OfficeBooks
Cloud Security

Wiz Review 2026: Enterprise agentless CNAPP built on the Wiz Security Graph — now a Google Cloud company

CNAPPCloud SecurityAgentless

Affiliate disclosure: this review contains affiliate links — we may earn a commission if you sign up, at no cost to you. Ratings are our own editorial scores.

Wiz screenshot
Our verdict

Wiz

4.6
out of 5 · our rating

Pros

  • Fully agentless — connects via API and inventories a cloud account in minutes, no per-VM agents
  • Security Graph correlates misconfigs, vulnerabilities, identities, exposure and secrets into prioritized attack paths
  • Unified CNAPP: CSPM, CIEM, DSPM, CWPP, IaC and AI-SPM in one console instead of stitched point tools
  • Consistently top-rated for UX and fast time-to-value; used by 50%+ of the Fortune 100

Cons

  • No public pricing and no free production tier — every deal is a custom quote
  • Expensive: enterprise estates commonly land at $100K–$200K+/yr, out of reach for SMBs
  • Add-ons (Code, Defend, Sensor) stack cost quickly beyond the base Cloud license
  • Agentless-first model means deeper runtime detection needs the paid Wiz Sensor add-on

Best for: Enterprise multi-cloud security teams, Fortune-scale AWS/Azure/GCP estates, Agentless CNAPP tool consolidation.

Try Wiz → Free 14-day trial + free cloud security self-assessment

What is Wiz?

Wiz is an enterprise cloud-native application protection platform that unifies what most security teams otherwise run as separate tools. Its homepage frames the goal as protecting everything you build and run. Instead of requiring agents on every workload first, Wiz scans cloud accounts agentlessly and builds a connected model of what exists, how it is configured, and how an attacker could move through it.

The platform sells as modules — Wiz Cloud, Wiz Code, and Wiz Defend — sitting on shared context, with Wiz Sensor adding runtime visibility where an agent earns its place. The about page notes the company is now part of Google Cloud.

The Wiz Security Graph

The Wiz Security Graph is the piece that makes everything else coherent. Wiz correlates configuration, vulnerabilities, identities, network exposure, and sensitive data into one model, then applies attack path analysis to surface the chains where a misconfiguration plus an over-permissioned role plus internet exposure add up to a genuine breach path. The platform page describes the aim as prioritizing risk with context, which is the difference between a queue of thousands of findings and a short list worth paging someone about.

What Wiz Cloud covers

The Wiz Cloud product page listing CSPM, CIEM, DSPM, AI-SPM, and container security capabilities

Wiz Cloud bundles categories most teams shop for separately. CSPM catches misconfigurations from build time to runtime. Vulnerability Management reaches VMs, serverless functions, containers, and appliances. Secure Cloud Identities (CIEM) analyzes entitlements and auto-generates least privilege policies. Data Security (DSPM) discovers and classifies sensitive data, while Secure AI (AI-SPM) extends the same treatment to models and AI services. Container and Kubernetes Security, Infrastructure as Code scanning against a library of more than a thousand rules, and Compliance assessment against frameworks including PCI, GDPR, and HIPAA complete the module.

Wiz Code and the developer workflow

Wiz Code pushes findings to where they get fixed. Code-to-cloud mapping traces a live cloud risk back to the source that introduced it, and one-click remediation proposes the change in place. Scanning spans SCA and SBOM across direct and transitive dependencies, hardcoded secrets in repositories and container images, malware before it reaches CI runners, and DSPM in code for PHI and PII. AppSec Posture Management aggregates third-party scanner findings and correlates them to cloud impact. Integrations reach IDE scanning, GitHub, Slack, and an MCP server, and the vendor reports that reachability context keeps developers focused on real issues.

Runtime coverage from Wiz Defend

The Wiz Defend product page describing runtime threat detection, forensics, and response automation

Wiz Defend covers runtime. eBPF-powered Cloud Workload Protection and Kubernetes runtime protection add file integrity monitoring and drift detection. Cloud Investigation and Response Automation gathers forensic data so an incident can be reconstructed, while Identity Detection and Response and Data Detection and Response watch for behavioral anomalies and unexpected access to sensitive stores. The Wiz Threat Intel Center feeds threat hunting, and AI Runtime Protection targets newer problems including prompt injection, model exfiltration, and attacks against MCP servers.

The Red, Green, and Blue agents

Wiz has wrapped its newer automation into three named agents. The Red agent discovers attack paths with automated penetration testing and risk discovery. The Green agent automatically turns risks into code fixes, opening pull requests to fix issues at the source and helping write secure code from the start. The Blue agent handles SecOps triage and investigation, and the vendor reports a large reduction in mean time to respond. The design intent is consistent: use the graph as grounding so automated action rests on real context rather than guesswork.

