Listing Thumbnail

    WIZ Cloud Infrastructure Security Platform

     Info
    Sold by: Wiz 
    Deployed on AWS
    Free Trial
    Vendor Insights
    AWS Free Tier
    Wiz provides an entirely new approach to cloud security that for the first time identifies the actual risks hidden in your cloud infrastructure.
    4.7

    Overview

    Wiz performs a deep assessment of your entire cloud and then correlates a vast number of security signals to trace the real infiltration vectors that attackers can use to break in. Wiz also gives you the tools to bring your DevOps and development teams into the process to fix these risks, creating a culture of security in your cloud operations that results in a stronger, more secure cloud. For more information visit: https://www.wiz.io 

    Wiz provides custom pricing for customers via Private Offer. Please contact marketplace@wiz.io  for a better understanding of our pricing model and products.

    Highlights

    • Covers every resource across your full cloud stack, multi-cloud environment using a 100% API approach that deploys in minutes.
    • Models overlapping cloud policies, configurations, and compensating controls that interact in ways that are often unpredictable to calculate their end result.
    • Maps all of the issues in your cloud together in a single graph database, revealing which of them combined pose the greatest risk.

    Details

    Sold by

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Trust Center

    Trust Center
    Access real-time vendor security and compliance information through their Trust Center powered by Drata or Vanta. Review certifications and security standards before purchase.

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Vendor Insights

     Info
    Skip the manual risk assessment. Get verified and regularly updated security info on this product with Vendor Insights.
    Security credentials achieved
    (7)

    Pricing

    Free trial

    Try this product free according to the free trial terms set by the vendor.

    WIZ Cloud Infrastructure Security Platform

     Info
    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (5)

     Info
    Dimension
    Description
    Cost/12 months
    Wiz Essential
    Protect 100 cloud workloads
    $24,000.00
    Wiz Advanced
    Protect 100 cloud workloads
    $38,000.00
    Wiz Sensor
    100 Wiz Sensors. Add-on for Wiz Advanced
    $28,000.00
    Wiz Code
    100 Wiz Code Licenses. Add-on for Wiz Cloud
    $58,500.00
    Wiz Defend
    Ingest 300 GBs of logs per month. Add-on for Wiz Advanced
    $18,000.00

    Vendor refund policy

    Please contact us at info@wiz.io 

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    Vendor support

    Wiz provides custom pricing for customers via Private Offer. Please contact marketplace@wiz.io  for a better understanding of our pricing model and products. tel:+01-240.823.5670

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    10
    In Application Development, Continuous Integration and Continuous Delivery, Security
    Top
    10
    In Vulnerability and Patch Management, Data Governance
    Top
    25
    In Observability, Software Development

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Multi-Cloud Resource Coverage
    Covers every resource across the full cloud stack in multi-cloud environments using a 100% API approach with deployment in minutes.
    Cloud Policy and Configuration Analysis
    Models overlapping cloud policies, configurations, and compensating controls to calculate their combined end result.
    Risk Correlation and Visualization
    Maps all issues in the cloud infrastructure together in a single graph database to identify which combined issues pose the greatest risk.
    Security Signal Correlation
    Correlates a vast number of security signals to trace real infiltration vectors that attackers can exploit.
    DevOps and Development Team Integration
    Provides tools to integrate DevOps and development teams into the security risk remediation process.
    Attack Surface Management
    Aggregates comprehensive attack surface visibility across hybrid environments with external attack surface scans to provide 360-degree view of entire attack surface
    Vulnerability Management
    Delivers complete visibility across on-premise and remote endpoints to identify, communicate, and remediate vulnerabilities, misconfigurations, and risks
    Cloud Security
    Provides code-to-cloud protection for cloud-native applications with seamless CI/CD pipeline integration and agentless risk assessment based on reachability, exploitability, and potential impact
    Next-Generation SIEM and XDR
    Delivers accelerated detection and response with SaaS deployment, intuitive interface, out-of-the-box detections informed by MDR SOC, and built-in automation capabilities
    Threat Intelligence
    Delivers high-fidelity actionable threat intelligence infused with proprietary threat and vulnerability research from Rapid7 Labs and community-driven tools
    Offensive Security Engine
    Simulates external exploits to produce Verified Exploit Paths for prioritizing exposures that are reachable by outside attackers and reducing cloud attack surface.
    Cloud Security Posture Management
    Continuously monitors and manages security of AWS configurations to prevent public exposure and ensure compliance.
    Secrets Scanning
    Identifies more than 750 types of secrets across public and private repositories.
    Cloud Infrastructure Entitlements Management
    Detects and manages excessive or unused permissions to mitigate the risk of privilege escalation.
    Real-Time Malware Detection
    Detects malware including zero-days in milliseconds with scanning performed directly in cloud environment for object storage services like Amazon S3 and file storage services.

