Listing Thumbnail

    WIZ Cloud Infrastructure Security Platform

     Info
    Sold by: Wiz 
    Deployed on AWS
    Free Trial
    Vendor Insights
    AWS Free Tier
    Wiz provides an entirely new approach to cloud security that for the first time identifies the actual risks hidden in your cloud infrastructure.
    4.7

    Overview

    Wiz performs a deep assessment of your entire cloud and then correlates a vast number of security signals to trace the real infiltration vectors that attackers can use to break in. Wiz also gives you the tools to bring your DevOps and development teams into the process to fix these risks, creating a culture of security in your cloud operations that results in a stronger, more secure cloud. For more information visit: https://www.wiz.io 

    *Wiz provides custom pricing for customers via Private Offer. Please contact marketplace@wiz.io  for a better understanding of our pricing model and products.

    Highlights

    • Covers every resource across your full cloud stack, multi-cloud environment using a 100% API approach that deploys in minutes.
    • Models overlapping cloud policies, configurations, and compensating controls that interact in ways that are often unpredictable to calculate their end result.
    • Maps all of the issues in your cloud together in a single graph database, revealing which of them combined pose the greatest risk.

    Details

    Sold by

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Trust Center

    Trust Center
    Access real-time vendor security and compliance information through their Trust Center powered by Drata. Review certifications and security standards before purchase.

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Vendor Insights

     Info
    Skip the manual risk assessment. Get verified and regularly updated security info on this product with Vendor Insights.
    Security credentials achieved
    (7)

    Pricing

    Free trial

    Try this product free according to the free trial terms set by the vendor.

    WIZ Cloud Infrastructure Security Platform

     Info
    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (5)

     Info
    Dimension
    Description
    Cost/12 months
    Wiz Essential
    Protect 100 cloud workloads
    $24,000.00
    Wiz Advanced
    Protect 100 cloud workloads
    $38,000.00
    Wiz Sensor
    100 Wiz Sensors. Add-on for Wiz Advanced
    $28,000.00
    Wiz Code
    100 Wiz Code Licenses. Add-on for Wiz Cloud
    $58,500.00
    Wiz Defend
    Ingest 300 GBs of logs per month. Add-on for Wiz Advanced
    $18,000.00

    Vendor refund policy

    Please contact us at info@wiz.io 

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    We'd like to hear your feedback and ideas on how to improve this page.
    We'd like to hear your feedback and ideas on how to improve this page.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    Vendor support

    Wiz provides custom pricing for customers via Private Offer. Please contact marketplace@wiz.io  for a better understanding of our pricing model and products. tel:+01-240.823.5670

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    10
    In Application Development, Continuous Integration and Continuous Delivery, Security
    Top
    10
    In Vulnerability and Patch Management, Data Governance
    Top
    25
    In Observability, Software Development

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Cloud Infrastructure Scanning
    "Performs comprehensive assessment across entire cloud infrastructure using 100% API-based approach with rapid deployment"
    Risk Correlation Mechanism
    "Correlates multiple security signals to trace potential infiltration vectors and identify complex attack paths"
    Multi-Cloud Support
    "Provides unified security coverage across diverse cloud environments and resource types"
    Policy Interaction Modeling
    "Analyzes overlapping cloud policies, configurations, and compensating controls to predict complex security interactions"
    Graph-Based Visualization
    "Generates comprehensive cloud security mapping using graph database to reveal interconnected security issues and risk relationships"
    Attack Surface Management
    Aggregates comprehensive attack surface visibility across hybrid environments with external attack surface scans to build a dynamic, 360-degree view
    Cloud Security
    Provides code-to-cloud protection for cloud-native applications with seamless CI/CD pipeline integration and real-time, agentless risk assessment
    Threat Intelligence
    Delivers high-fidelity, actionable threat intelligence sourced from proprietary threat and vulnerability research with community-driven tools
    Vulnerability Management
    Offers complete visibility across on-premise and remote endpoints to identify, communicate, and remediate vulnerabilities and misconfigurations
    Security Automation
    Enables acceleration and streamlining of time-intensive processes through customizable workflows and plugins without requiring coding expertise
    Cloud Security Posture Management
    Continuous monitoring and management of cloud configurations to prevent public exposure and ensure compliance
    Infrastructure as Code Scanning
    Automated scanning and securing of infrastructure templates and images for secrets and vulnerabilities before deployment
    Threat Detection Mechanism
    AI-powered real-time detection and automated stopping of runtime threats including ransomware, zero-days, and fileless attacks
    Cloud Workload Protection
    Comprehensive security platform for servers, virtual machines, and containers across public and private cloud environments
    Cloud Object Storage Security
    Real-time malware detection and automated threat response for cloud storage services with millisecond scanning capabilities

