An analyst working across several screens of data
Wiz Cloud Security

Wiz pricing in 2026 and how to negotiate it. The workload count sets the bill.

How Wiz counts billable workloads, what its public marketplace prices show, and the averaging, scoping and contract terms that decide what an enterprise pays.

Contact Us Negotiation Advisory
500+Enterprise clients
$2B+Under advisory
PublishedFebruary 26, 2026UpdatedSeptember 24, 2026
ContentsKey takeawaysHow Wiz pricing worksWhat we have seenWhy first counts run highThe averaging clauseModule scopeCompeting quotesRenewal timelineWhat to do nextFAQ

Wiz quotes enterprise deals individually and posts no prices on its own site. What you pay depends on how workloads are counted, how the count is averaged and which modules cover which accounts, so settle those before you discuss the rate.

Key takeaways
  • Workloads are the meter. Wiz Cloud is priced on billable workloads, with VMs, container hosts, serverless functions and data resources converted at ratios fixed in your order form.
  • First counts run high. Unverified counts in first proposals ran 20 to 40 percent above the measured average in deals we advised, so build your own from 90 days of billing data.
  • Write the averaging method down. A peak based count can run double the term average, which outweighs any extra discount points on offer.
  • Scope the expensive modules. Limiting runtime sensors and data security to crown jewel accounts cut proposals 25 to 35 percent with no coverage loss buyers could name.
  • Bring a real competing quote. At enterprise volume a competitor's price is the only outside reference, and it moved the rate even where the security team had already standardized on Wiz.
  • Lock the rate for the term. A multi year rate lock with fixed expansion rates is usually worth more than a deeper single year discount.

Wiz sells its cloud security platform on counted units and posts no prices on its own website. Three things set your bill: what gets counted, how the count is averaged, and which modules cover which accounts. Each one can be negotiated before you sign or renew.

The prices below come from Wiz's public AWS Marketplace listing. The cost examples are hypothetical, and the patterns come from the cloud security negotiations we have advised.

How does Wiz pricing work in 2026?

Wiz prices each module on its own unit and quotes every enterprise deal individually. Wiz Cloud, the agentless core, is counted in billable workloads. Wiz Code is counted in active developers, Wiz Defend in log ingestion, and the Wiz Sensor in deployed sensors.

The pricing page on wiz.io lists products and a quote form, with no figures. The only public prices sit on the AWS Marketplace listing, which sells packs of 100 units on 12, 24 or 36 month contracts. Most enterprise deals run through a private offer or a direct order form at a negotiated rate.

Wiz public pack prices on AWS Marketplace, 12 month contract
ModuleUnit soldPrice for 12 monthsImplied price per unit
Wiz Essential100 workloads$24,000$240 per workload
Wiz Advanced100 workloads$38,000$380 per workload
Wiz Sensor (add on for Advanced)100 sensors$28,000$280 per sensor
Wiz Code100 licenses$58,500$585 per license
Wiz Defend (add on for Advanced)300 GB of logs per month$18,000$60 per GB of monthly ingestion

Read these as small buyer prices. They show no volume tiers, and an enterprise buying thousands of workloads should expect a lower unit rate. They are still useful, because they are the one published reference in a category where the vendor otherwise produces every number in the deal.

What counts as a billable workload?

A billable workload is not the same as a server. Virtual machines, container hosts, serverless functions and data resources each convert into billable workloads at ratios written into your order form, and the ratio differs by resource type. Wiz's public pages do not list those ratios, so the order form is the only place they are fixed.

The same number of cloud resources can therefore produce very different counts depending on your mix. Ask for the ratio schedule as an attachment to the order form, then check it against your own split of VMs, Kubernetes nodes, functions, buckets and databases before you accept any total.

What have we seen in recent cloud security negotiations?

Across roughly 10 to 14 cloud security negotiations we advised in 2024 and 2025, the definition of a workload decided the spend more than the unit rate did. Three patterns came up again and again.

  • Inflated counts. Unverified workload counts in first proposals ran 20 to 40 percent above the measured average, once autoscaling and ephemeral infrastructure were counted correctly.
  • Module scope. Buyers who limited runtime sensors and data security to crown jewel accounts, instead of rolling them out everywhere, cut the proposal 25 to 35 percent. Asked afterwards, none could name any security coverage they had given up.
  • Competition. A live competing quote moved the rate 15 to 30 percent, including in accounts where the security team had already standardized on the platform.

