Listing Thumbnail

    WIZ Cloud Infrastructure Security Platform

     Info
    Sold by: Wiz 
    Deployed on AWS
    Free Trial
    Vendor Insights
    Wiz provides an entirely new approach to cloud security that for the first time identifies the actual risks hidden in your cloud infrastructure.

    Overview

    Wiz performs a deep assessment of your entire cloud and then correlates a vast number of security signals to trace the real infiltration vectors that attackers can use to break in. Wiz also gives you the tools to bring your DevOps and development teams into the process to fix these risks, creating a culture of security in your cloud operations that results in a stronger, more secure cloud. For more information visit: https://www.wiz.io 

    *Wiz provides custom pricing for customers via Private Offer. Please contact marketplace@wiz.io  for a better understanding of our pricing model and products.

    Highlights

    • Covers every resource across your full cloud stack, multi-cloud environment using a 100% API approach that deploys in minutes.
    • Models overlapping cloud policies, configurations, and compensating controls that interact in ways that are often unpredictable to calculate their end result.
    • Maps all of the issues in your cloud together in a single graph database, revealing which of them combined pose the greatest risk.

    Details

    Sold by

    Delivery method

    Deployed on AWS

    Unlock automation with AI agent solutions

    Fast-track AI initiatives with agents, tools, and solutions from AWS Partners.
    AI Agents

    Features and programs

    Trust Center

    Trust Center
    Access real-time vendor security and compliance information through their Trust Center powered by Drata. Review certifications and security standards before purchase.

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Vendor Insights

     Info
    Skip the manual risk assessment. Get verified and regularly updated security info on this product with Vendor Insights.
    Security credentials achieved
    (7)

    Pricing

    Free trial

    Try this product free according to the free trial terms set by the vendor.

    WIZ Cloud Infrastructure Security Platform

     Info
    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (5)

     Info
    Dimension
    Description
    Cost/12 months
    Wiz Essential
    Protect 100 cloud workloads
    $24,000.00
    Wiz Advanced
    Protect 100 cloud workloads
    $38,000.00
    Wiz Sensor
    100 Wiz Sensors. Add-on for Wiz Advanced
    $28,000.00
    Wiz Code
    100 Wiz Code Licenses. Add-on for Wiz Cloud
    $58,500.00
    Wiz Defend
    Ingest 300 GBs of logs per month. Add-on for Wiz Advanced
    $18,000.00

    Vendor refund policy

    Please contact us at info@wiz.io 

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    We'd like to hear your feedback and ideas on how to improve this page.
    We'd like to hear your feedback and ideas on how to improve this page.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    Vendor support

    Wiz provides custom pricing for customers via Private Offer. Please contact marketplace@wiz.io  for a better understanding of our pricing model and products. tel:+01-240.823.5670

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    10
    In Application Development, Continuous Integration and Continuous Delivery, Security
    Top
    10
    In Vulnerability and Patch Management, Data Governance
    Top
    25
    In Observability, Software Development

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Cloud Infrastructure Scanning
    "Performs comprehensive assessment across entire cloud infrastructure using 100% API-based approach with rapid deployment"
    Risk Correlation Mechanism
    "Correlates multiple security signals to trace potential infiltration vectors and identify complex attack paths"
    Multi-Cloud Support
    "Provides unified security coverage across diverse cloud environments and resource types"
    Policy Interaction Modeling
    "Analyzes overlapping cloud policies, configurations, and compensating controls to predict complex security interactions"
    Graph-Based Visualization
    "Generates comprehensive cloud security mapping using graph database to reveal interconnected security issues and risk relationships"
    Attack Surface Management
    Aggregates comprehensive attack surface visibility across hybrid environments with external attack surface scans to build a dynamic, 360-degree view
    Cloud Security
    Provides code-to-cloud protection for cloud-native applications with seamless CI/CD pipeline integration and real-time, agentless risk assessment
    Threat Intelligence
    Delivers high-fidelity, actionable threat intelligence sourced from proprietary threat and vulnerability research with community-driven tools
    Vulnerability Management
    Offers complete visibility across on-premise and remote endpoints to identify, communicate, and remediate vulnerabilities and misconfigurations
    Security Automation
    Enables acceleration and streamlining of time-intensive processes through customizable workflows and plugins without requiring coding expertise
    Cloud Native Security Engine
    Agentless Cloud Native Application Protection Platform (CNAPP) with a unique offensive security engine for comprehensive cloud security
    Multi-Cloud Asset Management
    Includes asset inventory, graph explorer, and security posture management across public and private cloud environments
    Advanced Threat Detection
    Real-time AI-powered detection and prevention of runtime threats including ransomware, zero-days, and fileless attacks
    Infrastructure Security Scanning
    Comprehensive scanning capabilities including Infrastructure as Code (IaC), secrets scanning, and vulnerability assessment
    Cloud Object Storage Protection
    AI-powered malware detection for cloud object storage with millisecond scanning and automated quarantine capabilities

