Skip to content
Z Zendikt
W

Wiz

Redefined cloud VM with agentless graph-based scanning.

By Wiz, Inc. (Google acquisition pending close) · Founded 2020 · New York, NY · private

Wiz is the cloud-native vulnerability management leader, founded 2020 by Assaf Rappaport and the team behind Microsoft Cloud Security Group (Adallom alumni), private with a last reported $12B valuation. The product redefined cloud VM with agentless scanning that builds a unified security graph across cloud workloads, identities, data, and configuration. Strengths: agentless deployment that connects in hours rather than weeks, the Wiz Security Graph that correlates vulnerabilities with toxic combinations (exposure + privileges + sensitive data), and consistently the fastest time-to-value in the category for cloud-native estates. Best fit for cloud-native-first organizations of any size where AWS/Azure/GCP coverage is the priority. Trade-offs: the announced Google acquisition (March 2025, $32B, expected to close in 2025) is a vendor-stability question every buyer needs to weigh until post-close behavior is known, historical post-acquisition behavior on similar deals (Mandiant, Looker) has been mixed; on-prem and traditional infrastructure VM coverage is meaningfully thinner than Tenable / Qualys; and pricing is opaque and meaningful at scale.

Best for

Cloud-native-first organizations (any size) where AWS / Azure / GCP coverage and time-to-value matter more than on-prem breadth, particularly engineering-led security teams.

Worst for

Buyers with significant on-prem or OT estates (Tenable / Qualys broader), buyers with Google-vendor concentration concerns post-acquisition, Microsoft E5 shops where Defender VM is bundled, or buyers requiring deepest auditor familiarity (Tenable / Qualys stronger).

Vendor Trust Score

Is Wiz a trustworthy vendor?

7.5/10
Mixed
Pricing transparency
Published rates; no hidden fees
5.5
Contract fairness
Reasonable terms; no auto-renew traps
8.0
Incident response
How they handle outages and breaches
8.5
Post-acquisition behavior
Customer treatment after M&A or PE
6.5
Executive stability
Leadership churn over 24 months
8.5
Roadmap honesty
Public commitments held
8.0
Trust signal log
  • 2024-04-08
    Acquired Gem Security; runtime threat detection added to platform
  • 2024-07-22
    First Google acquisition discussion ($23B) reported abandoned; Wiz CEO statement on standalone path
  • 2025-03-18
    Google announced agreement to acquire Wiz for $32B; deal expected to close in 2025 pending regulatory review, vendor stability question for buyers until post-close behavior known
  • 2025-09-22
    CEO Assaf Rappaport committed to product roadmap continuity through close; integration timeline unspecified
Vendor Trust is scored independently of product quality. A great product from an unfair vendor still earns a low trust score.
Review Intelligence

What 780 reviews actually say

Synthesized from G2, Capterra, Reddit, Trustpilot. Patterns >15% prevalence shown.

Last synthesized
2026-04-29

Praise patterns

  • Agentless deployment connects in hours
    91%
  • Security Graph toxic-combination analysis
    84%
  • Fastest time-to-value in cloud VM
    78%
  • Best-in-class management UX
    71%

Complaint patterns

  • Google acquisition stability question flagged
    64%
  • Pricing opaque and meaningful at scale
    51%
  • On-prem and traditional infra coverage thinner
    38%
  • Concern about Google product integration timeline
    31%
Sentiment trend (6 months)
86/100 -3 pts
12
01
02
03
04
05
Patterns are extracted from review corpus and human-verified. We surface trends, not anecdotes.
Verified Pricing

What buyers actually pay

184 anonymized deal disclosures · last updated 2026-05-01

Contribute your deal price
Company size Median annual
500-2,500 cloud resources $78,000
2,500-10,000 cloud resources $264,000
10,000+ cloud resources $720,000
Verified pricing is crowdsourced from buyers under anonymity guarantees. Vendor-listed prices are validated against actual deals quarterly.
Compliance & Security

Auto-verified certifications

Verified 2026-05-01
SOC 2 Type II
ISO 27001
HIPAA
GDPR
CCPA
PCI DSS
FedRAMP In-Process

Editorial: Strengths

  • Agentless deployment connects in hours, not weeks
  • Wiz Security Graph correlates toxic combinations (exposure + privileges + data)
  • Fastest time-to-value in cloud-native VM
  • Made for cloud-native-first organizations of any size
  • Best-in-class management UX and reporting
  • Aggressive product velocity
  • Strong customer NPS pre-acquisition

Editorial: Weaknesses

  • Google acquisition pending close, post-close behavior unknown
  • On-prem and traditional infrastructure VM coverage thinner than Tenable / Qualys
  • Pricing opaque and meaningful at scale
  • Single-vendor concentration risk for buyers consolidating CNAPP+VM on Wiz
  • Some customer concern about Google product integration timeline

Key features & integrations

  • +Agentless cloud scanning (AWS, Azure, GCP, OCI)
  • +Wiz Security Graph (toxic combination analysis)
  • +CSPM + CWPP + CIEM unified
  • +Container and Kubernetes scanning
  • +IaC scanning (Wiz Code)
  • +Wiz Defend (runtime, post-Gem acquisition)
  • +Attack-path analysis
  • +Compliance frameworks (CIS, PCI, SOC2)
200+ integrations
AWSAzureGCPServiceNowJiraSlackGitHubSplunk
Geography supported
Global; strongest in US, EU, UK, AU, Israel
Best fit
100–500,000+ employees · Cloud-native-first organizations of any size
Editorial deep-dive

Read our full ranking of Vulnerability Management Software

Wiz ranks #4 in our editorial review of 10 vulnerability management software platforms. The deep-dive covers methodology, comparison tables, decision matrix, migration scoring, and FAQs.

Read the full ranking

Closest alternatives in Vulnerability Management Software

Help the next buyer

Contribute your verified deal price

Pricing in B2B software is opaque because vendors want it that way. Verified buyer prices fix that, anonymously. Share what you actually paid for Wiz; we’ll add it to the verified pricing dataset on this page (with company size band only, no identifying details).

Submit anonymously