

Wiz and Vanta compete in the cybersecurity platform market, with Vanta having an advantage in compliance features and Wiz strong in cloud security.
Features: Wiz offers advanced cloud workload protection, real-time visibility for threat detection, and Security Graph for risk prioritization. Vanta provides automated compliance management, prebuilt control frameworks, and real-time API integration for compliance integrity.
Room for Improvement: Wiz could improve on-demand scanning clarity and better explain scanner functions. Enhanced agentless operations would aid Wiz's multi-agent approach. Vanta would benefit from smoothing occasional API integration difficulties and expanding compliance support across more platforms.
Ease of Deployment and Customer Service: Vanta features efficient deployment and dedicated service for seamless compliance onboarding. Wiz offers flexible deployment with strong support for cloud configurations. Vanta's focus is compliance onboarding, differing from Wiz's cloud-centric approach.
Pricing and ROI: Wiz's competitive pricing suits complex cloud environments with positive ROI for cloud-focused companies. Vanta's higher costs align with its automation capabilities, yielding substantial ROI through resource efficiency and compliance upkeep.
We have seen ROI from Wiz and we continued to see value in Wiz.
I think we're reaching the point where we'll see a return on investment, and we'll be there by the end of the year.
We estimate a cost reduction of around 35% to 50%, or even more, due to consolidating our security management into one platform.
Every time I ask their customer success team, if I get a technical question and I've done this half a dozen times in the last year, they will respond within the next 24 hours.
On a scale from 1 to 10, I would give Wiz's support a 10.
The vendor was readily available to assist us over calls, clarifying both technical aspects and theoretical insights.
If I were to put Wiz support on a scale from one to ten, I would give them a ten.
We have deployed Wiz in three organizations on AWS, each with approximately 70 to 80 accounts, totaling more than 120 accounts.
Scalability-wise, I rate the solution a ten out of ten.
Our environment quadrupled in size. We didn’t have to make any adjustments or configuration changes; it just accommodated the growth.
Vanta is very stable; we haven't had any downtimes or weird behavior so far, which we really appreciate.
There are connection problems about 50% of the time because of the automated evidence collection.
The stability of Wiz has been good, with no downtime, bugs, or glitches.
Stability-wise, I rate the solution an eight to nine out of ten.
The solution is very stable.
Vanta has been really nice, with a nice user experience, clear layout, and very reasonable recommendations compared to other platforms we've tried.
The UI is not super intuitive, but now that I've worked with it for a couple of years, I know how to navigate and get around.
I have to clear all CVEs before the test will pass.
We would like to see preventive controls that can be applied through Wiz to protect against vulnerabilities that we're not going to be able to remediate immediately.
One significant area for improvement would be increasing automation. While they excel at identifying issues, we need assistance in minimizing the human hours required for tasks.
It's critical for our team to demonstrate the tool's value.
Vanta's pricing for small businesses allows you to double that person's SOC/ISO compliance capabilities for less than the cost of another staff member.
We are paying 250k per year.
In some cases, it has a very aggressive price, so very cheap.
I don’t think there’s anyone else out there offering the same level, scale, or efficiency.
Vanta has positively impacted my organization by helping us remediate a lot of vulnerabilities and bad practices, especially from vulnerable ECR repos, and enforced good behavior.
All our policy documents are organized so I always know where I can go to get the latest and greatest version of those.
The automated testing of controls and access reviews are valuable features.
The ability to scan every layer without agents is a huge selling point because we're multi-agent.
The feature leads to minimal false positives and a low volume of alerts, which is highly valuable for our operations.
It's highly customizable, allowing us to manage many custom features effectively.
| Product | Market Share (%) |
|---|---|
| Wiz | 17.8% |
| Vanta | 7.6% |
| Other | 74.6% |

| Company Size | Count |
|---|---|
| Small Business | 8 |
| Midsize Enterprise | 3 |
| Large Enterprise | 1 |
| Company Size | Count |
|---|---|
| Small Business | 9 |
| Midsize Enterprise | 8 |
| Large Enterprise | 20 |
Vanta helps companies scale security practices and automate compliance for the industry’s most sought after standards - SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, and CCPA.
Wiz is a highly efficient solution for data security posture management (DSPM), with a 100% API-based approach that provides quick connectivity and comprehensive scans of platform configurations and workloads. The solution allows companies to automatically correlate sensitive data with relevant cloud context, such as public exposure, user identities, entitlements, and vulnerabilities.This integration enables them to understand data accessibility, configuration, usage, and movement within their internal environments.
Wiz's Security Graph delivers automated alerts whenever risks emerge, allowing teams to prioritize and address the most critical issues before they escalate into breaches. Furthermore, Wiz ensures rapid and agentless visibility into critical data across various repositories, enabling organizations to easily determine the location of their data assets.
Wiz provides various features in the following categories:
Agentless Scanning: The solution can scan every layer of a cloud environment without requiring agents, managing the entire process and providing comprehensive visibility.
Workflow Integration: Users can create customized workflows within Wiz to identify and assign actions based on urgency, integrating them with ticketing systems for quick and efficient remediation.
Vulnerability Management: Wiz's vulnerability management modules provide detailed analytics and visibility across cloud systems, streamlining the manual process of vulnerability discovery. The automated attack path analysis helps identify risks and trace potential points of exposure, allowing users to understand and mitigate them effectively and proactively.
CSPM (Cloud Security Posture Management): Wiz's CSPM module offers instant visibility into high-level risks to an enterprise’s cloud environment, covering all accounts without the need for agents.
Out-of-the-Box Reporting and Custom Queries: The service supports comprehensive reporting with asset context, allowing users to perform complex custom queries on the solution’s user-friendly interface.
Automation Roles and Dashboards: The solution facilitates automation by providing essential roles and dedicated dashboards that enable teams to understand security information quickly, even those with limited expertise.
Contextual Risk Evaluation: The service contextualizes the various components contributing to an issue, providing a risk evaluation framework that helps prioritize remediation efforts.
Security Graph and Visibility: Wiz's security graph offers visibility across the entire organization, even with multiple accounts, enabling users to understand their environment and assets effectively.
Wiz offers the following benefits:
Comprehensive agentless scanning
Effective identification and mitigation of vulnerabilities
Streamlined vulnerability management
Robust reporting capabilities and customizable queries
Enhanced automation and role-based access control
Prioritized risk evaluation for efficient remediation
Security posture across multiple accounts
Kamran Siddique, VP Information Security at boxed.com, remarks his company has seen a ROI while using Wiz, as it simplifies the process by integrating multiple useful tools into one solution.
According to a Senior Security Architect at Deliveroo, Wiz has given their company a fresh approach to vulnerability management, as Wiz's native integrations are extremely useful and paramount to the operational success of their platform.
We monitor all Compliance Management reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.