Skip to main content

Help us improve the Digital Marketplace - send your feedback

SEP2 LIMITED

Wiz

Wiz is a leading cloud security platform that provides unified visibility and risk management across cloud, code, and applications. Leveraging our Security Graph, Wiz empowers organisations to prioritise critical risks, accelerate remediation, and ensure continuous compliance to secure dynamic environments and meet stringent regulatory requirements.

Features

  • Security Graph: Complete code-to-cloud visibility without agents.
  • Agentless Deployment: Rapid, frictionless deployment across multi-cloud.
  • Wiz Code: AI-powered code analysis, enhanced findings correlation.
  • Wiz Sensor: Runtime threat detection, exploitable vulnerability validation.
  • Data Security Posture Management: AI-powered data classification, shadow data detection.
  • Unified Policy Framework: Centralised code-to-cloud policy enforcement.
  • Attack Surface Management: Comprehensive external exposure visibility, risk assessment.
  • Automated Remediation: Integrates with workflows for efficient issue resolution.
  • Continuous Compliance: Automates assessment against 100+ security frameworks.
  • Wiz SecOps AI Agent: Proactive threat analysis, verdicts, confidence levels.

Benefits

  • Unify cloud security visibility across all environments.
  • Deploy frictionlessly, without agents, for rapid insights.
  • Prioritise critical risks with contextual, actionable intelligence.
  • Automate remediation workflows, accelerating issue resolution effectively.
  • Achieve continuous compliance against 100+ security frameworks.
  • Trace risks from code to cloud, preventing exploitations.
  • Reduce external attack surface through comprehensive management.
  • Validate exploitable vulnerabilities in runtime, reducing false positives.
  • Enhance security operations with AI-powered threat analysis.
  • Secure sensitive data effectively with AI-driven classification.

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at sales@sep2.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

4 2 5 2 6 6 9 6 6 4 0 4 0 3 3

Contact

SEP2 LIMITED sep2 sales team
Telephone: 03300437372
Email: sales@sep2.co.uk

About your service

Service categories

Systems Infrastructure Software

Security

  • Cloud native application protection platform
  • Security analytics
  • Governance, risk and compliance

Network security

  • Active application security
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
  • Public cloud
  • Private cloud
  • Community cloud
  • Hybrid cloud
Service constraints
No
System requirements
  • Internet access to the Wiz portal and its subsidiary services
  • In some scenarios outbound network connectivity to the Wiz backend
  • Wiz IP addresses must access customer cloud APIs

User support

Email or online ticketing support
Yes
Support response times
Wiz Support Overview:
Response times
• Urgent: Elite (30 mins), Enterprise (2 hrs), Free (4 hrs)
• High: Elite (2 hrs), Enterprise (4 hrs), Free (8 hrs)
• Normal: Elite/Enterprise (8 hrs), Free (1 day)
• Low: Elite (24 hrs), Enterprise/Free (1 day)

Availability:
• Elite & Enterprise: 24/7
• Free: 24x5 (Mon-Fri)
• Priority Level 1: 24/7/365 (All tiers)

Incident Acknowledgement (MTTA):
• P1 (Critical): ≤ 5 mins
• P2 (High): ≤ 15 mins
• P3 (Medium): ≤ 1 hr
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
No
Web chat support
Yes
Web chat support availability
24 hours, 7 days a week
Web chat support accessibility standard
WCAG 2.2 AA
Web chat accessibility testing
Wiz targets WCAG AA compliance for its overall platform to support screen readers and other assistive technologies.
While continuous improvements are made, specific features, compliance details, or testing results for a dedicated web chat function are not currently documented.
Wiz integrates with third-party communication tools, such as Google Chat, to provide automated alerts.
Wiz's commitment to WCAG 2.2 AA compliance is highlighted in our blog and is integrated into our design and engineering processes.
Onsite support
No
Support levels
Support Levels and Costs Wiz offers two primary support tiers:

• BASE: Designed for small to mid-sized enterprises, this level is included with the subscription. It provides 24x5 technical support availability with a 2-business-hour response time for critical (P1) issues.