Who should choose Wiz

Wiz suits organizations running substantial multi-cloud or hybrid estates where tool sprawl has become expensive — teams juggling separate CSPM, CIEM, DSPM, and detection products, and platform groups who need developers to own remediation. The agentless start makes initial coverage fast, which matters when an agent rollout would take quarters. Licensing is modular, described on the pricing page as scaling with workloads, active developers, log ingestion, or sensors, so a team can begin with one module. It is not ideal for a small shop with one cloud account and a tight budget: everything is quote-based and sales-led, and a lighter tool will serve better, although Wiz does list a Go Bundle aimed at SMBs.

Key features

FeatureWhat it does
Wiz Security GraphCorrelates misconfigurations, vulnerabilities, identities, exposure and secrets to surface only critical, exploitable attack paths ('toxic combinations').
Agentless scanningAPI + snapshot-based connector inventories cloud resources across AWS, Azure, GCP, OCI and Kubernetes without deploying agents.
Unified CNAPP modulesCSPM, CIEM, DSPM, CWPP, IaC and AI-SPM delivered on one policy engine and console rather than separate tools.
Wiz Code (ASPM)Shifts security left into repos, pipelines and IaC, tracing cloud risks back to the code and owner that introduced them.
Wiz Defend (CDR)Cloud detection and response using runtime signals and cloud logs to catch and investigate active threats.
Free self-assessment & risk reviewsFree cloud security self-assessment across 9 domains plus free 1-on-1 CVE, attack-surface and AWS risk reviews.

Wiz pricing

PlanPriceIncluded
Wiz CloudCustom quote
Wiz CodeCustom quote
Wiz DefendCustom quote
Wiz SensorCustom quote
Wiz Go Bundle for SMBsCustom quote

How Wiz compares

AlternativeHow it differs
Prisma Cloud (Palo Alto)Broadest enterprise CNAPP with agent-based runtime depth; also quote-only, credit-based licensing, six figures at scale.
Orca SecurityClosest agentless rival using SideScanning; strong single-platform coverage, often positioned as a lower-cost Wiz alternative.
CrowdStrike Falcon Cloud SecurityAgent-plus-agentless CNAPP tightly tied to CrowdStrike EDR; appeals to teams already on the Falcon platform.

Wiz ratings on other platforms

Independent user ratings from third-party review sites, linked here for transparency. These are not our editorial score, are captured on the date shown, and may have changed since.

Frequently asked questions

How much does Wiz cost?

Wiz pricing is custom and sales-quoted, scaling with workload count and modules. Public AWS Marketplace list prices start at $24,000/year for Wiz Essential (100 workloads) and $38,000/year for Wiz Advanced. Enterprise estates of 1,000–5,000 workloads typically run $100,000–$200,000+ per year, with per-workload rates dropping from roughly $24 to under $10 at volume.

Is Wiz free?

There is no free production tier, but Wiz offers a free 14-day trial that connects to your code, cloud and AI. It also provides a free cloud security self-assessment across 9 domains, plus free 1-on-1 assessments for CVEs, attack surface and AWS. Full platform use requires a paid annual contract quoted by sales.

Wiz vs Prisma Cloud — which is better?

Both are enterprise CNAPPs with quote-only pricing at six figures. Wiz is praised for fast agentless deployment and its Security Graph correlating misconfigs, vulnerabilities, identities, exposure and secrets. Prisma Cloud (Palo Alto) offers deeper agent-based runtime and credit-based licensing. Wiz usually wins on time-to-value and UX; Prisma on raw breadth.

Does Google own Wiz?

Yes. Alphabet closed its $32 billion all-cash acquisition of Wiz on March 11, 2026 — the largest deal in Google's history. Wiz now sits inside Google Cloud but remains multi-cloud, continuing to support AWS, Azure, Oracle Cloud and GCP. Existing contracts and the standalone platform continue unchanged for customers.

Does Wiz require agents?

No. Wiz is agentless-first, using an API connector and snapshot scanning to inventory a cloud environment within minutes with no per-VM agents. For deeper runtime detection and response, Wiz offers an optional lightweight eBPF Wiz Sensor, listed around $28,000/year for 100 sensors as an add-on to Wiz Advanced.

Verdict

Buy Wiz if you run a serious multi-cloud enterprise estate and want to replace a pile of point tools with one agentless CNAPP that deploys in hours and surfaces genuinely exploitable attack paths — its Security Graph, UX and fast time-to-value justify the six-figure spend for security teams that can afford it. Skip it if you're an SMB, a single-cloud shop, or budget-constrained: with no public pricing, no free production tier, and stacking add-ons, Wiz is priced for the Fortune 500, and Orca or CrowdStrike may fit smaller footprints better.

OB
OfficeBooks Editorial — Research desk

Our research desk checks every feature and price against the vendor’s own pricing page and dates each review when it was last checked. We do not run hands-on product tests — reviews are documentation-based, and third-party ratings are always attributed and dated.

Facts verified against: www.wiz.io, aws.amazon.com, www.wiz.io, blog.google, www.wiz.io, www.wiz.io, www.wiz.io, www.wiz.io, www.wiz.io, www.wiz.io (as of August 2026).

Wiz
Our rating 4.6/5 · Custom quote (contact sales)
Visit →