Anthropic launches upgraded Cyber Verification Program with new access tiers for enhanced cybersecurity capabilities

    Anthropic launches upgraded Cyber Verification Program with new access tiers for enhanced cybersecurity capabilities

    Anthropic is set to launch an enhanced version of its Cyber Verification Program (CVP), which offers advanced cyber capabilities as well as reduced blocking for qualifying security professionals. The revamped program now features three distinct tiers of access, enabling security teams to select the level of support that aligns with their needs. All tiers provide access to powerful models, including Claude Opus 5.5, Claude Sonnet 5.5, and Claude Mythos 5.1, with plans to introduce additional models in the future. Interested parties can apply here.

    The nature of cybersecurity is inherently dual-use, with tools that can help identify vulnerabilities equally capable of being exploited by malicious actors. Consequently, Anthropic’s publicly available models such as Claude Opus 5.5, Claude Fable 5.1, and Claude Sonnet 5.5 come equipped with stringent safeguards to prevent most cyber-related work. These measures are aimed at curbing misuse while efforts to minimize false positives in secure coding are ongoing.

    However, cybersecurity defenders require access to top-tier tools to effectively secure their systems. For the past six months, Anthropic has provided trusted access through two initiatives: Project Glasswing and the CVP. The former program had given a select group of organizations tasked with securing critical software access to Claude Mythos, whereas the latter allowed vetted security teams more flexibility with reduced safeguards on the Claude Opus and Claude Sonnet models.

    This integration marks a move towards a comprehensive offering designed to facilitate broader access to essential security capabilities.

    The updated access tiers cater to specific model functionalities and are determined based on the nature of cyber tasks professionals undertake. Each tier has varied verification and security controls. The first, known as Defense Access, is tailored for defensive operations, including tasks in security operations centers, incident responses, malware analysis, and vulnerability assessments. Organizations such as corporate security teams, non-profits, university departments, and governmental bodies are potential candidates for this tier, and applications are expected to receive responses in just a few days.

    Red Team Access is geared toward authorized penetration testing and red teaming in addition to defensive tasks. Qualifying entities include internal red teams, government contractors, and security testing firms. This tier allows for adversarial assessments solely on systems they are permitted to evaluate. Users will encounter real-time blocks on actions that could result in harm or significant disruptions such as deploying ransomware or testing sensitive safety systems. Given the heightened eligibility and security protocols, a thorough review of applications for this tier could take weeks.

    The third tier, Specialized Access, is designated for a limited number of verified organizations permitted to conduct tests on critical safety systems, such as those relating to air travel, energy grids, telecommunications, and financial infrastructure. Organizations in this tier will undergo comprehensive assessments in conjunction with the US government, while existing participants in Project Glasswing will transition automatically without needing to undergo re-approval.

    Enterprise Frontier Safeguards (EFS) solution is rolled out later this fall, eligible organizations will have the ability to control their data storage in cloud infrastructure. Until then, organizations with access to Claude Fable 5.1 or Claude Mythos 5.1 can use the CVP maintaining zero data retention protocols.

    A recent evaluation involving Claude Opus 5.5 assessed the efficacy of CVP protections through CyScenarioBench, an assessment designed to evaluate model performance in executing complex cyber operations under realistic limitations. The results demonstrated significant blocking in both the general and Defense Access tiers, whereas no blocks appeared in the Red Team Access and Specialized Access tiers.

    Findings showed that tasks were completely obstructed without any CVP access, with notable blocks occurring 46 times out of 50 in the Defense Access tier. In contrast, models in the Red Team Access tier completed 34 out of 50 tasks successfully, noting an effective success rate comparable to scenarios devoid of safeguards.

    These results provide confidence that advanced cyber capabilities can be made accessible to a wider array of defenders, broadening the protective measures established through Project Glasswing. The firm aims to continue refining its tier-based classification systems over time.

    Through Project Glasswing, significant increases in vulnerability detection rates were observed among participating organizations. Partners reported uncovering over 129,000 verified software vulnerabilities between April and July 2026, coupled with Anthropic’s own efforts that led to identifying an additional 5,500 vulnerabilities from April to October 2026. Treated cautiously, the tally of critical vulnerabilities exceeded 33,000. Insights from partners highlighted a dramatic acceleration in their vulnerability identification process, saving them months or even years.

    These enhancements to the Cyber Verification Program are designed to amplify the benefits of Project Glasswing for a more extensive network of cybersecurity defenders while continuing to safeguard open-source software and critical systems. More information will be forthcoming as Anthropic advances in these ongoing efforts to empower defenders.

    Organizations interested in CVP membership can apply to the program here. The application phase will require verification and proof of the necessary security controls associated with the relevant access tier. Current CVP members will maintain their existing settings and will be automatically considered for additional access to Claude Opus 5.5, Claude Sonnet 5.5, and Claude Mythos 5.1 under the new structure. Administrators can follow the designated steps for assigning access to specific workspaces.

    CVP will be available on Claude Platform, Google Cloud’s Vertex AI, and Microsoft Foundry, and is only accessible on Amazon Bedrock for customers registered for Enterprise Frontier Safeguards.

    If users encounter blocks on tasks believed to be permissible under their assigned tier, they can report it here. Detailed information regarding each tier can also be accessed in the Help Center.

    Leave a Reply