    Security credentials

     Info
    Validated by AWS Marketplace
    FedRAMP
    GDPR
    HIPAA
    ISO/IEC 27001
    PCI DSS
    SOC 2 Type 2
    No security profile
    No security profile

    Contract

     Info
    Standard contract
    No
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4.7
    828 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    82%
    17%
    1%
    0%
    0%
    24 AWS reviews
    |
    804 external reviews
    External reviews are from G2  and PeerSpot .
    Education Management

    Actionable, Risk-Based Cloud Visibility with Strong Prioritization and AI Insights

    Reviewed on May 29, 2026
    Review provided by G2
    What do you like best about the product?
    What I like best about Wiz is its ability to provide risk-based visibility across our cloud environment in a way that is actionable for both security and engineering teams.

    The most valuable aspect is the contextual risk prioritization. Rather than managing large volumes of findings, Wiz helps us focus on the exposures that matter most and drive remediation where it has the greatest impact.

    The platform is intuitive, scales well, and provides strong executive-level visibility into cloud risk. We've also found the AI capabilities helpful in accelerating investigations and understanding complex attack paths and security findings.
    What do you dislike about the product?
    As with any mature security platform, there is a significant breadth of functionality, which can create a learning curve for new users. While the platform does a strong job of contextualizing risk, some of the more advanced capabilities and reporting options could be simplified further to accelerate adoption across broader technical teams.

    As our cloud environment continues to evolve, I would also welcome continued investment in AI-driven recommendations and automation to further reduce investigation and remediation effort. These are relatively minor considerations, however, compared to the overall value the platform delivers.
    What problems is the product solving and how is that benefiting you?
    Wiz helps us address one of the biggest cloud security challenges: gaining clear visibility into risk across a rapidly evolving cloud environment while enabling teams to move quickly.

    Before Wiz, it was more difficult to correlate vulnerabilities, misconfigurations, exposed assets, and identity risks to understand which issues required immediate attention. Wiz provides the context needed to prioritize remediation based on actual risk, improving collaboration between security and engineering teams and allowing us to focus resources where they have the greatest impact.

    From a business perspective, this has improved our ability to manage cloud risk at scale, strengthen our security posture, and provide leadership with better visibility into our overall risk landscape. The result is a more efficient and risk-informed approach to cloud security without slowing down innovation.
    Mubasshir Quadri

    Cloud risks have become transparent and vulnerability management is now streamlined

    Reviewed on May 27, 2026
    Review from a verified AWS customer

    What is our primary use case?

    I basically use it for vulnerability management, so from an admin's perspective, I am using it as an actual user of Wiz . It is for vulnerability management majorly, and to apply or review the compliances of the cloud environment.

    How has it helped my organization?

    Wiz  helps to consolidate our tools. Wiz helps to identify active threats more effectively as it does active scanning on workloads, keeps looking into logs and images of virtual machines, and upon detecting threats, it checks possible connections through events and logs, giving visibility into where the issue started and exactly where it is.

    Wiz helps to achieve zero criticals in its issue queues. Wiz reduces alert fatigue overall, but there is a learning curve; out of the box, it may increase noise if there isn't a proper architecture in place.

    Wiz makes cloud security visibility clear for stakeholders, allowing them to understand risk posture, and does that really well. It creates a sense of ownership, as risk factors are presented, enabling anyone, including non-security and non-engineering teams, to use the tool if they are interested.

    What is most valuable?

    The biggest advantages of Wiz are that we can monitor multiple environments, as it has the capability to monitor multi-cloud models or architectures, providing visibility on a single page or tool. It also has AI integrations, so if you are finding a zero-day issue, you can calculate the risk score of that particular product and utilize that score to prioritize that particular CVE. If you are unsure about the resolution, Wiz also provides solutions and can craft custom PowerShell scripts to resolve a particular issue, all within the same tool, so you do not have to look elsewhere for solutions.

    Wiz only provides visibility; if you want to take any actions, Wiz requires your consent to do it, so it does not automatically fix issues until you provide feedback.

