The Anthropic Cyber Verification Program expanded on October 6, 2026, folding two earlier trusted-access efforts into one offering with three access tiers. Vetted security teams can now apply for reduced cyber safeguards on Claude Opus 5.5, Claude Sonnet 5.5 and Claude Mythos 5.1. How much access they get depends on the security work they are authorized to do.
This is a policy shift as much as a product update. Anthropic’s generally available models block most cyber work by default. For approved organizations, the expanded program swaps that blanket restriction for identity verification, tiered classifiers and mandatory data retention.
Here is what Anthropic confirmed about each tier, what it reports about vulnerability findings, where those numbers fall short, and what SOC teams, red teams and security leaders should check before applying.
Quick Answer
The Anthropic Cyber Verification Program gives verified security teams reduced cyber safeguards on Claude Opus 5.5, Sonnet 5.5 and Mythos 5.1 through three tiers: Defense Access for defensive work, Red Team Access for authorized penetration testing, and Specialized Access for organizations testing safety-critical systems. Approved organizations must allow data retention so Anthropic can monitor for misuse.
What Anthropic Confirmed
Anthropic framed the change as a merger of two programs it had run for about six months. Project Glasswing gave organizations that secure critical software access to Claude Mythos. The earlier Cyber Verification Program (CVP) gave vetted security teams reduced safeguards on Claude Opus and Sonnet models.
Both now sit inside one offering, and every tier includes Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1 and future models.
The restrictions exist because cybersecurity is dual use. The capability that lets a defender find and fix a flaw can also help an attacker exploit it. So Anthropic’s generally available models, including Claude Opus 5.5, Claude Fable 5.1 and Claude Sonnet 5.5, ship with conservative Claude cybersecurity safeguards that block most cyber work. Anthropic says it is still working to cut false positives for secure coding.
Teams outside the program are not shut out entirely. Anthropic says the generally available models still handle code review, patching known issues, vulnerability finding in owned source code and triage of security alerts.

The Three Access Tiers
Each tier of the Anthropic Cyber Verification Program has its own verification requirements and security controls. The table summarizes what Anthropic published.
| Tier | Authorized work | Example eligible organizations | Review time | Key limits |
|---|---|---|---|---|
| Defense Access | SOC and incident response tasks, malware reverse engineering, vulnerability analysis and validation | Security teams defending systems they own or maintain, critical infrastructure operators of any size, smaller security firms, open-source maintainers, individual researchers with a track record of reported vulnerabilities | Anthropic aims to respond within a few days | Does not include penetration testing or red-teaming |
| Red Team Access | Everything in Defense Access plus authorized penetration testing and red-teaming | In-house red teams, government red teams, security and penetration testing firms | A few weeks; applicants are enrolled in Defense Access during review | Organizations only; testing limited to systems the organization is authorized to test; real-time blocks remain for actions that could cause physical harm or mass disruption |
| Specialized Access | Fewest cyber blocks; testing of safety systems that could affect lives or disrupt markets | A limited set of verified organizations, for example those testing flight operating systems, power grids, telecom networks, interbank transfer infrastructure or government administrative networks | Every organization is currently reviewed in depth in collaboration with the US government | Existing Project Glasswing members transition here without reapproval for current models |
Defense Access
This tier covers the daily work of blue teams, so Claude cybersecurity use here centers on triage, incident response, malware analysis and confirming whether a suspected flaw is real. Anthropic expects many organizations doing defensive work to qualify. It named regional hospitals and municipal utilities as examples of critical infrastructure operators that can apply regardless of size. Individual researchers can apply too, if they have a record of reported vulnerabilities.
Red Team Access
For AI cybersecurity red teaming, this is the tier that matters. It adds authorized penetration testing and adversarial testing, including against IT systems in critical industries.
Anthropic still blocks, in real time, actions that could cause physical harm or mass disruption. Its examples are deploying ransomware, damaging physical systems and pen testing high-risk safety systems. Individual researchers are not eligible for this tier today.
Specialized Access
This tier has the fewest cyber blocks. Anthropic reserves it for verified organizations authorized to test systems where a failure could affect people’s lives or disrupt markets. The vetting is heavier to match: Anthropic currently reviews each applicant in depth in collaboration with the US government.

