Wiz performs a deep assessment of your entire cloud and then correlates a vast number of security signals to trace the real infiltration vectors that attackers can use to break in. Wiz also gives you the tools to bring your DevOps and development teams into the process to fix these risks, creating a culture of security in your cloud operations that results in a stronger, more secure cloud. For more information visit: https://www.wiz.io
Wiz provides custom pricing for customers via Private Offer. Please contact marketplace@wiz.io for a better understanding of our pricing model and products.
Highlights
Covers every resource across your full cloud stack, multi-cloud environment using a 100% API approach that deploys in minutes.
Models overlapping cloud policies, configurations, and compensating controls that interact in ways that are often unpredictable to calculate their end result.
Maps all of the issues in your cloud together in a single graph database, revealing which of them combined pose the greatest risk.
Access real-time vendor security and compliance information through their Trust Center powered by Drata or Vanta. Review certifications and security standards before purchase.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
Pricing is modular and sold by units. Two base options protect your cloud workloads in blocks of 100: Wiz Essential and Wiz Advanced. Three add-ons build on a base plan. Wiz Sensor and Wiz Defend extend Wiz Advanced; Wiz Sensor is sold per 100 sensors, and Wiz Defend is sold by log volume at 300 GB ingested per month. Wiz Code adds to Wiz Cloud in blocks of 100 licenses. You scale by buying more units of each dimension as your workloads, sensors, developers, or log ingestion grow.
Top-of-mind questions for buyers
What counts as one cloud workload for the Wiz Essential and Wiz Advanced unit blocks?
A workload is a cloud resource that Wiz scans, such as a virtual machine, container, or serverless function. Each base plan protects these in blocks of 100. Wiz connects through API connectors to inventory and scan your cloud environment, counting the workloads it covers.
How is Wiz Defend measured, and what happens if my log volume grows?
Wiz Defend is billed by log ingestion at 300 GB per month per unit. It combines runtime signals from the Wiz Sensor with analysis of cloud and SaaS logs. As your monthly log volume grows past a unit, you add more Defend units to cover the added ingestion.
Which base plan does each add-on attach to, and can I mix them freely?
Add-ons attach to specific base plans. Wiz Sensor and Wiz Defend extend Wiz Advanced. Wiz Code adds to Wiz Cloud in blocks of 100 licenses. You need the matching base plan before buying its add-on. Each dimension bills independently, so your total combines every unit you purchase.
Request a private offer to receive a custom quote.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Wiz provides custom pricing for customers via Private Offer. Please contact marketplace@wiz.io for a better understanding of our pricing model and products.
tel:+01-240.823.5670
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Covers every resource across the full cloud stack in multi-cloud environments using a 100% API approach with deployment in minutes.
Cloud Policy and Configuration Analysis
Models overlapping cloud policies, configurations, and compensating controls to calculate their combined end result.
Risk Correlation and Visualization
Maps all issues in the cloud infrastructure together in a single graph database to identify which combined issues pose the greatest risk.
Security Signal Correlation
Correlates a vast number of security signals to trace real infiltration vectors that attackers can exploit.
DevOps and Development Team Integration
Provides tools to integrate DevOps and development teams into the security risk remediation process.
Attack Surface Management
Aggregates comprehensive attack surface visibility across hybrid environments with external attack surface scans to provide 360-degree view of entire attack surface
Vulnerability Management
Delivers complete visibility across on-premise and remote endpoints to identify, communicate, and remediate vulnerabilities, misconfigurations, and risks
Cloud Security
Provides code-to-cloud protection for cloud-native applications with CI/CD pipeline integration and agentless risk assessment based on reachability, exploitability, and potential impact
Next-Generation SIEM and XDR
Delivers accelerated detection and response with SaaS deployment, out-of-the-box detections informed by MDR SOC, and built-in automation capabilities
Threat Intelligence
Delivers high-fidelity actionable threat intelligence infused with proprietary threat and vulnerability research from Rapid7 Labs and community-driven tools
Offensive Security Engine
Simulates external exploits to produce Verified Exploit Paths for prioritizing exposures that are truly reachable by outside attackers, reducing cloud attack surface.
Cloud Security Posture Management
Continuously monitors and manages security of AWS configurations to prevent public exposure and ensure compliance.
Secrets Scanning
Identifies more than 750 types of secrets across public and private repositories.
Cloud Infrastructure Entitlements Management
Detects and manages excessive or unused permissions to mitigate the risk of privilege escalation.
Real-Time Malware Detection
Detects malware including zero-days in milliseconds with scanning performed directly in cloud environment for object storage services like Amazon S3 and file storage services.
Unified cloud visibility has improved risk mapping and reduces code-level vulnerabilities quickly
Reviewed on Sep 03, 2026
Review provided by PeerSpot
What is our primary use case?