The third pattern surprises security teams most. Many treat the platform decision as the end of the commercial discussion. In our experience the rate stays open for as long as you hold a priced alternative.

Free white paper

Cloud Security Negotiation Brief

The counting rules, contract terms and scoping test from this guide, in one document.

Get the white paper →

Why is the first Wiz workload count usually too high?

The first proposal is normally built from Wiz's connector scan, and a scan counts whatever exists when it runs. Autoscaling groups at full size, short lived containers and abandoned development accounts all land in it. Once signed, that number becomes the baseline for the next renewal, so the excess compounds each term.

Your cloud bill is the neutral record. It shows what you paid to run, month by month, and a scan taken in a busy week cannot contradict it. Build the count from billing data and ask the vendor to reconcile to your number.

How do you build a count Wiz has to accept?

  1. Use billing data as the inventory. Take at least 90 days of billing exports in place of the connector scan. The bill records the whole period, while a scan captures one moment.
  2. Average across the whole window. Calculate the daily count and average it, then write that averaging method into the order form so the vendor cannot switch to a peak later.
  3. Agree the ephemeral ratios. Settle how spot nodes and short lived containers convert to billable workloads. That conversion is fixed in the order form, and the product documentation will not protect you if the form says otherwise.
  4. Split production from non production. Development environments can often license at reduced rates or stay out of scope entirely, but only if you ask before signature.
  5. Purge decommission drift. Dead accounts and orphaned resources persist in scans long after they have left your bill. They are counted at full rate until someone removes them.

Where do you find the real numbers in your own clouds?

  • AWS. Cost and Usage Reports, now delivered through AWS Data Exports, break EC2, Lambda and EKS usage down by account and by hour. AWS Config shows which resources still exist.
  • Microsoft Azure. Cost Management exports give daily usage by subscription and resource, and Azure Resource Graph lists live resources across subscriptions.
  • Google Cloud. The Cloud Billing export to BigQuery gives detailed usage by project, and Cloud Asset Inventory lists current resources.
  • Kubernetes. Node counts over time, for example the kube_node_info metric in Prometheus or CloudWatch Container Insights on EKS, show how many container hosts actually ran against the maximum the cluster autoscaler allowed.
  • Wiz. Ask the account team for the usage report behind the proposal, broken down by cloud account, resource type and day, so you can reconcile it line by line.

What should the Wiz averaging clause say?

The averaging clause decides whether you pay for your peak, a monthly average or the average across the term. In an elastic environment a peak based count can run double the term average, so this one sentence is worth more than two extra discount points. Put it in the order form in writing.

A worked example of peak versus average

Say your term average is 1,200 workloads, your busiest month averages 1,500, and a quarter end batch run pushes a single day to 2,400. At the $380 per workload implied by the Wiz Advanced marketplace pack, the counting method alone changes the annual bill like this.

Hypothetical: the same environment under three counting methods
Counting methodWorkloads billedAnnual cost at $380 per workload
Peak day2,400$912,000
Busiest monthly average1,500$570,000
Average across the term1,200$456,000

Moving from a peak count to a term average saves $456,000 in this example. Two extra discount points on the peak based bill would save $18,240. Your negotiated rate will likely be lower than $380, but the proportions hold at any rate.

A peak based count charges you for the busiest day of the year on every day of the term.
A spreadsheet cost model displayed on a computer screen
Finance teams already reconcile cloud bills every month for chargeback, so the export behind that work can double as the workload count you take into the negotiation.

Which contract terms should you ask for?

  • Averaging method. Billable workloads measured as the average of daily counts across the subscription term. This stops a short spike from setting the price.
  • Ratio schedule. The conversion ratio for each resource type, attached and fixed for the term, so a change in how Wiz counts container hosts or functions cannot raise your bill mid contract.
  • Non production accounts. The development and test accounts named, with their reduced rate or their exclusion stated.
  • Growth at the contract rate. Usage above the committed count billed at the same unit rate, and only after the average exceeds the commitment for a full quarter, so one busy month does not trigger a true up.
  • Expansion price holds. Pre agreed rates for adding workloads, sensors, Defend ingestion or Code licenses during the term.
  • Reduction at renewal. The right to renew at a lower count when decommissioned workloads leave the bill, keeping the same unit rate.
  • Active developer definition. For Wiz Code, the lookback period and the activity that makes a developer billable, in writing.

Which Wiz modules should cover everything, and which should not?

Core Wiz Cloud coverage belongs in every cloud account, because misconfigurations and attack paths only show up when the scan looks everywhere. Runtime sensors, data security and code security rarely need that reach. Scope them to accounts where the risk justifies the rate, and expand later at pre agreed rates.