• PREMIUM: Designed for large enterprises, this level costs 17.5% of the Annual Subscription. It provides 24x7x365 technical support availability with a 30-minute response time for critical (P1) issues. Personnel Provided: • Technical Account Manager (TAM): Premium customers receive an Assigned Technical Account Manager. Base customers have access to Pooled TAM resources and self-service tools rather than a dedicated individual.
• Support Engineers: Both plans provide access to highly trained support engineers via email and the support portal.
Support available to third parties
Yes
AI chatbot
No

Onboarding and offboarding

Getting started
Wiz provides user documentation, online training plus customer success teams to support operationalisation of the service.
Service documentation
Yes
Documentation formats
HTML
End-of-contract data extraction
When your contract with Wiz ends, there's a clear process for managing your data:
Initial Grace Period: An 8-day grace period allows you to access your data and reports directly within your Wiz tenant.
Suspension Period: Following the grace period, your tenant enters a 90-day suspension. During this time, new data isn't ingested, but existing data can still be restored if you renew your subscription.
Permanent Deletion: After the 90-day suspension, your tenant and all associated data are permanently deleted and cannot be recovered.
Data Export Responsibility: You are responsible for downloading your data, and Wiz keeps it available for up to 90 days after termination via the platform.
Expedited Deletion: If you need faster deletion, you can request an expedited deletion, which removes your tenant within 14 business days.
Backup & Personal Data:
Copies of data might remain in backups for up to 180 days for internal recovery.
For Customer Personal Data, Wiz will delete or return it in a standard format based on your choice, unless legal obligations require longer storage.
End-of-contract process
End of Contract:
When your Wiz contract concludes, your subscriptions stop, requiring you to discontinue using the platform and delete any associated documentation. Remember to download your data before the contract ends, as Wiz might delete it according to Wiz's retention policy.
What's Included:
Wiz's standard pricing covers access to the Wiz cloud security platform (SaaS) for internal use, including updates and improvements. This typically features core offerings like Wiz Cloud, Wiz Code, Wiz Defend, and Wiz Sensor, depending on your chosen tier (e.g., Wiz Go, Wiz Essential, Wiz Advanced), all designed to cover a specific number of cloud workloads.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
No
Designed for use on mobile devices
No
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
Wiz offers various ways to interact with its platform, such as through cloud connectors for different cloud providers, integrations with CI/CD pipelines, and the use of its CLI tool and API. Wiz also provides an inventory of workloads deployed in the cloud(s) which provides predictability on service usage. The primary function of Wiz is to provide deep security analysis and monitoring for cloud environments, rather than offering tools for monitoring the performance of the Wiz platform. Users can view system health and deployment status within Wiz, which may indirectly provide some insights into the performance of the Wiz application.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
Wiz's main interface is designed with accessibility in mind, and we strive for compliance with the Web Content Accessibility Guidelines (WCAG) 2.2 at the AA level. The Wiz portal has been through multiple WCAG compliance reviews, which means it's built to work smoothly with screen readers and other assistive technologies.
While we consistently work on improvements and conduct these reviews, we don't have explicit records in our documentation or internal discussions about direct interface testing with users of assistive technology, such as screen readers or Braille keyboards. We always welcome and encourage users to let us know if they run into any specific accessibility concerns.
API
Yes
What users can and can't do using the API
With the Wiz API, users have the power to programmatically perform every task and action available within Wiz. This includes performing actions such as bulk add connectors, mimicking UI behaviour in textual format, or performing complex data manipulation operations.
API documentation
Yes
API documentation formats
  • HTML
  • Other
API sandbox or test environment
No
Customisation available
Yes
Description of customisation
Wiz gives you flexible ways to fine-tune your security environment. You can create custom Cloud Configuration Rules (CCRs) using Rego and Host Configuration Rules (HCRs) using OVAL to define precise policies across cloud and host workloads. This extends to tailored checks for Wiz Code, Wiz Defend, and Wiz Sensor, as well as custom compliance frameworks, data classification, posture policies, and granular RBAC. Near real-time scanning behaviour can also be adjusted to suit operational needs.

Most customisation is handled directly in the Wiz platform, where you can create new rules or duplicate and modify existing ones by changing scope, severity, and mapped compliance standards. For deeper control, advanced users can write their own Rego or OVAL rules and manage reusable logic with custom Rego packages. Programmatic customisation is available via the Wiz GraphQL API.

