Integrations / Security & monitoring
Screenata + WizHow do you turn Wiz into SOC 2 and ISO 27001 evidence?
Quick answer
Wiz does the detecting. SOC 2 CC3.2 and CC7.1 and ISO 27001 A.8.8 then ask you to prove the risk and vulnerability management program around it operates, which is a different question from whether the scanner sees your cloud. Having Wiz is not the control. The control is the enforced configuration, such as full coverage of the cloud estate and findings triaged, owned, and closed inside your policy timelines, plus the record that it operated across the whole audit period. Screenata syncs Wiz findings on a schedule into a risk register where each one carries a control mapping, an owner, and a treatment plan, recorded as signed evidence and with risk acceptance always requiring human approval.
Screenata connects to Wiz read-only and syncs cloud risk findings into the Screenata risk register, where each risk is linked to controls, given an owner and treatment plan, and tracked to resolution. The sync turns Wiz's security signal into the governed risk management record SOC 2 and ISO 27001 auditors test.
Read-only · signed evidence
What it proves
Wiz evidence, mapped to controls.
Findings from Wiz are synced into the risk register as candidate risks, deduplicated against what is already tracked.
A risk register that reflects what your cloud security tooling actually sees, not what someone remembered to type in.
Synced risks carry owners, treatment plans, and due dates inside the register, with risk acceptance always requiring human approval.
The treatment record auditors sample: every identified risk either mitigated, accepted by a human, or in progress with an owner.
Control references are the requirements each evidence area supports, via the shared control catalog. Your auditor decides sufficiency; the artifacts are theirs to verify.
How it connects
Read-only, revocable, yours.
Read-only by construction
OAuth scopes and IAM roles are scoped to read. Vera never gets write access to your systems.
Signed findings
SHA-256 per artifact, RSA/ECDSA signatures, RFC 3161 timestamps. Verifiable without a Screenata account.
Mapped to controls
Each finding lands on the shared control catalog, so one scan satisfies SOC 2, HIPAA, and ISO 27001 at once.
What access does Screenata need to Wiz?
Read-scoped API credentials that you create and control. Screenata uses them to sync findings on a schedule and never receives write access to your Wiz tenant. You can revoke them at any time.
Does Screenata replace Wiz?
No. Wiz finds the cloud risks; Screenata governs them. The sync feeds Wiz findings into a risk register with owners, treatment plans, and human-approved acceptances, which is the record an auditor tests.
Do Wiz findings become audit evidence automatically?
They become risk register entries linked to controls. What auditors see is the governed record: the risk, its assessment, its owner, and its treatment history, all signed like any other artifact. Risk acceptance always requires human approval.
What are the steps to implement SOC 2 with Wiz?
First, create read-scoped API credentials and connect them. Second, let the first sync run so the baseline is the set of findings Wiz actually sees across your cloud estate, deduplicated against risks you already track. Third, work the register down: confirm every account and subscription is in Wiz coverage so nothing sits outside the program, give each synced risk an owner, a treatment plan, and a due date, and close the critical findings inside the timelines your vulnerability management policy sets, with any acceptance approved by a named human rather than left implicit. Fourth, leave the scheduled syncs running so the register and its treatment history accumulate as signed evidence across the observation window, which for a Type 2 report is usually three to twelve months. Fifth, hand the evidence package to an independent auditor. The audit is a separate engagement with a licensed CPA firm, which issues the report; Screenata prepares and holds the evidence it asks for.
What evidence do auditors ask for about vulnerability management?
Three things. Coverage across the whole estate, so the scanned population matches the asset register and no account, subscription, or workload sits quietly outside the program. A documented severity triage with remediation timelines, so critical and high findings have a defined window rather than an open-ended one. And a record showing findings were actually worked down inside those timelines, not just discovered. Detection is the easy half. The finding auditors write up is the open critical that sat past its own deadline with no owner.
Do auditors accept evidence Screenata collects from Wiz?
Yes. Every finding is exported as a signed, timestamped artifact, a SHA-256 hash with an RSA or ECDSA signature and an RFC 3161 timestamp, that an auditor verifies outside Screenata with a free CLI. A person reviews and approves the evidence before it reaches the auditor. Screenata collects and signs it; it does not decide the audit result.
Connect and see
Fifteen minutes after connecting Wiz, you know your real posture.
Related: Snyk · CrowdStrike · AWS · Datadog