Sensible scope for each Wiz module
ModuleWhat it coversSensible scope
Core cloud security (Wiz Cloud, CSPM)Misconfigurations and attack pathsEvery cloud account
Runtime sensor (Wiz Sensor)Workload runtime detectionProduction crown jewels
Data security (DSPM scanning in Wiz Cloud)Data discovery and exposureAccounts holding regulated data
Code security (Wiz Code)Infrastructure as code and pipeline scanningActive development organizations only

The sensor shows how much scope is worth. Say you run 800 production hosts. At the marketplace price of $280 per sensor, covering all of them costs $224,000 a year, while limiting the sensor to 250 crown jewel hosts costs $70,000.

How do you test whether a narrow scope is safe?

After scoping the expensive modules to crown jewel accounts, ask your security team which coverage you actually surrendered. If they name a concrete gap, such as an unmonitored production service that handles payments, widen the scope there. If the answer is a general unease about coverage, the narrow scope stands.

The question turns a debate about risk appetite into a check of scope discipline. It also gives procurement a written reason for every account in or out of scope, which helps at renewal when the vendor proposes rolling modules out further.

Why we would not chase the biggest platform bundle discount

The common advice is to consolidate onto the full Wiz platform and take the largest bundle discount on offer. For most buyers we disagree. The discount looks generous until you price the modules you would not otherwise buy, which is the usual shape of a consolidation offer where enterprise prices are private.

Buy the modules that have a named owner and a stated use case, and let the vendor justify the rest. Fixed expansion rates mean a module added later costs no more than it would today. Palo Alto sells a comparable multi module platform, and our Palo Alto licensing guide covers how its packaging compares.

How does this change with the size of your cloud footprint?

  • A few hundred workloads. Marketplace packs of 100 may be the simplest route, and Wiz also sells a Wiz Go bundle for smaller businesses. Put your effort into module scope, where the sums are largest relative to the deal.
  • Several thousand workloads. Negotiate a private offer. The counting method and the ratio schedule carry most of the value, and a competing quote is your main pressure on the rate.
  • Tens of thousands across several clouds. Split the count by cloud and by business unit so each part can be verified, and ask for the right to shift workloads between clouds without a new order form.
  • Buying through a cloud marketplace. Check whether the purchase counts toward an existing committed spend agreement with that provider. Our AWS Marketplace procurement guide explains how that works on AWS.

How much can a competing quote move Wiz pricing?

In the negotiations described above, a live competing quote moved the rate 15 to 30 percent, even after the buyer had standardized on Wiz. The marketplace packs show what a small buyer pays. At enterprise volumes a competitor's price is the only outside reference, so a quote works even when you have no plan to switch.

Credible sources include Palo Alto Networks Cortex Cloud (the successor to Prisma Cloud), CrowdStrike Falcon Cloud Security, Microsoft Defender for Cloud and Orca Security, quoted for the same workloads, modules and term. Our Prisma Cloud negotiation guide and CrowdStrike Falcon negotiation guide cover two of them, and the neighboring secure access market sits in the Zscaler negotiation guide.

What will the Wiz account team say, and how should you answer?

  • "The count comes straight from your environment." The scan is one moment. We will reconcile to 90 days of billing data, and the averaged figure is what we sign.
  • "The bundle price only applies if you take the full platform." Price each module separately so we can see the real bundle discount, and quote fixed expansion rates for the modules we defer.
  • "Development accounts need the same protection as production." They get core Wiz Cloud coverage. Name the non production rate, or the exclusion, before we sign.
  • "This pricing is only valid until the end of the quarter." We will sign when the count and the averaging clause are agreed. The deadline does not change our workload numbers.

Is a multi year rate lock worth more than a bigger first year discount?

Usually, yes. The Wiz price book changes quickly, and single year deals reprice at renewal against a baseline that rises as your cloud grows. A rate lock tends to be worth more than the extra points on a deeper one year discount, and the marketplace listing already offers 24 and 36 month terms.

When should you start preparing a Wiz renewal?

Start 12 months before the renewal date if you want to set the count yourself. The billing window needs 90 days of clean data, and module scoping and a competing quote each need time before quarter end pressure arrives.

