycle management, stronger IAM  across multi-account environments, more transparent attack path scoring and risk modeling, improved AI and ML security scanning, reduced false positives in runtime threat detection, more fine-grained access control and tenant separation, and better integration for serverless workloads.

    For how long have I used the solution?

    I have been using Wiz for around two years.

    What do I think about the stability of the solution?

    In my experience, Wiz is very stable.

    What do I think about the scalability of the solution?

    Wiz is very scalable.

    How are customer service and support?

    I do use Wiz's post-sale support services, and I am improving every quarter the performance of the tool with their assistance.

    The customer support for Wiz is very good.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    I have evaluated multiple solutions before Wiz, including Palo Alto Prisma Cloud, Orca Security , Lacework , Check Point, Qualys cloud solution, Snyk , Checkmarx, and other DevSecOps platforms.

    What was our ROI?

    I have seen a return on investment with Wiz by reducing our budget spent on other tools, saving time, and needing fewer employees.

    Wiz has reduced alert fatigue in my organization by around 90% over a given time period.

    What's my experience with pricing, setup cost, and licensing?

    My experience with pricing, setup cost, and licensing for Wiz was through an RFP where they offered us a good price, and the licensing was a flexible solution based on our business.

    What other advice do I have?

    My advice for others looking into using Wiz is to try it not just as another security tool, but as a foundational visibility and risk prioritization platform for your entire cloud environment; to get the full value, you need to think strategically about adoption, ownership, and cross-team alignment. I would rate this review as a 9 out of 10.

    Which deployment model are you using for this solution?

    Hybrid Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Financial Services

    Comprehensive Multi-Cloud Analysis and Posture Management

    Reviewed on Nov 27, 2025
    Review provided by G2
    What do you like best about the product?
    Clean, clear interface, and thorough context aware analysis of our multi-cloud environment. Risk analysis of our environment, and trusted / verified identification of vulnerabilities.
    What do you dislike about the product?
    It is pretty expensive, but we have been able to decommission other services, as these are adequately covered by Wiz.
    What problems is the product solving and how is that benefiting you?
    Getting a clear and concise understanding of the risk posture and vulnerabilities in our multi cloud configurations. Identifying vulnerabilities, and configuration issues that we trust and rely upon. Clear dashboarding and reporting capabilities.
    Financial Services

    Unified Multi-Cloud Security with AI-Driven Features

    Reviewed on Nov 25, 2025
    Review provided by G2
    What do you like best about the product?
    The platform offers a multi-cloud strategy, providing unified visibility across Azure, OCI, and Kubernetes environments. Its risk-based prioritization ensures that remediation efforts are directed toward the most critical attack paths, rather than addressing isolated issues. Additionally, it is designed with future-ready security in mind, featuring AI-driven security posture management and integration with ServiceNow to enable automated workflows.
    What do you dislike about the product?
    The alert noise generated at scale can be overwhelming for smaller teams, making careful fine-tuning necessary. Additionally, the current Wiz connectors lack support for ingesting real-time threats into SIEM tools, which can be a limitation. There is also a learning curve involved in mastering the platform's extensive features. Furthermore, the pricing is quite high, especially for access to the advanced feature set.
    What problems is the product solving and how is that benefiting you?
    Unified visibility into our cloud workloads, along with risk-based prioritization, helps us address any misconfigurations effectively.
    Antwon L.

    Unmatched Cloud Visibility and Seamless Jira Integration

    Reviewed on Nov 25, 2025
    Review provided by G2
    What do you like best about the product?
    What I like best about Wiz is the insight visibility and overview of issues and vulnerabilities within a cloud environment. Being able to not only track the primary resource of each individual issue but to also be able to view that in a security graph at a very high level. This type of insight capabilities helps users like me understand the full history of the issue as well as the different access points. Also being able to integrate these issues/vulnerabilities directly into Jira for direct progress tracking improves the workflow of solving them within a timely manner.
    What do you dislike about the product?
    The only downside I have for Wiz is that it can give a ton of information and telemetry on your environment all at once. Which can seem kinda overwhelming when first onboarding Wiz because a user may not know exactly what areas to search for in Wiz, and as a result it can take some time to understand.
    What problems is the product solving and how is that benefiting you?
    Wiz is solving the gaps of public exposure and vulnerabilities that our cloud environment has had in the past. That directly benefits me by giving my team more visibility into our cloud environments security posture overall, and knowing that I'm taking the correct steps into making our cloud environment as secure as possible.
    View all reviews