Cyber Verification Program graphic showing three access tiers for security teams

Anthropic’s Cyber Verification Program Now Has Three Tiers: Who Qualifies and How to Apply

Anthropic just reorganized its Cyber Verification Program into three tiers, so security teams can now apply for fewer Claude cyber blocks depending on how sensitive their work is. If you do defensive security, you can apply for the entry tier today and expect an answer within days.

Here’s what changed, who qualifies, and what the catches are.

Quick facts before the details:

  • The program now has three tiers: Defense Access, Red Team Access, and Specialized Access.
  • Project Glasswing, Anthropic’s earlier invite-only effort, has been folded in.
  • Claude Opus 5.5, Sonnet 5.5, and Claude Mythos 5.1 are available at every tier.
  • Enrolled organizations must allow data retention so Anthropic can watch for misuse.

How the Cyber Verification Program’s three tiers differ

Each tier removes more safeguards, and each asks for more proof that you’re a legitimate defender. According to SiliconANGLE, the entry tier is meant to be quick, while the top tier involves a deep review.

Tier What it unlocks Who can apply Review time
Defense Access Incident response, malware analysis, vulnerability validation Security teams, open-source maintainers, researchers with disclosure records A few days
Red Team Access Everything above, plus authorized penetration testing Organizations only (no individuals yet) A few weeks
Specialized Access Fewest cyber blocks, for high-risk systems like grids and telecom Orgs cleared to test critical systems, reviewed with the US government In-depth review

Red Team Access still blocks requests that drift toward ransomware deployment or actions that could cause physical harm or widespread disruption, as Help Net Security reports. Applicants waiting on Red Team review get Defense Access in the meantime.

Who can apply for Defense Access

This is the tier most readers will care about. It covers security teams at businesses, nonprofits, universities, and governments, plus critical infrastructure operators, smaller security firms, and open-source maintainers.

Individual researchers can apply too, if they have a record of vulnerability disclosures. That’s a notable opening, since the Red Team tier currently excludes individuals.

If you maintain an open-source project, this is also the tier that lets Claude help validate vulnerabilities in code you own, rather than refusing halfway through.

What happens to Project Glasswing and Claude Mythos

Project Glasswing launched in April 2026 and grew to about 150 organizations by June. Those partners now move straight into Specialized Access without reapplying.

Anthropic says Glasswing partners found 129,000 verified vulnerabilities between April and July, and its open-source scanning added 5,500 more through October. More than 33,000 of the combined total were rated critical or high severity. Those are Anthropic’s own numbers, so treat them as the company’s claim.

For background on the Mythos rollout, see our earlier note on Anthropic’s AI slowdown plan.

The safeguard test, and why to read it carefully

Anthropic tested the tiers on CyScenarioBench, running five attempts at each of ten challenges. With no access, every task was blocked on the first prompt. Under Defense Access, 46 of 50 runs hit a block.

Under Red Team Access, nothing was blocked and 34 of 50 runs finished. Anthropic says that matches the roughly 67.6% success rate Opus 5.5 gets with no safeguards at all.

The catch: as Mixed News points out, Anthropic built the benchmark, ran the model, and scored the results. No outside party is named as checking any of it.

What to do before you apply

Getting approved is the easy part. The data-retention rule is the part that may stall a legal or compliance review.

Anthropic says Enterprise Frontier Safeguards, due later in 2026, will let eligible customers keep that data in their own cloud. It also mentions zero-data-retention approval for specific models as an alternative. The program runs on Claude Platform, Google Vertex AI, and Microsoft Foundry, while AWS Bedrock access is limited to customers eligible for the new safeguards.

If you also handle package security, our guide to checking for malicious npm packages pairs well with this.

Frequently Asked Questions

What is the Anthropic Cyber Verification Program?

It’s a vetting program that lets approved security professionals use Claude with fewer cyber-related blocks. It now has three tiers, from Defense Access to Specialized Access.

Can I apply as an individual researcher?

Yes, for Defense Access, if you have documented vulnerability disclosures. Red Team Access is currently open to organizations only.

How long does approval take?

Anthropic expects Defense Access reviews to take a few days and Red Team Access reviews a few weeks. Specialized Access involves a longer review with the US government.

Does Claude Mythos come with every tier?

Per SiliconANGLE, Opus 5.5, Sonnet 5.5, and Mythos 5.1 are available at all tiers. What changes is how many cyber-related blocks apply.

My take: if you do defensive work, apply for Defense Access now, since it costs little and the review is fast. Hold off on the higher tiers until someone outside Anthropic tests those safeguards, because a zero-block result on a self-run benchmark is a reason to ask questions, not to relax.


Comments

Leave a Reply

Your email address will not be published. Required fields are marked *