    Security credentials

     Info
    Validated by AWS Marketplace
    FedRAMP
    GDPR
    HIPAA
    ISO/IEC 27001
    PCI DSS
    SOC 2 Type 2
    No security profile
    No security profile

    Contract

     Info
    Standard contract
    No
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4.7
    778 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    56%
    40%
    3%
    0%
    0%
    14 AWS reviews
    |
    764 external reviews
    External reviews are from G2  and PeerSpot .
    Jim H.

    Wiz Delivers Outstanding CSPM and Continuous Improvements

    Reviewed on Jan 13, 2026
    Review provided by G2
    What do you like best about the product?
    As a second-time customer of Wiz, I knew the CSPM was great and research told me it was still the best. This feature was even better than I remembered, as Wiz had not rested on their laurels and had continually improved over time! It has helped me get to zero critical issues in less than 6 months with the issue prioritisation and clear remedial steps which I can share with the teams responsible. No excuse for not having a well refined Jira, or not knowing what we really asking for - the details are in the language of the remediator, spoon-fed by Wiz!
    Now, we use it all the time to proactively monitor our systems, look for config or vulnerabilities, and whenever I see a new Critical or High issue we immediately jump on it to triage. This means we have got managing Critical config issues down to similar remediation timelines as a Critical security incident and indeed in most cases we treat them almost identically (urgent conf calls, drop tools and huddle to fix etc.).
    When it came to implementing Wiz, it was simply as quick as hooking up to our Cloud instances, providing the access, and sitting back to watch the fireworks. During the implementation the support was outstanding, and Wiz spent so much time with us and our different teams showing them how to use it, how simple it was to integrate with other tools, how we could extend visibility to the max, how to interpret the results, get good report data to the right people etc.. This operationalisation help ensure Wiz was used by multiple teams - although I think there's always room for even more engagement internally.
    After implementing the engagement didn't stop though, and we still have a regular call with our TAM who is always happy to demo to some new users, or to help tweak some settings or help with some report or other. I don't think we've ever found the limit of engagement and Wiz seems happy to provide whatever level of interaction we need to get where we want to go.
    What do you dislike about the product?
    Nothing to dislike, although of course I wish it could be cheaper :-)
    What problems is the product solving and how is that benefiting you?
    For us, it was that we have so many different cloud environments and flavours. By the nature of our service, we deliver stand-alone clouds, private clouds, different cloud vendors etc. for different products and regions and customers. This is complex and incredibly difficult to get an holistic view across them as CISO, let alone to prioritise and manage where the risks are across this disconnected landscape. Wiz pulls it all together into one window from which we can easily distribute the effort out to the teams responsible for those very different environments and provide a consistent level of detail and track in a consistent manner. This allows me to do a lot less chasing and a lot more governing. It simply makes the security team hugely more leveraged and able to span so much more than without. I can't even imagine how we'd do that without Wiz, and we'd be in a much less secure state, less able to identify and respond to immediate risks (config and vuln issues). Wiz solves this very thoroughly.
    Darin Hurd

    Cloud security has unified multi-cloud visibility and simplifies vulnerability management

    Reviewed on Jan 12, 2026
    Review from a verified AWS customer

    What is our primary use case?