    Security credentials

     Info
    Validated by AWS Marketplace
    FedRAMP
    GDPR
    HIPAA
    ISO/IEC 27001
    PCI DSS
    SOC 2 Type 2
    No security profile
    No security profile

    Contract

     Info
    Standard contract
    No
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4
    2 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    0%
    100%
    0%
    0%
    0%
    2 AWS reviews
    |
    715 external reviews
    Star ratings include only reviews from verified AWS customers. External reviews can also include a star rating, but star ratings from external reviews are not averaged in with the AWS customer star ratings.
    MatthewSnyder

    Accelerates decision making and reduces alert fatigue with smart event consolidation

    Reviewed on Oct 01, 2025
    Review provided by PeerSpot

    How has it helped my organization?

    Wiz  allows us to get a view into what's happening in our cloud environments, helping us see the gaps, how things are connected, and it aids in CVE monitoring, especially during incident response as we're able to look at what that environment or host might look like, how it connects, and how big of an issue this might be versus how small it could be, along with other indications gathered from Wiz 's reporting that help us better understand what's happening and how it might have all started.

    We have created a couple of custom dashboards and charts for Wiz to help keep track of specific environments. One example is when we were looking for certain types of activities; it allowed us to create a singular place to see the events in the subscriptions of interest that needed remediation, bringing it together quickly, allowing us to take action and track progress as things were fixed.

    Zero Criticals is the dream for us; that's our goal, and we've made good progress, with Wiz allowing us to see everything together in an easy-to-understand way, giving us a path to have conversations with the business about what can be done from policy or user education standpoints to prevent recurring issues that need remediation, resulting in improved numbers and positively impacting our approach over time.

    Wiz has enabled us to consolidate tools. Having multiple cloud providers presents challenges as each has its own versions of security products, leading to the problem of needing to monitor three different tools, which do different things. Wiz helps standardize alerting and responses while allowing us to fill in the gaps since many tools don't do CVE analysis and reporting, resulting in time savings and less effort in creating detections to fill those gaps.

    Wiz helps us consolidate our alerting process. I am a strong advocate for avoiding alerts that do not add value to our environment. It's especially crucial to eliminate alerts that are single-instance or one-off occurrences. Instead, we need detections that tell a comprehensive story. Additionally, we require a way to drill down into these detections to understand them fully. Wiz has surpassed other tools across the multi-cloud landscape in alerting us to the issues that truly matter. It presents the information in a manner that allows us to address and remediate those issues effectively.

    Wiz also includes excellent remediation steps within the detection, helping us understand what is happening. Our SOC team comprises individuals with varying levels of seniority and experience in the cloud, which can present challenges for skill development. Therefore, it is vital that we don’t just receive a barrage of noise in our SOC; we need information that clarifies what actually happened. Being able to communicate to the business how to resolve these issues is extremely important to us. Wiz has filled the gaps where other tools excelled in one or two areas but failed to provide a complete picture.

    What is most valuable?

    My favorite feature of Wiz is how it gathers information together; instead of generating a thousand independent signals, it rolls that up and shows you within that environment how all the different toxic combinations contribute to a critical alert, making it an issue worth responding to, unlike many other vendors or tools that show singular things which may appear small, but when looked at holistically, are actually part of a much bigger issue needing attention.

