Expanding the Cyber Verification Program

Anthropic
Anthropic expands its Cyber Verification Program into three access tiers, giving vetted defenders broader access to advanced cyber capabilities.

Summary

Anthropic is launching an expanded version of its Cyber Verification Program (CVP), which makes advanced cyber capabilities and reduced blocking classifiers available to qualifying security professionals. The updated program consists of three access tiers, letting security teams apply for the level of access that best suits their work. All tiers include access to the company's most capable models, including Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1, and new models going forward. Because cybersecurity is inherently dual use, Anthropic's generally available models carry conservative cyber safeguards that block most cyber work; the CVP exists to give trusted defenders reduced safeguards without enabling malicious actors.

The three tiers are: Defense Access, for defensive work such as security operations center tasks, incident response, reverse-engineering malware, and vulnerability analysis and validation; Red Team Access, which adds authorized penetration testing and red-teaming and is currently for organizations only; and Specialized Access, which has the fewest cyber blocks and is reserved for a limited set of verified organizations authorized to test safety systems such as flight operating systems, power grids, telecom networks, interbank transfer infrastructure, and government administrative networks, reviewed in collaboration with the US government. Data retention is required to monitor for cyber misuse, with zero-data-retention options through Enterprise Frontier Safeguards (EFS) expected later this fall.

Anthropic tested the tiers using CyScenarioBench: without CVP access every task was blocked on the first prompt; in the Defense Access tier 46 of 50 trials were blocked; and in the Red Team Access tier no blocks occurred, with Claude Opus 5.5 completing 34 of 50 tasks, matching its no-safeguards success rate. The company reports that Project Glasswing partners uncovered at least 129,000 verified software vulnerabilities between April and July 2026, plus 5,500 more from Anthropic's own open-source scanning, with more than 33,000 rated critical or high severity and the true impact expected to be at least five times higher. The changes aim to extend Glasswing's impact to far more defenders.

(Source:Anthropic)