Screenata

Integrations / Security & monitoring

Screenata + Wiz

How do you turn Wiz into SOC 2 and ISO 27001 evidence?

Quick answer

Wiz does the detecting. SOC 2 CC3.2 and CC7.1 and ISO 27001 A.8.8 then ask you to prove the risk and vulnerability management program around it operates, which is a different question from whether the scanner sees your cloud. Having Wiz is not the control. The control is the enforced configuration, such as full coverage of the cloud estate and findings triaged, owned, and closed inside your policy timelines, plus the record that it operated across the whole audit period. Screenata syncs Wiz findings on a schedule into a risk register where each one carries a control mapping, an owner, and a treatment plan, recorded as signed evidence and with risk acceptance always requiring human approval.

Screenata connects to Wiz read-only and syncs cloud risk findings into the Screenata risk register, where each risk is linked to controls, given an owner and treatment plan, and tracked to resolution. The sync turns Wiz's security signal into the governed risk management record SOC 2 and ISO 27001 auditors test.

Read-only · signed evidence

What it proves

Wiz evidence, mapped to controls.

Each area below is scanned on a schedule. A finding is not a green checkmark: it is a signed artifact an auditor can verify, mapped to the exact requirement it satisfies.
Evidence area
What the checks verify
Maps to
Cloud risk findings

Findings from Wiz are synced into the risk register as candidate risks, deduplicated against what is already tracked.

A risk register that reflects what your cloud security tooling actually sees, not what someone remembered to type in.

SOC 2CC3.2SOC 2CC7.1
Risk treatment tracking

Synced risks carry owners, treatment plans, and due dates inside the register, with risk acceptance always requiring human approval.

The treatment record auditors sample: every identified risk either mitigated, accepted by a human, or in progress with an owner.

SOC 2CC3.2ISO 27001A.8.8

Control references are the requirements each evidence area supports, via the shared control catalog. Your auditor decides sufficiency; the artifacts are theirs to verify.

How it connects

Read-only, revocable, yours.

You create read-scoped API credentials and Screenata uses them to sync findings on a schedule. Vera never receives write access to your Wiz tenant, and credentials never touch the Screenata database.

Read-only by construction

OAuth scopes and IAM roles are scoped to read. Vera never gets write access to your systems.

Signed findings

SHA-256 per artifact, RSA/ECDSA signatures, RFC 3161 timestamps. Verifiable without a Screenata account.

Mapped to controls

Each finding lands on the shared control catalog, so one scan satisfies SOC 2, HIPAA, and ISO 27001 at once.

Wiz FAQ

What teams ask before connecting.

Full provider list on the integrations page.
What access does Screenata need to Wiz?

Read-scoped API credentials that you create and control. Screenata uses them to sync findings on a schedule and never receives write access to your Wiz tenant. You can revoke them at any time.

Does Screenata replace Wiz?

No. Wiz finds the cloud risks; Screenata governs them. The sync feeds Wiz findings into a risk register with owners, treatment plans, and human-approved acceptances, which is the record an auditor tests.

Do Wiz findings become audit evidence automatically?

They become risk register entries linked to controls. What auditors see is the governed record: the risk, its assessment, its owner, and its treatment history, all signed like any other artifact. Risk acceptance always requires human approval.

What are the steps to implement SOC 2 with Wiz?

First, create read-scoped API credentials and connect them. Second, let the first sync run so the baseline is the set of findings Wiz actually sees across your cloud estate, deduplicated against risks you already track. Third, work the register down: confirm every account and subscription is in Wiz coverage so nothing sits outside the program, give each synced risk an owner, a treatment plan, and a due date, and close the critical findings inside the timelines your vulnerability management policy sets, with any acceptance approved by a named human rather than left implicit. Fourth, leave the scheduled syncs running so the register and its treatment history accumulate as signed evidence across the observation window, which for a Type 2 report is usually three to twelve months. Fifth, hand the evidence package to an independent auditor. The audit is a separate engagement with a licensed CPA firm, which issues the report; Screenata prepares and holds the evidence it asks for.

What evidence do auditors ask for about vulnerability management?

Three things. Coverage across the whole estate, so the scanned population matches the asset register and no account, subscription, or workload sits quietly outside the program. A documented severity triage with remediation timelines, so critical and high findings have a defined window rather than an open-ended one. And a record showing findings were actually worked down inside those timelines, not just discovered. Detection is the easy half. The finding auditors write up is the open critical that sat past its own deadline with no owner.

Do auditors accept evidence Screenata collects from Wiz?

Yes. Every finding is exported as a signed, timestamped artifact, a SHA-256 hash with an RSA or ECDSA signature and an RFC 3161 timestamp, that an auditor verifies outside Screenata with a free CLI. A person reviews and approves the evidence before it reaches the auditor. Screenata collects and signs it; it does not decide the audit result.

Connect and see

Fifteen minutes after connecting Wiz, you know your real posture.

Pricing

Related: Snyk · CrowdStrike · AWS · Datadog