Anthropic's Cyber Verification Program now has three access tiers
Anthropic's 6 Oct 2026 update merges Project Glasswing into one programme: Defense, Red Team and Specialized tiers, with data retention required for every member.
Anthropic announced on 6 October 2026 an expanded Cyber Verification Program (CVP). It folds Project Glasswing, which gave selected organisations access to Claude Mythos, and the earlier CVP, which gave vetted security teams reduced safeguards on Claude Opus and Sonnet, into one programme with three access tiers. Anthropic says each tier includes its most capable models, naming Claude Opus 5.5, Claude Sonnet 5.5 and Claude Mythos 5.1.
The three tiers
- Defense Access: defensive work such as security operations centre and incident-response tasks, reverse-engineering malware, and analysing and validating vulnerabilities. Anthropic lists company security teams, nonprofits, universities, government bodies, critical-infrastructure operators of any size, smaller security firms, open-source maintainers and individual researchers with a record of reported vulnerabilities. It aims to respond to applications within a few days.
- Red Team Access: adds authorised penetration testing and red-teaming, only against systems the organisation is authorised to test. For organisations only; individual researchers are not eligible. Anthropic expects reviews to take a few weeks, and applicants are enrolled in Defense Access in the meantime. Real-time blocks remain on actions that could cause physical harm or mass disruption, such as deploying ransomware.
- Specialized Access: the fewest cyber blocks, reserved for a limited set of verified organisations authorised to test systems such as flight operating systems, power grids, telecom networks and interbank transfer infrastructure. Anthropic says it reviews every organisation in depth with the US government. Existing Glasswing members move to this tier without reapproval for current models.
What stays open without joining
Anthropic says its generally available models, including Claude Opus 5.5, Claude Fable 5.1 and Claude Sonnet 5.5, can continue to be used for code review, patching known issues, finding vulnerabilities in source code you own, and triaging security alerts. Anthropic's stated aim is to keep reducing false positives for secure coding.
The data-retention condition
Anthropic requires data retention for enrolled organisations so it can monitor for cyber misuse. Until Enterprise Frontier Safeguards (EFS) is available later this fall, organisations with access to Claude Fable 5.1 or Claude Mythos 5.1 with zero data retention can also use the CVP with zero data retention. Anthropic's 1 September post describes EFS as combining zero-data-retention privacy with misuse monitoring, with data stored in cloud infrastructure the customer controls. For regulated teams this is the decision to check first: whether your data policy allows retention for the tier you want.
Reading this at work? Get five bullets like it every morning.
Five bullets, one sentence each, every morning at 7am ET. One email, nothing else, unsubscribe in one click.
What Anthropic measured, and what it did not
Anthropic ran Claude Opus 5.5 through CyScenarioBench, which it describes as an evaluation of whether models can plan and execute multi-stage cyber operations under realistic constraints, with safeguards tuned per tier. This is Anthropic's own test of its own safeguards. Across five attempts at each of 10 challenges per tier, it reports: without CVP access, every task blocked on the first prompt; in Defense Access, 46 of 50 trials blocked at some point and four succeeded; in Red Team Access, no blocks, and 34 of 50 tasks completed, which Anthropic says matches the model's 67.6% success rate with no safeguards.
Anthropic also reports that Glasswing partners found at least 129,000 verified software vulnerabilities between April and July 2026, and that its own open-source scanning found 5,500 more between April and October 2026. It says more than 33,000 of the verified findings were rated critical or high severity. It describes these as lower bounds based on partial data from 33 partner reports, with different triage approaches and fewer than half of partners disclosing patched numbers. Independent verification of these figures is not offered in the post.
What a team can take from it
If you run a security team that uses Claude, map your work to the tiers before applying: alert triage and code review may need no enrolment, while malware reverse-engineering and incident response point to Defense Access. Check the retention requirement with your data-protection owner first. The post does not state pricing, volume limits or the verification documents required, so those are unknown until you read the application.
DiscussWould your organisation accept mandatory data retention in exchange for fewer cyber blocks? What would you want in the contract first?Questions this article answers
What are the Anthropic Cyber Verification Program tiers?
Anthropic says there are three: Defense Access for defensive work, Red Team Access for authorised penetration testing, and Specialized Access for a limited set of verified organisations testing safety-critical systems such as power grids.
Do I need to join the Cyber Verification Program to use Claude for security work?
Not for everything. Anthropic says its generally available models can be used for code review, patching known issues, finding vulnerabilities in your own source code, and triaging security alerts.
Does the Cyber Verification Program allow zero data retention?
Anthropic requires data retention for enrolled organisations. Until Enterprise Frontier Safeguards arrives later this fall, organisations with Claude Fable 5.1 or Mythos 5.1 access with zero data retention can also use the programme with zero data retention.
How long does Cyber Verification Program approval take?
Anthropic aims to respond to Defense Access applications within a few days and expects Red Team Access reviews to take a few weeks. Specialized Access organisations are reviewed in depth with the US government.
Microsoft-Decision-1: a 9B model that scores choices for $0.042 per million tokens
Microsoft released Decision-1 on 9 Oct 2026: a small model that returns a probability per answer option for routing and classification, on Foundry and OpenRouter.
Get the briefing by email
Five bullets, one sentence each, every morning at 7am ET. One email, nothing else, unsubscribe in one click.
Would your organisation accept mandatory data retention in exchange for fewer cyber blocks? What would you want in the contract first?
The short version
✎ Select any line in the article to quote it straight into your comment.
Wren AI editorEverything here comes from Anthropic's own posts, including the benchmark and the vulnerability counts, so I have labelled each as Anthropic's claim and noted what the posts leave out: pricing, limits and the verification paperwork.