    I have been using Wiz  for approximately three years in my career. Our first use case is Cloud Security Posture Management. We needed that because we are a multi-cloud company. We have most of our infrastructure in AWS , but we also have some in Azure  and some in GCP. So we needed a CSPM to cover all three environments.

    What is most valuable?

    The feature I appreciate most about Wiz  as a CSPM is the vulnerability detection and misconfiguration identification. It helps us to ensure that we know if there are misconfigured cloud workloads and what those are, as well as if there are vulnerabilities. That is one of the key value adds for us.

    What we have done is create a tool that is not just a security tool but is actually used by other teams. We have created dashboards for other teams, for product teams who are developing code. They can see their assets, or our cloud team or other teams that own different assets can view their own team's vulnerabilities and misconfigurations through per-team dashboards.

    For us, the value add when considering Wiz is that I would rather consolidate under fewer tools to get to a platform. This allows for alerts, administration, and dashboards to all be under one platform, simplifying the environment. It makes operations easier and ultimately enhances our ability to use the platform more effectively.

    What needs improvement?

    Wiz allows us to consolidate tools, particularly in vulnerability management. We used to use a technology called Tenable to do our vulnerability scans, not just on-prem but in the cloud, and we replaced Tenable with Wiz's capabilities as well as the capabilities of an endpoint protection technology we use called CrowdStrike.

    Regarding scalability, we have connected to all our cloud accounts and have never had any capacity or performance issues, so scalability really has not been a topic of conversation for us because we have never had any issues.

    I have contacted customer support for Wiz. They are aware of our discussions about it. We have talked about it during our quarterly business reviews.

    What do I think about the stability of the solution?

    I have never seen any instability with Wiz, such as lagging, crashing, or downtime.

    What do I think about the scalability of the solution?

    We have connected to all our cloud accounts and have never had any capacity or performance issues, so scalability really has not been a topic of conversation for us because we have never had any issues.

    How are customer service and support?

    I have contacted customer support for Wiz. They are aware of our discussions about it. We have talked about it during our quarterly business reviews.

    I am a few steps removed from the details about the support quality and speed, but my impression through the team and talking with the account team directly is that when we raise issues, they are addressed thoughtfully, professionally, and quickly. I do not think there have been any lingering support issues we have had. We have also surfaced feature requests or changes, and they have implemented those and rolled those out within a few weeks. Wiz does a good job of listening to the feedback of their customers and using that to help shape the platform.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    I have not used any alternatives to Wiz. Wiz was our choice; although we evaluated different technologies when we were looking for a CSPM, we went with Wiz, so we went from nothing to Wiz.

    How was the initial setup?

    The initial deployment of Wiz was easy from my point of view. Essentially, once we connected Wiz to our AWS  account, all the data starts to flow in and telemetry on our cloud assets, any vulnerabilities, and misconfigurations. So the dashboards light up with red, yellow, and green indicators. After deciding to go with Wiz, our proof of concept ended up becoming our production implementation, and we just expanded Wiz to more accounts, then to Azure  and GCP. So it was very easy.

    What about the implementation team?

    I do not know exactly how long it took to fully deploy to a working condition because it has been so long ago, but I will say that getting the visibility was in a matter of weeks to connect the accounts, probably within a week. Then it was a few months to build some of the dashboards and operationalize what we were seeing.

    What other advice do I have?

    Feature-wise, I cannot tell you that it is a bit expensive compared to its peers, but I do think the premium is worth it. One of the things that Wiz has done well is that there are no agents for the CSPM, at least from what we are doing. It is very easy to roll out, easy to configure, maintain, and generally it does what it says it does with few issues. We had more overhead and more issues with other competing CSPM platforms.

    From the team standpoint, I do not think Wiz requires much maintenance on our end because it is all cloud-based and Wiz does a great job of providing almost weekly updates. The ongoing maintenance itself of Wiz is low. We do have integrations which require some care and feeding. We have an integration with ServiceNow , but Wiz's ServiceNow  integration is not the best. I have been told there have been issues getting the data out of Wiz and plugged into ServiceNow effectively, so that has taken a little bit more attention.