Wiz is being tested to compare against Checkmarx, examining scanning capabilities, native visibility, ease of deployment, and code-level analysis. The proof of concept has completed, and we had interaction with the user interface, gaining the ability to use some of the features and functionality of Wiz. The scanning process was very easy, with a single pane of glass making it simple to move from one feature to another. There is significant customization involved, allowing for bespoke configuration to meet specific requirements. Wiz provided many advantages, and the proof of concept was very impressive. The interface was simple to use and quick to become familiar with.
We were able to examine risks and vulnerabilities very easily, which was the main focus of the initiative—to identify exactly where the vulnerabilities, risks, and threats were located and to detect and identify those immediately within the framework provided. Multi-cloud risk mapping proved very useful because we could see everything with no hidden elements. Everything was visible and transparent. In terms of prioritization, we could identify which specific area of the cloud or container contained vulnerabilities. When critical issues appeared, we could develop metrics to understand where specific problems lay. If a certain area had multiple critical vulnerabilities, we looked deeper into that area to find underlying causes. There was immediate information available, as well as information that could be gleaned after conducting root cause analysis. Trends and trend analysis have improved, helping us build a clearer picture of what is happening, where it is happening, and why. Robust static application security testing (SAST) and SCA analysis at the code level proved very useful. Catching vulnerabilities early was a key highlight and takeaway from the proof of concept.
What is most valuable?
The best feature Wiz offers is the ability to identify different threats, weaknesses, and vulnerabilities, with vulnerabilities being the main focus because that is what we have to communicate to our coders and developers. We were able to see what specific vulnerabilities contained in terms of root cause analysis, such as whether libraries needed updating, whether certain CVEs were related to those vulnerabilities, and how common those vulnerabilities were, including whether patches or fixes were available. Significant information was available that could help remediate numerous issues. Vulnerabilities identification and detection were very important; we were immediately able to see through drilling down exactly what was available in terms of remediation, whether it was possible immediately or what could be done afterward.
In terms of posture management, it was fantastic because we could see how risks were mapped across multi-cloud infrastructure seamlessly. The threat detection algorithms and mapping prioritized vulnerabilities based on actual exposure, allowing us to see critical, high, medium, or low priorities instantly. The deployment was also very easy.
Wiz has positively impacted our organization with improved remediation speed and efficiencies in terms of time saved, as well as reducing false positives. We are currently conducting deep code scanning alongside posture management, and we have seen improvements and efficiencies in both areas. Final metrics have not been established, and I am certain that will be completed in October once analysis is finished. However, the initial findings and recommendations are very positive, indicating benefits in time saved and efficiency, as well as economies of scale in performing tasks more easily and quickly while eradicating false positives and achieving a clearer picture of real vulnerabilities.
Wiz has met my expectations in terms of accuracy and reliability of output, with the co-pilot functionality being very good. The assistant services from AI exceeded what I had anticipated. Although the full range has not been tested, my experiences, along with my colleagues', have been very impressive regarding the outputs generated by AI.
What needs improvement?
While Checkmarx may perform better in some deep code scanning aspects, Wiz is considerably easier to use, has a better user interface, and offers a more compelling argument for its use. It is more robust and stable, making these positive points quite clear. The only slight negative is its scanning capability compared to Checkmarx, but it is still very good. Additional comments regarding needed improvements around scanning capabilities or any other area where Wiz could catch up to Checkmarx are not necessary.
For how long have I used the solution?
Wiz has been used for a proof of concept over the course of a few weeks. A decision regarding adoption will be made by our company based on the findings and recommendations from the participants in the proof of concept initiative.
What do I think about the stability of the solution?
Wiz is stable based on proof of concept experience, and it is certainly much more stable than Checkmarx.
What do I think about the scalability of the solution?
I am very impressed with Wiz's scalability. We began with 50 licenses and quickly increased that number to 200. It was efficient in scaling up. While we anticipate needing in excess of 200 licenses moving forward, we are confident Wiz can handle that demand.
How are customer service and support?
Customer support receives a rating of 10 because we had a few initial questions, and they responded quickly and professionally, resolving all our issues regarding identity and access management in a short period.
Which solution did I use previously and why did I switch?
The main solution currently in use is Checkmarx. We considered switching because Checkmarx experienced several outages and failures in service delivery, prompting us to explore other options in the marketplace.
How was the initial setup?
During the proof of concept, there was minimal interaction with other applications. There was a link to Jira and Confluence for ticket creation, but since it was a proof of concept, much of the information was dummy data. Wiz was used primarily in isolation to see how the product would function on its own, without integration with other products.
What about the implementation team?
Post-sale support services were not used during the proof of concept. The next step will be to collect all findings and make recommendations to senior management, who will decide whether to implement Wiz within the company.