How the Anthropic Cyber Verification Program Handles Verification and Monitoring
Anthropic says it verifies every applicant and asks for proof of the security controls required for the requested tier. A few operating details matter for security leaders:
- Data retention is required. Anthropic says it needs retained data to monitor for cyber misuse.
- A zero data retention path is coming. Anthropic says Enterprise Frontier Safeguards (EFS) will arrive later this fall and will let eligible organizations store data in cloud infrastructure they control. Until then, organizations with access to Claude Fable 5.1 or Claude Mythos 5.1 under zero data retention can also use the program under zero data retention.
- Existing members carry over. Current CVP members keep their settings for previous models and are automatically evaluated for Opus 5.5, Sonnet 5.5 and Mythos 5.1.
- Admins assign access by workspace. Anthropic says admins must assign the program to specific workspaces.
- Platform coverage varies. The program is available on the Claude Platform, Google Cloud’s Vertex AI and Microsoft Foundry. On Amazon Bedrock it is available only to customers eligible for EFS.
- Misclassified blocks can be reported. Anthropic provides a form for blocks that seem inconsistent with a team’s approved tier.
One note on documentation. Anthropic’s Help Center article on real-time cyber safeguards still describes the earlier version of the program, and says it does not apply to Opus 5.5 or Sonnet 5.5. That page also separates prohibited use, such as mass data exfiltration and ransomware code development, from high-risk dual-use work that approved users can unlock. Treat it as legacy context and rely on the October 6 announcement for the new tiers.

What the CyScenarioBench Results Show
Anthropic tested its tier safeguards with CyScenarioBench, an evaluation of whether models can plan and execute multi-stage cyber operations under realistic constraints. The company ran Claude Opus 5.5 through five attempts at each of 10 challenges in each tier. It is the clearest Claude Opus 5.5 security evaluation in the announcement.
| Tier | Result reported by Anthropic |
|---|---|
| No program access | Every task blocked on the first prompt |
| Defense Access | 46 of 50 trials blocked at some point; 4 succeeded |
| Red Team Access | No blocks; 34 of 50 tasks completed |
| No safeguards (representative of Specialized Access) | 67.6% success rate on this evaluation |
Anthropic says the Red Team Access completion rate is effectively equivalent to the no-safeguard rate. It also says it expected significant blocks without program access and in Defense Access, and no blocks in the two higher tiers, so the results confirm the intended design.
CyberInfos analysis: these are company-run results on one benchmark, with 50 trials per tier. They show that Anthropic’s classifiers behave as designed on this test. They say little about how the controls hold up against a determined adversary, a compromised verified account or an approved user who exceeds their authorization. CyberInfos has not seen independent replication.

