Wiz Unified Vulnerability Management
Cloud-native VM / CNAPP
Agentless-first cloud vulnerability visibility built on the Wiz Security Graph.
- Not itemizedGov / FedRAMP
- No / integrationBuilt-in patch
- NoOpen source
- SaaSDeployment
- Classification
- Cloud-native vulnerability management / CNAPP / unified vulnerability aggregation.
- Discovery / scanning
- Official/Verified: Agentless-first, scanning cloud environments via API connectors; an optional Sensor adds deeper runtime/workload visibility where needed. Wiz's Unified Vulnerability Management page states coverage of 120,000+ vulnerabilities across 40+ operating systems, per current vendor claims.
- Agent model
- Official/Verified: Primarily agentless; Sensor available for runtime depth. Can also extend to on-premises via third-party aggregation and the Sensor Workload scanner.
- Asset inventory
- Not itemized in source research.
- Risk prioritization
- Official/Verified: Wiz Security Graph correlates vulnerabilities with internet exposure, identity permissions, data sensitivity, network relationships, cloud misconfigurations, and attack paths. Wiz Threat Center adds rapid visibility into emerging/exploited vulnerabilities.
- Remediation
- Official/Verified: Remediation guidance, one-click remediation in supported workflows, patch recommendations, ownership identification, CMDB context, workflow routing, and visibility into transitive dependencies/base-image vulnerabilities. Not a traditional endpoint patch server.
- ITSM / ticketing integration
- EVULNABLE Assessment: Workflow routing/integrations are referenced but not itemized as explicit native ServiceNow/Jira support in this research — confirm current integration list with Wiz.
- Cloud / container / OT coverage
- Official/Verified: Vulnerability coverage across cloud workloads including VMs, serverless, containers, and appliances — a core strength. Can also ingest third-party findings (existing scanners, pen tests, DSPM, SAST, DAST).
- Data residency
- Not itemized in source research.
- Pricing
- Wiz's pricing page states licensing is modular and scales on metrics such as workloads, developers, log ingestion, or sensors depending on product. No simple public per-asset VM price should be assumed.Do not invent a flat per-asset number for Wiz.
- Time to initial data
- Estimated: Often minutes/hours for a first cloud inventory after connecting a cloud account.
- Typical production rollout
- Estimated: Days to 4 weeks — the agentless architecture speeds cloud onboarding; workflow integration takes longer.
- Best-fit company size
- EVULNABLE Assessment: Mid-market through very large enterprise with significant cloud infrastructure.
- Potential limitations / evaluation considerations
- EVULNABLE Assessment: Not designed to replace classic network-appliance/legacy on-prem scanning; no simple public per-asset VM price is published, which complicates budget comparison.
Last verified: August 27, 2026