What was our ROI?
A return on investment has not been technically realized yet, but efficiencies have been achieved in terms of fewer false positives and reduced analyst time on resolving vulnerabilities. These metrics will become clearer in October after assessing how Wiz performed against Checkmarx. The initial findings are encouraging, and we are optimistic about future assessments.
What's my experience with pricing, setup cost, and licensing?
No involvement occurred with pricing, setup cost, and licensing for Wiz since it was a free proof of concept. Approximately 200 licenses were provided for the initiative, but pricing moving forward is unknown. It is expected to be more expensive than Checkmarx; however, the overall feeling is that Wiz is the more stable and user-friendly product, strong with features and functionality, potentially favoring the decision to move forward.
Which other solutions did I evaluate?
The recommendations provided by Wiz were valuable. This functionality is not available with Checkmarx currently. The concept of using the co-pilot and large language models, along with agentic AI, is refreshing and potentially very beneficial for future operations, particularly in troubleshooting and root cause analysis.
What other advice do I have?
Multi-cloud risk mapping was very useful because we could see everything with no hidden elements. Everything was visible and transparent. In terms of prioritization, we could identify which specific area of the cloud or container contained vulnerabilities. When critical issues appeared, we could develop metrics to understand where specific problems lay. If a certain area had multiple critical vulnerabilities, we looked deeper into that area to find underlying causes. Significant immediate information was available, as well as information that could be gleaned after conducting root cause analysis. Trends and trend analysis have improved, helping us build a clearer picture of what is happening, where it is happening, and why. Robust static application security testing (SAST) and SCA analysis at the code level proved very useful. Catching vulnerabilities early was a key highlight and takeaway from the proof of concept.
The recommendations provided by Wiz were valuable. This functionality is not available with Checkmarx currently. The concept of using the co-pilot and large language models, along with agentic AI, is refreshing and potentially very beneficial for future operations, particularly in troubleshooting and root cause analysis.
My overall rating for this review is 9.
Hospital & Health Care
Easy, Fast Setup with Best-Practice Templates Across Many Platforms
Reviewed on Aug 19, 2026
Review provided by G2
What do you like best about the product?
very easy and quick to set up and covers a lot of platforms and has many best practice templates
What do you dislike about the product?
there are a lot of tabs and the main interface is very busy
What problems is the product solving and how is that benefiting you?
a single view of cyber security posture of different organisations
david z.
User-Friendly Security Boost with Some Delays
Reviewed on Aug 13, 2026
Review provided by G2
What do you like best about the product?
I find Wiz very easy to use, which is a huge plus for me. I also like the red agent feature because it helps me to add security to my system effectively. The initial setup was very easy, which made getting started with Wiz smooth.
What do you dislike about the product?
I dislike that it takes 24 hours to inform me.
What problems is the product solving and how is that benefiting you?
I use Wiz to add security to my system. It's very easy to use, and the red agent helps in enhancing my system's security.
Alternative Medicine
Efficient Cloud Security Visibility with an Intuitive UI
Reviewed on Aug 07, 2026
Review provided by G2
What do you like best about the product?
Very efficient view of all cloud assets and security aspects of the infrastructure. very intuitive UI and simple integration and implementation. Onboarding was easy. The solution allowed us to to find and resolve issues that we would not have found or resolved without it (also thanks to the green/red agents).
What do you dislike about the product?
Can be a little costly when workloads grow, but still worth the investment.
What problems is the product solving and how is that benefiting you?
Wiz gives us a 360-degree view of all our cloud assets, including issues, vulnerabilities, and EOL components. Instead of dealing with thousands of lines of vulnerabilities and issues, it helps us focus and prioritize what needs to be fixed first. AI agents (green/red) help resolve issues and discover others that are otherwise invisible.
Government Administration
Wiz: agentless cloud visibility with Security Graph and truly prioritized risks
Reviewed on Aug 06, 2026
Review provided by G2
What do you like best about the product?
The most useful aspect of Wiz, in my opinion, is the agentless approach combined with the Security Graph: it analyzes the entire cloud environment via API (without installing software) and clearly maps the relationships between vulnerabilities and access.
One of the advantages I appreciate the most is the Zero Alert Fatigue: it identifies only real risks and concrete attack paths (Toxic Combinations), minimizing false alarms.
What do you dislike about the product?
The aspect I appreciate least about Wiz is the high cost, calculated based on the number of resources/workloads.
Among the main disadvantages is the complexity of the initial integration: even though the scanning is fast, correctly configuring policies, reports, and more advanced workflows requires in-depth expertise and some time to be set up properly.
What problems is the product solving and how is that benefiting you?
Help improve our posture and correct the misconfigurations on our public clouds.