AI Vulnerability Discovery Results: Reported Figures and Limits
Anthropic also published results on AI vulnerability discovery from Project Glasswing. These are company-reported figures, and Anthropic itself calls them a lower bound.
What Anthropic reported:
- Glasswing partners uncovered at least 129,000 verified software vulnerabilities between April and July 2026.
- Anthropic’s own open-source scanning found another 5,500 verified vulnerabilities between April and October 2026.
- More than 33,000 of the verified vulnerabilities have so far been rated critical or high severity.
- Several partners told Anthropic the models sped up their vulnerability finding by months or even years.
What Anthropic says limits the data:
- The totals rest on survey data from a subset of Glasswing partners, specifically 33 partner reports plus Anthropic’s open-source partnerships.
- Partners used different triage approaches.
- Fewer than half of partners disclosed patched numbers, often because fixes were still in progress, so Anthropic says the patch rate is significantly undercounted.
- Anthropic expects the true impact to be at least five times higher. That is a projection, not a measurement.
CyberInfos analysis: the announcement text does not break the totals down by project, severity method or CVE assignment, so readers cannot yet compare these counts with standard vulnerability statistics. “Verified” here means Anthropic reports the issues were confirmed, not that they were patched or exploited. The signal worth watching is the gap: discovery is reported at scale, while remediation figures remain incomplete.
Defensive and Policy Implications (CyberInfos Analysis)
The points below are CyberInfos interpretation, not statements from Anthropic.
Access control moves from the prompt to the person. Under the old model, a request was blocked or allowed based on how it looked. Under the Anthropic Cyber Verification Program, the same request can be allowed or blocked depending on who the organization is and what it is authorized to test. That mirrors how penetration testing contracts already work. The difference is that it leans heavily on verification quality.
Verified workspaces become attractive targets. A workspace with reduced blocks on Claude Opus 5.5 security work is worth more to an attacker than an ordinary account. CyberInfos recommends treating program workspaces as privileged: enforce single sign-on and multi-factor authentication, limit who can use them, and keep your own logs of how they are used. Anthropic says it requests proof of tier-specific controls, so confirm the exact requirements for your tier in its overview graphic and application portal.
Remediation becomes the bottleneck. If AI vulnerability discovery produces findings faster than maintainers and internal teams can fix them, triage queues grow while risk stays put. Anthropic’s own note on undercounted patch rates points this way. Open-source maintainers in particular should expect more incoming reports.
Data retention is a real trade-off. Retention lets Anthropic watch for misuse. It also means source code, findings and client material may sit with a vendor. CISOs should review the terms with legal and compliance teams, including any obligations that apply to personal data under laws such as India’s DPDP Act. Pen testing firms should also check whether client contracts allow third-party AI processing. This is not legal advice.
Open questions remain. The announcement does not list country-level eligibility, and Specialized Access review involves the US government. Organizations outside the United States should confirm eligibility on the application portal before planning around the program.
Which Tier Fits Which Team
| Team or role | Likely tier based on Anthropic’s descriptions |
|---|---|
| SOC analysts and incident responders | Defense Access |
| Malware analysts and reverse engineers | Defense Access |
| Open-source maintainers | Defense Access |
| Independent researchers with reported vulnerabilities | Defense Access (individuals are eligible) |
| Teams running AI cybersecurity red teaming, including in-house or government red teams and penetration testing firms | Red Team Access (Defense Access during review) |
| Operators testing safety-critical or market-critical systems | Specialized Access |
| Teams doing code review, patching known issues, owned-code vulnerability finding or alert triage | Generally available models may already cover this |

Checklist Before Applying
- Identify the lowest tier that covers your actual work.
- Document ownership or written authorization for every system in scope.
- Confirm which admin will apply and assign workspaces.
- Gather evidence of the security controls required for your tier.
- Review data retention terms with legal and compliance, and decide whether to wait for EFS.
- Write internal rules of engagement for AI cybersecurity red teaming and other AI-assisted testing, including logging and human review.
- Lock down program workspaces with single sign-on, multi-factor authentication and least privilege.
- Prepare a patching and disclosure workflow before findings start arriving at scale.
- Bookmark the form for reporting incorrect blocks.
Frequently Asked Questions
What is the Anthropic Cyber Verification Program?
It is an application-based program that gives verified security organizations reduced cyber safeguards on Anthropic’s advanced Claude models. The October 6, 2026 expansion merged the earlier CVP and Project Glasswing into one program with three access tiers.
Which Claude models does the program cover?
Anthropic says each tier includes Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1 and new models going forward.
Can individual researchers join?
Individuals can apply for Defense Access if they have a track record of reported vulnerabilities. Red Team Access is currently open to organizations only.
Can Red Team Access users deploy ransomware?
No. Anthropic says real-time blocks remain in Red Team Access for actions that could cause physical harm or mass disruption, including deploying ransomware. The announcement does not say how that applies in Specialized Access, which has the fewest blocks.
Are the 129,000 vulnerability figures independently verified?
No independent verification has been published that CyberInfos is aware of. The figures are Anthropic’s own and rest partly on partner survey data, which the company describes as a lower bound.
Final thoughts
The Anthropic Cyber Verification Program turns one restrictive policy into a graded system of trust. For defenders, the practical gain is easier access to stronger Claude cybersecurity capabilities, as long as the organization can show who it is, what it is authorized to do and how it will protect that access.
The reported results are promising but incomplete. The benchmark behind the Claude Opus 5.5 security claims is company-run, and the vulnerability totals carry Anthropic’s own warnings about partial data and unknown patch rates. Evaluate the program with care, and measure its value by vulnerabilities fixed, not vulnerabilities found.