    Wiz has significantly reduced alert fatigue in our organization. One of the key functions is that it groups together elements that can form toxic combinations. Instead of treating a policy violation and a critical CVE as separate issues that would generate two different alerts requiring two different tools, it consolidates them into a single event. This allows us to identify problems more effectively. For example, if I see a high or critical CVE alongside a policy misconfiguration tied to an account, I know I need to address both issues. This grouping enables us to take action rather than approaching it as a simple decision of whether or not to act on a single alert. Previously, I might see a policy issue and wonder if it’s significant enough to warrant attention. However, when these issues are combined, I can assess the full scope of what’s happening, allowing me to take appropriate action. I can also determine quickly whether something might be a false positive, preventing unnecessary investigations.With the critical issues we identify, we can confidently fix them and reach out to the right people without relying on a "hope" strategy or waiting for an hour of research to see if it turns into something actionable. Based on my experience with other tools, Wiz helps us bypass that frustrating process.

    What needs improvement?

    I believe they are on the right path. However, Wiz has a unique way of identifying issues. As part of its growth and maturity, I'm noticing that it is taking an approach where it not only detects problems but also provides solutions to fix them. This expansion into a more comprehensive ecosystem allows it to become a 360-degree product. Instead of just continuously pointing out findings and detections, it starts to integrate with existing solutions, reducing the cycle of repeated issues. We can learn from these mistakes, and ideally, they will only occur once, allowing us to address them effectively. I appreciate the continued growth in this partnership, as it aims to reduce the number of findings over time by tackling the root of the problem.

    One significant area for improvement would be increasing automation. While they excel at identifying issues, we need assistance in minimizing the human hours required for tasks. Ideally, the process would become more automated, allowing us to quickly respond with steps such as: we found an issue, reached out, and fixed it immediately. In cybersecurity, if it takes several hours to address a concern and a human attacker is present, that delay can lead to severe consequences. We need more immediate measures in our response strategies.

    For how long have I used the solution?

    I have been using Wiz for almost two years.

    What do I think about the stability of the solution?

    Regarding stability, I was pleasantly surprised by the performance of this SaaS provider. We haven't encountered any outages or issues with reports not running, finishing, or data being incomplete or inaccurate.

    What do I think about the scalability of the solution?

    Scalability is great. We haven't faced any problems. There were no requirements like, “once you get to this point, you have to do this or that.” We were simply able to connect our accounts, and during our last round, our environment quadrupled in size. We didn’t have to make any adjustments or configuration changes; it just accommodated the growth. Even as some environments scaled back down, the service scaled back down with us, which has been a great benefit.

    How are customer service and support?

    Regarding technical support, we haven't needed to contact them. All the questions and issues we encountered were addressed by our account team. It was very helpful not having to open a ticket and wait for assistance; our account team was knowledgeable about the tool and could provide immediate answers. This level of support was refreshing, as we didn’t have to deal with delays or uncertainty. Overall, we were very satisfied with the support we received.

    For support, I would rate them a ten out of ten. They have great documentation and excellent support from the account team, which reduces how much you have to rely on technical support. I've dealt with other tools where the account team couldn't answer any questions, and the only option was to open a ticket and wait, sometimes for a day or two, for someone to respond. However, with this service, we received answers immediately and at the level we needed. Additionally, we received plenty of training and education without having to pay for expensive classes. So, I would definitely give them a ten in that area.

    How would you rate customer service and support?

    Positive

    How was the initial setup?

    It was very easy to deploy. We were able to get everything set up quickly during a call with our Wiz account team. They walked us through the process, and once we connected the accounts, it was off and running. From that standpoint, it was great to easily tap into the different cloud providers. The experience was positive overall.

    After the initial setup, the team also assisted us with health checks to ensure everything was functioning properly. They provided feedback and helped us make any necessary adjustments to permissions so that the tool would work effectively.

    As for the setup time, we had a 30-minute call scheduled, and we managed to complete the setup within that timeframe. It mostly involved connecting the parent account and giving Wiz access to deploy the tool. After that, we were able to start viewing the results. So, in total, we spent about 10 to 15 minutes actually configuring it during that 30-minute window.

    What's my experience with pricing, setup cost, and licensing?

