Wiz vs Orca: Agentless CNAPP, Two Graphs
Choose Wiz when toxic combinations on a security graph are the product. Choose Orca when SideScanning without a host agent is the product.
Shortlists treat Wiz and Orca as one interchangeable agentless CNAPP graph. On Hacker News, one comment put it bluntly during the Google-to-buy-Wiz thread: Orca is “pretty much the same product.” That is the wrong assumption.
They are both agentless multicloud CNAPP platforms. Between these two, Wiz productizes toxic combinations and attack paths on its Security Graph. Orca productizes SideScanning: an out-of-band read of runtime block storage that rebuilds a workload filesystem without installing a host agent.
If you already run CSPM checklists, the gap is not “another posture scan.” It is which agentless model and which prioritization story you want the team to live in. The wider shortlist lives on cloud security platforms; posture-only tools stay on CSPM tools.
| Job | Agentless CNAPP centered on the Security Graph and toxic-combination Issues | Agentless-first CNAPP centered on SideScanning plus context-aware risk scoring |
|---|---|---|
| How risk is scored | Toxic combinations / attack paths on the Security Graph become critical Issues | Multi-factor score (severity, exploitability, accessibility, business impact) with attack paths and reachability |
| Deploy | Agentless cloud connectors; Wiz Sensor is a separate runtime module on the pricing page | SideScanning via cloud APIs / shared virtualization; optional Orca Sensor for runtime |
| Runtime | Optional Wiz Sensor; agentless findings follow scan cadence (CVA shortens catalog lag) | SideScanning is out-of-band / snapshot-shaped; Orca Sensor adds real-time CDR |
| Multicloud vs home-cloud gravity | Markets multicloud CNAPP across major public clouds | Markets multicloud CNAPP across major public clouds (and related estates) |
| License/pricing | Sales-quoted modular licenses (Cloud, Code, Defend, Sensor, Go Bundle) | Sales-quoted; no public dollar SKU on orca.security |
| Who operates it | Cloud security and platform engineering; code modules may sit with AppSec | Cloud security and platform engineering; sensor scope set with runtime owners |
Recent launches have not collapsed that split. On 1 September 2026 Wiz introduced Continuous Vulnerability Assessment (CVA) in Public Preview so newly published CVEs can be reassessed without waiting for the next scheduled scan. On 21 July 2026 Orca connected Claude Enterprise via the Compliance API, extending the same Unified Data Model into AI org settings and identities. One still leads with graph Issues. The other still leads with SideScanning depth.
A comment on Hacker News in August 2026 described the buyer pressure from the other side of the ticket: customers who run agentless scanners such as Wiz against vendor-installed cloud estates and then demand remediations. That is why these two land on the same shortlist. It is not proof they are identical.
We reviewed first-party documentation, public pricing pages, release notes, and live community threads. We did not test the products in paid production environments, so this is not a hands-on benchmark.
Wiz

Orca Security

Editions and pricing
Neither vendor publishes a self-serve dollar table that a spreadsheet can trust without sales. Packaging still differs: Wiz lists modular lines on its pricing page; Orca sells the platform as a sales conversation with SideScanning first and Sensor optional.
| Public price table | Request-quote form. Licensing is modular by workloads, developers, log ingestion, or sensors | No public dollar SKU on orca.security (verified 5 Sep 2026). Request a demo / sales quote |
|---|---|---|
| Named lines | Wiz Cloud, Wiz Code, Wiz Defend, Wiz Sensor, Wiz Go Bundle for SMBs | Agentless platform first; Orca Sensor called out as the runtime add-on |
| What the quote usually meters | Cloud workloads and optional modules (sensor, code, defend, log volume) | Protected cloud workloads and whether Sensor / extra modules are in scope |
| Free forever SKU | None on the public pricing page | None on the public site |
If procurement needs a published monthly seat price before a call, both vendors will stall that spreadsheet. Ask for workload counting rules, sensor uplift, and true-up language in the same quote.
How findings are prioritized
| Primary unit | Toxic combination / attack path surfaced as a critical Issue on the Security Graph | Context-aware risk score with attack path analysis and reachability |
|---|---|---|
| What raises priority | High likelihood of compromise plus significant business impact when risks combine | Severity (CVSS/EPSS), exploitability, accessibility, and business impact together |
| False-positive pressure | Graph context aims to shrink thousands of vulns into tens of critical paths | Reachability and path context aim to demote packages that are never loaded or reachable |
| DSPM / data in the score | Sensitive data and exposure participate in toxic combinations on the graph | DSPM is a named platform pillar; PII and crown-jewel adjacency feed the score |
Between these two, do not buy “attack path” as a unique checkbox. Both sell path-shaped prioritization. Buy the unit your operators will open every morning: a Wiz Issue built from toxic combinations, or an Orca score that reorders when exposure and reachability change.
What the agentless scan actually reads
| Agentless core | Agentless disk and cloud configuration analysis feeding the Security Graph | SideScanning reads runtime block storage out of band and rebuilds a virtual filesystem |
|---|---|---|
| Host agent required? | No for the agentless core; Wiz Sensor is optional for runtime | No for SideScanning; Orca Sensor is optional for real-time runtime |
| Cadence limit | Findings follow scan / reassessment cadence; CVA targets near-real-time CVE catalog updates | Out-of-band snapshots by design; Sensor covers in-memory / live activity SideScanning cannot |
| What teams argue about | Graph coverage vs scan delay and cloud cost of volume cloning | Depth of filesystem evidence vs how often snapshots refresh |
That practitioner note maps to the Runtime row: agentless volume analysis is powerful and still cadence-bound, which is why both vendors sell an optional sensor. Orca’s SideScanning page states the mirror claim for its model: it reads block storage out of band so nothing runs on the workload itself.
Where they overlap
Both are agentless CNAPP products for multicloud estates. Both correlate vulnerabilities, misconfigurations, identities, and data into toxic or path-shaped risk. Both offer an optional lightweight runtime sensor on top of the agentless core. If your RFP only says “agentless CNAPP with attack paths,” both will tick the box.
When to use both
Running both is rare and usually wasteful. One security graph is enough for most cloud security teams. Keep a second only during a time-boxed bake-off, or when a regulated estate forces a parallel validation you cannot fold into one tenant.
Skip Orca for this pair if the buying committee already standardized on Wiz Issues and the Security Graph, and SideScanning depth is not a requirement. Skip Wiz for this pair if the team wants SideScanning filesystem evidence as the default agentless read and is willing to live in Orca’s score and Unified Data Model.
Decide the agentless model first. If the product must be toxic combinations on a security graph, that is Wiz. If the product must be out-of-band block-storage SideScanning, that is Orca. Only then open the sales quotes.
FAQs
Are Wiz and Orca the same agentless CNAPP?
No. Both are agentless multicloud CNAPP, but between these two Wiz leads with Security Graph toxic combinations, and Orca leads with SideScanning of runtime block storage.
Do I need the runtime sensor on day one?
Often no. Both platforms sell agentless-first coverage. Add Wiz Sensor or Orca Sensor when snapshot cadence or in-memory threats become the gap.
Is there a public list price?
Not a trustworthy self-serve dollar table on either first-party pricing surface we checked on 5 Sep 2026. Expect sales-quoted contracts metered on workloads and modules.
Is this a scored bake-off?
No. Order is editorial.