Access to these features depends on role and licence. Administrative or Owner roles are typically required, and advanced capabilities such as custom rule authoring usually require Wiz Cloud Advanced or Wiz for Gov Advanced. Some custom user roles may need explicit enablement to unlock specific functions.

Scaling

Independence of resources
Wiz ensures consistent user performance through a robust multi-tenant architecture, powered by Wiz's PEACH tenant isolation framework. This framework is key to safeguarding against cross-tenant vulnerabilities and maintaining clear data separation for each user. Wiz is a multi-tenant service with a shared tenancy model. Our approach to isolation relies on several layers of protection both at rest and in runtime. Wiz has proven performance at scale for some of the largest cloud customers in the world.

Analytics

Service usage metrics
Yes
Metrics types
Wiz Security Score: This is an overall numerical rating that shows your security posture at a glance.
Compliance Posture Percentage: We track your adherence to over 100 industry frameworks (like NIST), giving you a clear percentage of compliance.
Issue Counts: You'll see precise numbers for unresolved Cloud Configuration, Vulnerability (categorised by severity), Attack Surface, and End-of-Life Findings.
Resolution Times: We help you measure Mean Time To Detect (MTTD) and Mean Time To Resolve (MTTR) for efficient remediation.
These metrics give you measurable insights, easily viewable in dashboards and exportable via API.
Reporting types
  • API access
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
No

Resellers

Supplier type
Reseller (no extras)
Organisation whose services are being resold
Wiz

Staff security

Staff security clearance
Other security clearance
Government security clearance
None

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
Other locations
User control over data storage and processing locations
No
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least every 6 months
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
  • Encryption of all physical media
  • Scale, obfuscating techniques, or data storage sharding
  • Other
Other data at rest protection approach
The physical and environmental security controls are provided by our underlying IaaS provider (AWS), this includes security cameras, lighting, fire detection/suppression, and power redundancy. Wiz employees do not have physical access to any of the data centers. AWS is responsible for implementing an appropriate set of controls in order to address physical security issues. Wiz reviews the Service Organisation Control (SOC) reports of AWS (subservice organisations) on an annual basis. Documentation of the review is retained.
Data sanitisation process
Yes
Equipment disposal approach
In-house destruction process
Data sanitisation type
Data Erasure

Data importing and exporting

Data export approach
Logs and specific findings be exported either through the API or generating custom reports (either in CSV for solely data, or Executive reports which are formatted in PDF).
Data export formats
  • CSV
  • Other
Other data export formats
  • PDF
  • JSON
Data import formats
Other
Other data import formats
  • Rego
  • JSON

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
Guaranteed Up Times
The service availability to customers is 99.5% of all Scheduled Available Time calculated on a monthly basis and excluding Scheduled Downtime as defined below, or circumstances beyond reasonable control.
Downtime
Downtime refers to any period within the Scheduled Available Time (excluding Scheduled Downtime) during which the Customer’s security team or users authorised by Customer are unable to log on with proper credentials. Scheduled Downtime for planned upgrades and maintenance will be detailed to the Customer, giving at least 48 hours prior notice. Wherever possible, this will be targeted for Sundays and limited to a maximum of four hours. Scheduled Downtime will not exceed 10 hours per calendar year. Any overrun beyond the planned completion time or the yearly limit will be considered Downtime.

Monthly Uptime Percentage: The Monthly Uptime Percentage is calculated using the following formula:

("User Minutes - Downtime"/"User Minutes" x 100)