    I’m familiar with their pricing. I believe it aligns well with what we typically see for security tools. It’s not unreasonable or outrageous. They have a great product that works effectively and fulfills its intended purpose. I don’t think there’s anyone else out there offering the same level, scale, or efficiency. While their pricing may be a bit on the premium side, it also enables users to consolidate tools, which can offset some of those costs.

    Which other solutions did I evaluate?

    A significant alternative out there is AWS GuardDuty. It operates within a single scope, analyzing your logs and identifying signals of potential issues. However, this can lead to high alert fatigue because it focuses on individual events. Instead of grouping and triaging alerts, it may send you multiple separate notifications for a single host or device performing several actions.

    In addition, we've utilized scanners for Common Vulnerabilities and Exposures (CVEs) like Rapid7. This tool effectively scans for CVEs, but it requires thorough configuration, continuous monitoring of output, and the creation of reports to take necessary actions. This process is not on the same level as Wiz, which consolidates all of these tools into one platform.

    What other advice do I have?

    We haven't used Wiz Runtime Sensor; we've seen demos and it looks really cool, but it's not something we have implemented.

    I believe there isn't a perfect tool, but Wiz comes very close, continuously growing and expanding to add more value into its ecosystem, and I'm happy with it. I would rate Wiz a nine out of ten.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    reviewer2755878

    Helps eliminate critical issues and streamline threat investigation

    Reviewed on Sep 09, 2025
    Review provided by PeerSpot

    What is our primary use case?

    I use Wiz  for both my own company and other companies to detect and investigate vulnerabilities and any type of alerts that pop up. 

    What is most valuable?

    I am really enjoying the new Threat Detection that they have set up; it is pretty nice. I appreciate the way that it lays out the data.

    For some of my customers, I create custom dashboards, charts, or counters, and they're actually really helpful. It's quite easy. They have extensive technical documentation that guides you through the process. Additionally, there are short videos available in each section that demonstrate how to do things.

    Wiz  has helped my organization achieve zero criticals in its issue queues after a month. 

    What needs improvement?

    It would be better if, when you get an alert type, you are able to view the regex or alert logic without having to dig through all the different options; it is difficult to find where the alert logic is because you have to go to the investigations and then actually find and search for the individual alert. If they just showed the alert logic, that would be really nice. 

    Also, if there was an easier way for threats to convert those into issues rather than having to set up a custom rule to pull those in as issues, it would be great.

    For how long have I used the solution?

    I have been using Wiz for just under a year.

    What do I think about the stability of the solution?

    I have not seen any sort of instability with Wiz; I was curious how their SRE team works because I have not seen a single downtime.

    What do I think about the scalability of the solution?

    Wiz scales really efficiently; I have worked with some huge companies that have multiple clouds and thousands of workflows, and it all seems to work.

    How are customer service and support?

    We have account executive people that we talk to for help with Wiz. We talk to them sometimes when new features come out or when we see weird things for the first time. They provide help with writing either new regex alert queries or just helping us figure out how to do something with using the product. They are very helpful and very responsive, and if they cannot get you the answer, then they will find someone to help you; it has been as quick as a turnaround time of one business day, which is really good.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    I have used CrowdStrike, Prisma, and I think that Wiz is the best out of all of them. Wiz is good at conveying the information for the active threats. The way that it shows you is easier to understand as a human. It is about the same quality of detection, but the presentation is better.

    How was the initial setup?

    It's really easy. It's very user-friendly, and it's very intuitive.

    My team had Wiz set up already when I joined, but I have gone through the whole setup process myself; they let me reset it up. I found that to be pretty simple. It only took about an hour and a half to install Wiz because we do not have a super big system.

    Once you set up Wiz, it is good to go. As a security engineer, you need to maintain the alerts and keep that stuff moving. Once we have the system in place, I have not noticed it disconnect any of our accounts. It seems once you set it, it is good to go.

    What about the implementation team?

    One person can deploy Wiz; they just have to have the right access.

    What's my experience with pricing, setup cost, and licensing?

    I don't know how much we pay, but I do know that Wiz charges a lot. However, they're offering a good product, so it might be fair. I haven't seen the exact numbers.

    What other advice do I have?

    I would rate Wiz a 10 out of 10. I really like it.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    Avi L.

