Anthropic Expands Claude Cyber Access With Three Tiers
Vetted security teams can apply for broader Claude capabilities, but access depends on authorized work, security controls, and the platform they use.
Listen
AI narration
12:21
0:00 / 12:21
AI SummaryGenerated from this article
Anthropic expanded its Cyber Verification Program on October 6, 2026, offering security teams three tiers of access to Claude models with varying permitted activities. Defense Access covers operational security and vulnerability work; Red Team Access adds authorized penetration testing; Specialized Access, limited to organizations testing safety-critical systems like power grids, has the fewest blocks. Applicants must provide organization details, describe security work, attest to required controls, and implement phishing-resistant multifactor authentication by December 15, 2026. Testing showed Red Team Access achieved 68% completion on multistage cyber operations, though approval does not guarantee misuse prevention or eliminate false positives in production.
Security teams can now apply for access to Claude Mythos 5.1 alongside Opus 5.5 and Sonnet 5.5 through Anthropic’s expanded Cyber Verification Program. Three tiers determine which cybersecurity activities receive fewer blocks; approval does not give customers unrestricted model access.
Anthropic introduced Defense Access, Red Team Access, and Specialized Access in its October 6, 2026 program announcement. The expansion combines its existing Cyber Verification Program with Project Glasswing, which previously provided selected organizations with Claude Mythos for critical software security work.
For security leaders, access comes with application reviews, identity requirements, data-handling obligations, and deployment restrictions. Claude’s general safeguards have not been relaxed for everyone.
Three Tiers Match Access to Authorized Security Work
All three tiers include Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1, and future models, according to Anthropic. They differ in permitted activities, verification requirements, security controls, and how aggressively cyber classifiers block requests.
Defense Access Covers Operational Security and Vulnerability Work
Defense Access covers security operations center tasks, incident response, malware reverse engineering, and vulnerability analysis and validation.
Potential applicants include company security teams, nonprofits, universities, government bodies, smaller security firms, open-source maintainers, and individual researchers with a record of reported vulnerabilities. Anthropic also lists critical infrastructure operators, including regional hospitals and municipal utilities.
Qualification is not reserved for large technology companies. A smaller organization defending systems it owns or maintains may have a route into the program.
Substantial restrictions on offensive activity remain. Approval for malware analysis or vulnerability validation should not be treated as approval to conduct every penetration-testing workflow.
Red Team Access Adds Authorized Offensive Testing
Red Team Access includes the defensive uses above and adds authorized penetration testing and red-teaming. Eligible applicants include in-house red teams, government red teams, and security or penetration-testing firms.
This tier currently accepts organizations, not individual researchers. Testing must target systems the organization is authorized to assess.
Work with Zeniteq
Let’s work together
We’re open to thoughtful collaborations with teams building in AI. Explore the ways we can work together.
Real-time blocks remain for actions that could cause physical harm or mass disruption, Anthropic says. Its examples include deploying ransomware, damaging physical systems, and penetration testing of high-risk safety systems.
Permission is more specific than “offensive work allowed.” An organization may be authorized to test conventional IT systems, including those in critical industries, while still encountering blocks on higher-risk activities.
Specialized Access Covers Safety-Critical Systems
Specialized Access has the fewest cyber blocks and is reserved for a limited set of verified organizations authorized to test systems whose failure could affect lives or disrupt markets.
Anthropic’s examples include flight operating systems, power grids, telecommunications networks, interbank transfer infrastructure, and government administrative networks. The company says it reviews each applicant in depth in collaboration with the US government.
Existing Project Glasswing members transition into Specialized Access without reapproval for their current models. That exemption applies to existing access; it does not imply unconditional approval for every future model or activity.
Apply Once, but Plan for Review and Provisioning
The Claude Help Center directs applicants to Anthropic’s Verification Portal. Organizations submit one application instead of having each employee apply separately. Anthropic says it will assign the highest tier supported by the information it receives.
Applicants need to provide:
Organization and applicant details for verification.
A description of their security work.
An attestation to the controls required for the requested access.
Information about how they access Claude.
Anthropic will also request proof of the relevant security controls, according to the announcement. Teams should prepare to substantiate their access-management arrangements as well as describe a legitimate cybersecurity use case.
The published review timelines need careful interpretation. The announcement targets a response within a few days for Defense Access and a few weeks for Red Team Access. The Help Center gives a target of seven business days for either a decision or a request for more information. These are response targets, not guaranteed completion dates.