Where Downtime is measured in user-minutes; that is, for each month, Downtime is the sum of the length (in minutes) of each Incident that occurs during that month multiplied by the number of users impacted by that Incident.
Service Credits:
Monthly Uptime Percentage Service Credit
< 99.5% = 10%
< 99% = 25%
Approach to resilience
Wiz runs isolated in multiple datacenters. Additionally, from a data perspective, we perform continuous backups and Business Continuity and Disaster Recovery (BCDR) readiness, supporting immediate transition to another availability zone or another region as required. Each Wiz data centre has a central region and a backup region, which can become active within hours.
Outage reporting
Current and historical information is available on https://status.wiz.io. Plus it's possible to subscribe to status alerts.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
Wiz has defined various user roles according to the various positions and activities in the company. Each Wiz employee and contractor is assigned one of these roles and receives the relevant access control privileges.
Users are required to log in to Wiz's Single Sign-on portal to access their user accounts. The authentication method employed depends on the sensitivity of the information asset, the authorisation level requested by the user and the access method used.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
Between 6 months and 12 months
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
Between 6 months and 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • ISO/IEC 27001
  • Other
Other security governance standards
"SOC2 Type 2
SOC3
ISO27701
HIPAA
CyberGRX
CAIQ
SIG
Information security policies and processes
Wiz leverages multiple layers of defence to protect key information and handles all critical facets of network and application security, including authentication, authorisation, and assurance. As a security provider focusing on security architecture, Wiz designed its internal architecture from the ground up for minimal manual intervention in the deployment and maintenance process. The production update process is fully automated, greatly reducing the risks to the service and to customers' data. The security program systematically evaluates our information security risks, taking into account the impact of company threats and vulnerabilities.
For reporting and transparency, Wiz provides a public Trust Centre, which is the single source of truth for the most accurate and up-to-date copies of security policies, certifications, and reports. Stakeholders can request access to the Compliance Command Centre through the Trust Centre to review these documents. More information can be provided with our security pack, including our attestations.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
The CI/CD pipeline is the only gateway into the Wiz production environment. This encompasses both code changes as well as infrastructure changes as we follow the GitOps principle of "everything is code". By baking controls into the CI/CD pipeline, including automated testing and mandatory code reviews, we can ensure that all code changes follow the same pipeline and are approved, reviewed, and audited before shipped to production. Furthermore, as we follow the immutable infra design pattern, any unauthorised change to production is immediately detected, flagged, and remediated.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Security incidents detected by Wiz employees, clients or business partners are reported to the Chief Security Officer (CSO). The CSO acts according to Wiz's "Incident Response Plan" procedure in classifying, handling, documenting and reporting the incident. The incident response plan is available under NDA.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
We leverage the Wiz natively-built controls engine to continuously validate the state of the infrastructure, review the inventory and ensure compliance with the required configuration baseline. More information is available under NDA.
Incident management type
Supplier-defined controls
Incident management approach
Wiz has an incident response plan, which is monitored as part of our SOC2 report audit.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
Alcumus ISOQAR
ISO/IEC 27001 accreditation date
Friday 21 December 2018
What the ISO/IEC 27001 doesn’t cover
Nothing
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
Bee1f05f-b715-4f2b-bc36-27fd6ddc66ab
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
D926878b-32ee-4e25-afa0-46693c10b31a
Other security certifications
Yes
Any other security certifications
CREST:SOC

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Plans to engage the contract workforce in deciding the most important workplace issues to address
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Volunteering opportunities for staff
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
    • How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
    • Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Plans for engaging a diverse range of businesses in engagement activities prior to appointing subcontractors (including activities prior to award of the main contract and during the contract term)
    • Structuring of the supply chain selection process to ensure fairness (e.g. anti-corruption) and encourages participation by a diverse range of businesses, including with regard to new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutual
    • Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
    • Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
    • Support for community-led initiatives relevant to the contract. Illustrative examples: improving transport links; reducing loneliness; helping with English language proficiency; and facilitating social mixing among people with different backgrounds
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
    • Creation of employment opportunities particularly for those who face barriers to employment, such as prison leavers, care leavers and/or who are located in deprived areas, and for people in industries with known skills shortages or in high growth sectors
    • Delivery of training schemes and programmes to address any identified skills gaps and under-representation in the workforce for the contract (e.g. prison leavers, care leavers, kinship carers, disabled people)
    • Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Offering a range of quality opportunities with routes of progression if appropriate, e.g. T Level industry placements, students supported into higher level apprenticeships.
    • Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Understanding of the issues affecting the development of new skills by target cohort
    • Understanding of issues relating to entering the contract workforce
    • Creation of outreach activities to create a pipeline of employees for the future contract delivery
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
    • Actions to invest in the physical and mental health and wellbeing of the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at sales@sep2.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.