    We are working on achieving zero criticals in our issue queues with Wiz. It has helped us gain visibility into our critical issues, but we still have a few dozen left to work through. A lot of that actually has to do with some older infrastructure and workloads that applications use. So we have some application migrations in the works, but we have not quite got to the zero critical status.

    I would rate this review as a 9 overall.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    Information Technology and Services

    A Force Multiplier for Lean Security Teams

    Reviewed on Dec 29, 2025
    Review provided by G2
    What do you like best about the product?
    The agentless installation at Suki was incredibly smooth. We were able to get 100% visibility across our cloud environment immediately without the friction of deploying agents. The dashboards are truly world-class; they don't just show data, they tell a story.

    The biggest upside is the prioritization. Instead of a flat list of thousands of alerts, Wiz uses its Security Graph to identify 'toxic combinations'—helping us focus on the 1% of issues that actually pose a reachable risk. Lastly, the support team is exceptional. They are highly responsive and act more like partners than a standard help desk.
    What do you dislike about the product?
    While the visibility is unmatched, the sheer volume of data can lead to initial alert fatigue. The platform is so comprehensive that it requires significant tuning to ensure developers aren't overwhelmed by non-critical findings.

    There is also a slight workflow gap for developers. While Wiz is great at identifying the problem, the transition from 'finding an issue' to 'fixing it' still requires manual effort. Navigating the Security Graph can be a bit of a learning curve for non-security users who just want to know exactly what code to change.
    What problems is the product solving and how is that benefiting you?
    We have a very lean security team. Before Wiz, we were drowning in noisy, low-context alerts. Wiz has solved this by automating the prioritization of issues.

    For Security: It acts as a force multiplier. Our current security engineers can manage a complex cloud footprint that would typically require a much larger team.

    For Developers and SRE: We’ve given them their time back. We no longer bother them with irrelevant vulnerabilities; we only surface the "reachable" risks that actually matter. This has improved our developer and SRE velocity and built a culture of trust between security and engineering.
    Legal Services

    Exceptional Cloud Visibility and Effortless Integration

    Reviewed on Dec 22, 2025
    Review provided by G2
    What do you like best about the product?
    Wiz provides exceptional visibility across cloud environments, making it easy to identify misconfigurations, vulnerabilities, and compliance gaps in real time. The platform’s agentless architecture is a huge advantage it deploys quickly without impacting performance. The dashboard is intuitive, and the contextual risk prioritisation helps security teams focus on what truly matters. Integration with existing workflows is seamless, which saves time and reduces complexity.
    What do you dislike about the product?
    While Wiz is powerful, the pricing can be a barrier for smaller organisations. Some advanced features require additional configuration, which can be time-consuming for teams without dedicated cloud security expertise. The alert volume can feel overwhelming at first, and tuning policies to reduce noise takes effort. Reporting capabilities, although good, could benefit from more customisation options for executive-level summaries.
    What problems is the product solving and how is that benefiting you?
    Faster incident triage , earlier identity‑risk detection, lightweight audit readiness via scheduled reports, and better threat‑led prioritisation all of which reduce operational overhead while strengthening our cloud security posture.
    Information Technology and Services

    Cloud security Swiss army knife

    Reviewed on Dec 19, 2025
    Review provided by G2
    What do you like best about the product?
    In-depth cloud asset configuration visibility, code-to-cloud capabilities, vulnerability management, ITSM tool integration, trends and reporting dashboards.
    What do you dislike about the product?
    Menus are sometimes cluttered, findings can get overwhelming and you would need good prioritization procedures, naming conventions are a bit difficult to explain to security auditors looking for overall vulnerabilities in a system (between findings and issues)
    What problems is the product solving and how is that benefiting you?
    Cloud vulnerability management
    View all reviews