Anthropic expanded its Cyber Verification Program (CVP) on October 6, 2026. CVP verifies security professionals and organizations before granting access to advanced cyber capabilities in Claude. The revised program has three levels: Defense Access, Red Team Access, and Specialized Access. Each tier includes current models such as Claude Opus 5.5, Claude Sonnet 5.5, and Claude Mythos 5.1. Source

Three tiers for defensive, adversarial, and high-risk work

Defense Access covers defensive tasks such as security operations, incident response, malware reverse engineering, and vulnerability analysis and validation. Applicants can include security teams at companies, nonprofits, universities, and government bodies; operators of critical infrastructure such as regional hospitals or municipal utilities; smaller security firms; open-source maintainers; and individual researchers with a record of reported vulnerabilities. Anthropic aims to respond to these applications within a few days. Source

Red Team Access adds authorized penetration testing and red-team work. A red team tests an organization’s defenses by simulating attacks. This level is limited to organizations, and testing must target systems that the organization owns or is authorized to test. Reviews can take a few weeks, with qualifying applicants receiving Defense Access during the review. Real-time blocks remain for actions that could cause physical harm or mass disruption, including ransomware deployment, damage to physical systems, and testing high-risk safety systems. Source

Specialized Access has the fewest cyber blocks and is reserved for a limited set of verified organizations authorized to test safety systems that could affect lives or disrupt markets. Examples include flight operations, power grids, telecommunications networks, interbank transfer infrastructure, and government administrative networks. Anthropic reviews these organizations in depth with the U.S. government. Existing Project Glasswing members move to this tier without reapproval for current models. Source

Data retention and the scope of generally available Claude

Organizations enrolled in CVP must retain data so Anthropic can monitor for cyber misuse. Anthropic plans to offer Enterprise Frontier Safeguards (EFS), which combines zero data retention with stronger safeguards, later in fall 2026. Until EFS is available, organizations already eligible for zero data retention with Claude Fable 5.1 or Claude Mythos 5.1 can use CVP under that arrangement. Source

Generally available Claude models can still be used for code review, patching known issues, finding vulnerabilities in source code the user owns, and triaging security alerts. CVP provides higher access levels for verified work that can be blocked by the conservative cyber safeguards used on general models. Source

Applying and choosing a supported platform

Anthropic verifies every applicant and requests proof of the security controls required for the requested tier. Existing CVP members keep their current settings for earlier models and are automatically evaluated for access to the three models in the updated program. After approval, an administrator must assign access to specific workspaces. Source

CVP is available through the Claude Platform, Google Cloud’s Vertex AI, and Microsoft Foundry. On Amazon Bedrock, it is limited to customers eligible for Enterprise Frontier Safeguards. Source