Qualifying organizations seeking Red Team Access will be enrolled in Defense Access while Anthropic reviews the higher-tier application.
Deployment may require further work after approval. Console and API organization owners must assign the program to workspaces, while Claude Enterprise owners assign it through a custom role. Other routes have their own provisioning steps.
Existing CVP members retain their settings for previous models and are automatically evaluated for Opus 5.5, Sonnet 5.5, and Mythos 5.1. Automatic evaluation does not guarantee approval.
Cloud Availability Comes With a Bedrock Exception
Anthropic says the expanded CVP is available through the Claude Platform, Google Cloud Vertex AI, and Microsoft Foundry. Its Help Center also provides first-party enrollment instructions for Claude.ai, Claude Code, and the Anthropic API.
On Amazon Bedrock, CVP is available only to customers eligible for Enterprise Frontier Safeguards, or EFS. An existing Bedrock account alone does not make the program available.
Cloud enrollment requires linking the relevant account, project, or subscription through the Verification Portal. Microsoft Foundry applicants must first deploy a Claude model, then link their Azure subscription and tenant.
Third-party coding tools and other Claude-powered applications have a separate limitation. Supported platforms can provide an Anthropic enrollment link for Defense or Red Team Access, but Specialized Access is not available through that route.
Procurement and provisioning can add further steps. For Bedrock customers with an Anthropic committed contract, the documentation describes linking the account to the contract and accepting an AWS Marketplace private offer. It also says Mythos access can trail application approval by approximately five business days.
The tiers are access categories, not a published three-tier AI pricing menu. Teams should separate verification approval from their model billing and contractual arrangements.
Reduced Blocking Requires Stronger Governance
Anthropic requires data retention so it can monitor for cyber misuse, subject to specified exceptions. This is one of the program’s consequential conditions.
The announcement describes EFS as a forthcoming solution combining zero-data-retention privacy with safeguards. Once it becomes available later in the fall, eligible organizations will be able to store data in cloud infrastructure they control.
Until then, organizations already accessing Claude Fable 5.1 or Claude Mythos 5.1 with zero data retention can also use CVP under zero data retention. That exception does not extend to every new applicant.
Identity controls also affect deployment planning. The security requirements guidance says Defense Access users have until December 15, 2026, to adopt phishing-resistant multifactor authentication and stop using API keys. During the transition, some form of multifactor authentication is required, and API keys expire every seven days. Anthropic recommends moving to Workload Identity Federation.
Teams whose tools depend on long-lived API keys will have integration work beyond securing approval. Credential changes and access provisioning belong in the implementation plan.
Anthropic’s Usage Policy continues to apply in full, and the company may review, narrow, or withdraw an access grant. Building a client-facing product using these capabilities is governed separately by its Cyber Productization Policy.
Approval does not automatically authorize an organization to pass the same capabilities through to customers. Internal security use and product distribution are separate governance questions.
Anthropic’s Benchmark Shows the Boundary, Not Proven Safety
Anthropic tested Opus 5.5 on CyScenarioBench, an evaluation of planning and executing multistage cyber operations under realistic constraints. It ran five attempts on each of ten challenges under different safeguard configurations.
The company reported:
Without CVP access, all 50 trials were blocked at the first prompt.
Under Defense Access, 46 trials encountered a block; the other four succeeded.
Under Red Team Access, no trials were blocked, and Opus 5.5 completed 34 of 50.
That Red Team completion rate is 68%. Anthropic describes it as effectively equivalent to the model’s 67.6% success rate with no safeguards applied, a configuration it treats as representative of Specialized Access.
These CyScenarioBench results support a narrow conclusion: Anthropic’s configurations produced sharply different blocking behavior on this offensive evaluation while preserving substantial task completion under Red Team Access.
The results do not establish that verified users cannot misuse the system, that every allowed workflow will succeed, or that Defense Access will avoid false positives in production. Anthropic ran the evaluation to assess model behavior; it is not an independent audit of applicant verification, monitoring, or organizational controls.
The first-prompt blocking result also does not mean ordinary Claude cannot perform cybersecurity work. Anthropic says generally available models remain usable for secure code review, patching known issues, finding vulnerabilities in owned source code, and triaging security alerts.
Organizations considering an application should identify which blocked workflows they need to conduct, against which systems, and under whose authorization. The expanded program provides a route to fewer interruptions and more capable models, but its value depends on whether a team can meet and operate within the corresponding controls. Approval begins that responsibility.