    We do have Wiz Code , but it is only for visibility, and we have not integrated it into our CI/CD pipelines yet, as it just gives us the library views and reports on DevOps content.

    What needs improvement?

    An area of improvement is that there is a lot of data inside Wiz and the naming is confusing, as similar categories for vulnerabilities and issues sometimes duplicate issues across resources, which can be hectic. While it doesn't cost much in terms of workloads, larger environments may incur higher costs based on architecture, and Wiz does not provide pre-configured reports but rather a dashboard requiring access to the tool.

    For how long have I used the solution?

    I am using Wiz for the last three years.

    What do I think about the stability of the solution?

    Wiz is stable; aside from the mentioned cons, there are no other issues from the tool's perspective, so it is about 99% stable.

    What do I think about the scalability of the solution?

    There is no issue with scalability; depending on architecture, you can scale Wiz anytime, as it has ready-to-deploy workloads utilizing cloud capabilities.

    How are customer service and support?

    Technical support is quite good; they help with configuration, cyber advisory, and provide support for any major changes needed.

    Which solution did I use previously and why did I switch?

    I have worked with Prisma, which is Palo Alto's CSPM, and Azure  Cloud Security tools.

    How was the initial setup?

    Deployment for Wiz is not complex; various deployment types exist depending on the desired approach, primarily requiring keys and registrations to connect to environments, though installing workloads can be complicated.

    What about the implementation team?

    We are not using post-sales support, just the regular support for major configuration-related issues.

    What was our ROI?

    Wiz is worth the investment, and if everything is properly configured, it definitely offers value for money. I would say around 80% in ROI benefits. That is in terms of money and time; doing everything manually would take a lot of work and effort, and Wiz reduces both the workload and the need for manual thinking and human feedback.

    What's my experience with pricing, setup cost, and licensing?

    Wiz is fairly priced compared to competitors and fits well within a low budget. Wiz is less expensive than Microsoft and Palo Alto.

    Which other solutions did I evaluate?

    This particular integration of AI Security  Posture Management is kind of new, introduced in one or two years, and for customers who have integrated their own LLMs or opted for special Azure  or AWS  Bedrock services, it is useful as it lets you know about security-related risks and provides visibility around AI-specific resources in the cloud, grouping risk factors, which helps present details in meetings.

    The current AI integration makes Wiz good for those not using on-premises or other environments, but proprietary cloud tools like Azure or AWS  excel in features and ease of deployment.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    Vikram Chakravarthy

    Contextual risk insights have transformed how our teams prioritize and remediate cloud exposures

    Reviewed on May 26, 2026
    Review from a verified AWS customer

    What is our primary use case?

    Wiz  is primarily used to identify risks, assert exposed workloads, identify publicly exposed resources, and prioritize vulnerabilities in our cloud environment. The main use case for Wiz  revolves around cloud security posture visibility, risk prioritization, vulnerability exposure management, misconfiguration detection, and identifying toxic combinations of risks in our cloud environments.

    Our main use case for Wiz is contextual prioritization. In many environments, there are thousands or millions of vulnerabilities, but not all are equally important. Wiz helps reduce noise by enabling security teams to focus on exploitable and high-impact risks first.

    What is most valuable?

    One of the best features of Wiz, in my opinion, is risk prioritization and the context for visibility. Another major strength is its cloud posture visibility across environments, supporting multiple cloud environments. The attack path visualization and ability to correlate vulnerabilities, exposure, identities, and permissions into a single risk view are very helpful for our security teams.

    In our day-to-day work, the contextual prioritization feature reduces our investigation effort because analysts do not need to perform manual correlations related to vulnerabilities, exposure, or cloud asset permissions. Instead of reviewing thousands of alerts individually, the team can focus on high-priority risks where exposure and business impact are clearer. Another useful aspect is visibility across multi-cloud environments and the centralized posture management, which helps our team understand risk in one place instead of depending on fragmented visibility.

    Wiz helps us by identifying a publicly exposed cloud asset with critical vulnerabilities and permission-related risks. Instead of reviewing findings separately, Wiz provides contextual visibility that shows which issues were internet exposed, whether they had vulnerabilities, and the high risks from a business perspective, which accelerates our prioritization remediation instead of treating every vulnerability equally.

    Wiz improves efficiency because remediation teams receive more context about why something matters. Instead of only seeing a vulnerability, teams can understand the exposure, permissions, affected assets, and the business relevance. The biggest impact Wiz has had on our organization is improved visibility and better prioritization, as previously mentioned. The security teams in our environment are able to focus on meaningful cloud risks faster rather than spending too much time manually reviewing low-priority findings.