Wiz renewal timeline
Before renewalWhat to doWhat you should have
12 monthsStart billing exports; tag production, non production and decommissioned accountsA clean resource list
6 monthsBuild the 90 day averaged count and request Wiz's usage reportA reconciled workload count
3 monthsScope modules, run the coverage test, request competing quotesModule scope and a priced alternative
1 monthPaper the averaging clause, ratio schedule, non production terms and rate lockAgreed order form language

Which mistakes cost Wiz buyers the most?

  • Negotiating only the discount. A discount on an inflated count still leaves you paying for workloads you do not run, and that count becomes next term's baseline.
  • Leaving the averaging method to standard terms. If the order form is silent, the vendor's default applies, and you find out which one at the first true up.
  • Buying expansion up front. Paying now for sensors or Code licenses you may deploy next year costs more than a contract right to add them later at a fixed rate.
  • Losing the terms in a marketplace private offer. A private offer carries its own license agreement. If the averaging clause, ratio schedule and non production terms are not attached to the offer itself, the negotiated wording may not apply to what you buy.

What to do next

  1. This month. Pull at least 90 days of billing exports from every cloud and tag production, non production and decommissioned accounts.
  2. Before the first proposal. Build your own averaged workload count and ask Wiz for the usage report behind its number, by account and resource type.
  3. In the order form. Write in the averaging method and attach the ratio schedule, including how spot nodes and short lived containers convert.
  4. Before signature. Agree the non production rate or exclusion, and scope the sensor, data security and Code to crown jewel and active development accounts.
  5. Three months out. Get a live competing quote for the same scope, and ask for a multi year rate lock with fixed expansion rates.
  6. If you want help. Vendor Shield builds the count with you and negotiates the order form terms on your side of the table.

Frequently asked questions

How does Wiz pricing work?

Wiz licenses each module on its own unit: workloads for Wiz Cloud, active developers for Wiz Code, log ingestion for Wiz Defend and deployed sensors for the Wiz Sensor. Enterprise deals are quoted individually, usually as a private offer, so the counting rules in your order form do the job a price list does for other vendors.

Why does the Wiz workload count need auditing?

Because the vendor's first number measures a single moment and then carries forward. Whatever sits in the signed count becomes the starting point for every renewal, so an inflated baseline costs you again each year. Checking it once against billing data corrects every later term as well.

What is the averaging clause and why does it matter?

It is the sentence that says whether billable workloads are measured at peak, as a monthly average or as an average over the term. Elastic environments swing widely, so the method can change the bill more than any rate discount. It is often missing from the order form, which leaves the vendor's default in charge.

Which Wiz modules should be scoped narrowly?

Usually the Wiz Sensor, data security scanning and Wiz Code. Keep core Wiz Cloud coverage across every account, then put sensors on production crown jewel workloads, data security on accounts with regulated data, and Code on teams that actively ship infrastructure as code.

Does a competing quote help if we have already standardized on Wiz?

Yes. A quote changes the rate discussion even when switching is unlikely, because it gives the account team a price it has to beat for your volume. Keep it honest: same workloads, same modules, same term, from a vendor your security team would accept.

Should development environments be in scope for Wiz?

Often not, or not at full rate. Name the development and test accounts in the order form and agree their rate or exclusion before signature. Raised at true up instead, the same request becomes a plea for a concession, which is a much weaker position.

Is a multi year Wiz term worth it?

Usually. Single year deals reprice at each renewal against a baseline that tends to rise as your cloud grows and Wiz adds modules. A 24 or 36 month rate lock, with pre agreed expansion rates, protects the unit price, and that matters more than a few extra points of first year discount.

Has Google's acquisition of Wiz changed how it is sold?

Google closed the deal on March 11, 2026 and has said Wiz products will stay available across AWS, Microsoft Azure, Google Cloud and Oracle Cloud. Existing contracts carry on. At renewal, confirm that unit definitions and the ratio schedule are unchanged, and check whether a marketplace purchase counts toward your cloud spend commitment.

Newsletter
Licensing news that changes what you pay

One email a week on vendor price moves, audit activity and what worked in recent renewals.

Subscribe
Vendor Shield
An advisor on call for every vendor conversation

Always on advisory for renewals, audits and contract questions across your software vendors.

Explore Vendor Shield
Advisory White Paper

Get the cloud security negotiation brief, as a guide.

The workload counting rules, the averaging clause, module scoping by risk and the competitive quotes that change a CNAPP price.

Gated with a work email on the download page. No sales follow up you did not ask for.

Get the White Paper →
We never share your details with vendors.

enterprise software licensing news, once a week.

Price changes, audit activity and what worked in recent renewals. No vendor spin.