    A Game-Changer for Cloud Security team

    Reviewed on Sep 01, 2025
    Review provided by G2
    What do you like best about the product?
    What I like best about Wiz is its clear visibility across our entire cloud environment without requiring agents. The platform maps risks end-to-end — from infrastructure misconfigurations to vulnerabilities, secrets, and compliance gaps — in a single dashboard.

    For SecOps, it’s extremely valuable that Wiz prioritizes issues by context (e.g., exposed to the internet, contains sensitive data, exploitable path), so we don’t waste time chasing noise. Integrations with existing workflows (SIEM, ticketing, etc.) make it easy to operationalize findings.

    From an admin perspective, the ease of deployment and scalability stand out. It’s quick to onboard new accounts, and visibility is almost immediate, which is rare in this space.
    What do you dislike about the product?
    What I dislike about Wiz is that the platform is not yet truly unified in management. With the number of products and capabilities they’ve added, it feels like they could be consolidated better — today it’s more like managing three different consoles instead of a single pane of glass.

    The DSPM (Data Security Posture Management) capabilities are promising but still relatively immature compared to Wiz’s core strengths. Coverage is not as deep as I’d like, and it still needs more development to give us the same confidence we have with vulnerability and misconfiguration findings.

    In addition, the volume of findings can be overwhelming, especially early on, and it requires tuning and integrations to avoid alert fatigue. Wiz is improving here, but out-of-the-box prioritization can still surface too much noise for smaller teams.
    What problems is the product solving and how is that benefiting you?
    Wiz helps us address several critical areas in cloud security, including monitoring and analytics, detection and response, compliance, vulnerability management, exposure management, and DSPM. Providing agentless visibility across our cloud environment eliminates blind spots and gives our SecOps team clear insight into risks and misconfigurations.
    Its cloud detection and response features stand out because alerts are contextualized, allowing us to focus on real threats instead of noise.
    Continuous compliance checks against industry frameworks save significant time during audits, while vulnerability scanning and exposure management prioritize issues based on exploitability and exposure paths, so we can remediate what truly matters first.
    The DSPM capabilities are still maturing, but already help us locate sensitive data and highlight where it may be at risk, and help us to map most of our data.

    Benefits to Us:

    Time savings—Instead of manually correlating risks, Wiz shows the attack path in context, which accelerates the response.
    Risk reduction – Prioritized findings ensure our limited SecOps resources focus on the most dangerous issues first.
    Audit readiness – Compliance reporting is much faster and less painful.
    Operational efficiency – With Wiz’s agentless deployment, onboarding new cloud accounts takes minutes, not days.
    Alex P.

    Fantastic product and team!

    Reviewed on Aug 28, 2025
    Review provided by G2
    What do you like best about the product?
    Immediately gained actionable insight into our cloud security posture which was previously considered a 'security black hole'.

    The onboarding process was a breeze and the team we are working with know their stuff!

    It's very intuitive, even for someone with no prior devsecops experience.
    What do you dislike about the product?
    Not an issue with Wiz itself but we are still working on buy-in and utilization from all our devs on the Wiz Code component.
    What problems is the product solving and how is that benefiting you?
    Lack of visibility into cloud security posture. No dedicated DevSecOps staff.
    Financial Services

    Engineer-Friendly Cloud Risk Management

    Reviewed on Aug 28, 2025
    Review provided by G2
    What do you like best about the product?
    Wiz provides comprehensive visibility across AWS without agents (so really easy to get started). The security graph highlights risks by factoring in exposure, lateral movement, known vulnerabilities, so only the most relevant issues surface. This reduces false positives and alert fatigue compared to for example AWS native Security Hub. Dashboards, root cause analysis, and Terraform fix snippets make it engineer-friendly and actionable, not just a compliance tool.
    What do you dislike about the product?
    The platform can feel overwhelming at first due to the breadth of features and data. Role-based access and project scoping require careful setup to avoid visibility gaps.
    What problems is the product solving and how is that benefiting you?
    Wiz solves the lack of visibility across a complex AWS environment. It consolidates security findings, eliminates noise from false positives, and prioritizes risks based on exposure and business impact. This reduces alert fatigue, accelerates remediation, and frees engineers from manual triage. Also supports compliance audits (useful if you have yearly audits), and enables proactive risk reduction.
    View all reviews