    Wiz allows us to consolidate tools, meaning we can use a single tool for vulnerability management, risk analysis, and threat management, which the SOC team utilizes. It is a flexible tool, enabling every team to use Wiz to detect and defend their organizational posture. On the consolidation aspect, Wiz integrates multiple tools; for example, we have integrated Microsoft Teams  and ServiceNow , allowing us to create tickets directly using a single tool and send notifications via Teams or Slack.

    Wiz's runtime sensor provides visibility across multiple cloud environments, including AWS , Azure , GCP , and Oracle. It helps us prioritize vulnerabilities by discovering newly identified assets or vulnerabilities and has different signatures and policies compared to other CSPM tools, which proves to be very helpful.

    What needs improvement?

    One important area for improvement in Wiz could be customization and reporting flexibility. Sometimes organizations want deeper tailoring based on their internal workflows and governance requirements. If we can have customization for reports and dashboards, it will be helpful.

    Reporting  and dashboard customization can improve further, especially for leadership reporting that can be highly customized to meet specific workflows.

    For how long have I used the solution?

    I have been working in cybersecurity, particularly on vulnerability management-related tasks for around six years.

    What do I think about the stability of the solution?

    Wiz has been stable for cloud visibility and posture monitoring activities.

    What do I think about the scalability of the solution?

    Wiz scales well for our enterprise cloud environment and growing workloads because visibility requirements increase significantly in a cloud-first environment.

    How are customer service and support?

    The customer support experience typically depends on the complexity of the issues. When we raise a ticket with the support team, the deployment is handled well, and the support is generally good.

    Which solution did I use previously and why did I switch?

    We have used McAfee MVISION in the past. As we expanded our cloud, we switched to Wiz because it offers more visibility for our fragmented security approach.

    What was our ROI?

    We see a return on investment primarily from improved prioritization and reduced investigation effort. Instead of spending time on thousands of findings, teams can focus on the highest risk exposures, which improves remediation efficiency.

    Which other solutions did I evaluate?

    We compared Wiz with other CNAPP  and CSPM solutions based on visibility, prioritization, cloud integration, and operational simplicity.

    What other advice do I have?

    My advice for others looking to use Wiz is to first understand their cloud visibility gaps. If an organization struggles with prioritization, cloud posture visibility, or encounters too many findings with little context, Wiz can provide strong value in addressing those issues. I rate this product 9 out of 10.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Nigel H.

    Wiz Leads Cloud Security with Powerful Insights and an Intuitive UI

    Reviewed on May 24, 2026
    Review provided by G2
    What do you like best about the product?
    Wiz is an incredible company. Their solutions have hit the right mark between visual representation of data, and actual technical insights. I've been incredibly impressed by it's balance of usability and powerful information. I've used a few different providers in the cloud security space, and Wiz is definately the leader for me.
    What do you dislike about the product?
    It can sometimes be hard to understand what new features I should be exploring. They incrementally improve the products at a fast rate, and it can be hard to keep up.
    What problems is the product solving and how is that benefiting you?
    Full cloud security coverage across our multiple cloud platforms.
    Hospital & Health Care

    Unified, Agentless Cloud Security Visibility That Helps Us Prioritize Risk

    Reviewed on May 23, 2026
    Review provided by G2
    What do you like best about the product?
    Wiz has made a big difference in how we approach cloud security. What I like most is how easy it is to get a complete, unified view of everything across our cloud environment without needing to deploy agents everywhere. The platform does a great job of connecting the dots between vulnerabilities, misconfigurations, and exposures, so instead of chasing a flood of alerts, we can focus on the issues that actually pose real risk. That context has really helped us prioritize and move faster when it comes to remediation.
    What do you dislike about the product?
    The platform can feel a bit overwhelming at first, and there’s a learning curve to fully understand the depth of features and data.

    Pricing can be on the higher side to similar tools.
    What problems is the product solving and how is that benefiting you?
    Wiz is helping us solve the challenge of getting clear, end-to-end visibility across our cloud environment. Instead of dealing with multiple tools and a high volume of disconnected alerts, Wiz brings everything into a single platform.

    The biggest benefit is speed and efficiency. Our team spends less time chasing noise and more time focusing on meaningful remediation. It’s also improved collaboration across security and engineering teams since everyone is working from the same data and insights, which helps us address issues faster and more effectively.
    View all reviews