Today ainotis Join

My notis

SafetyPublished Top storyAll news from that day

Anthropic sets three access tiers in its Cyber Verification Program

Anthropic's 6 October post sets Defense, Red Team and Specialized Access tiers for security teams, with review times of a few days, a few weeks, and an in-depth review with the US government.

Share

Check our sources · 11 facts from 1 source
Illustration: A wall-mounted access panel with three stacked card slots; the green slots stand for the three access tiers of Anthropic's Cyber Verification Program.Illustration made with AI for ai notis
source · Illustration made with AI for ai notis; not a picture of what happened

Key points

  1. Anthropic says the program now has three tiers, Defense, Red Team and Specialized Access, each including Claude Opus 5.5, Claude Sonnet 5.5 and Claude Mythos 5.1.
  2. Anthropic aims to answer Defense Access applications in a few days; Red Team Access, for organizations only, adds authorized penetration testing and is expected to take a few weeks.
  3. Specialized Access has the fewest cyber blocks and is for a limited set of verified organizations, each currently reviewed in depth with the US government, Anthropic says.

What happened

Anthropic announced an expanded Cyber Verification Program on 6 October 2026, built on three access tiers for qualifying security professionals. Defense Access covers defensive work such as incident response and malware reverse-engineering, and Anthropic aims to answer applications within a few days.

Red Team Access adds authorized penetration testing for organizations only and is expected to take a few weeks to review. Specialized Access, with the fewest cyber blocks, is reserved for a limited set of verified organizations, and Anthropic currently reviews each one in depth with the US government.

Anthropic says existing Project Glasswing members move to that tier without reapproval for current models. In its own test on CyScenarioBench, Anthropic reports that Defense Access blocked 46 of 50 trials on Claude Opus 5.5, while Red Team Access blocked none and Claude completed 34 of 50.

What it means for you

Our view

The tiers set how much a security team can do with Claude and how long it waits for approval. Anthropic's own CyScenarioBench test on Claude Opus 5.5 shows the gap: Defense Access blocked 46 of 50 trials, while Red Team Access blocked none and Claude completed 34 of 50. That is Anthropic's evaluation, not an independent one.

Red Team Access is currently for organizations only, so individual researchers are not eligible. If your team does penetration testing, check whether your organization qualifies and allow for a review of a few weeks before an engagement depends on it.

It adds no new facts.

Share this story

Your reaction

We count reactions per story and day, never who reacted. The counts help us choose what goes in the monthly issue. If you are signed in, your own page shows yours too.

Check our sources

Every sentence above is checked against this source.

1 Cyber Verification ProgramAnthropic · 6 Oct 2026 · 11 facts Open the source
  1. Anthropic announced a new, expanded Cyber Verification Program on 6 October 2026. Quote: "We’re launching a new, expanded version of our Cyber Verification Program (CVP)"

    Expanding the Cyber Verification Program Oct 6, 2026 We’re launching a new, expanded version of our Cyber Verification Program (CVP)
  2. Anthropic says the program now consists of three access tiers, and each tier includes access to Claude Opus 5.5, Claude Sonnet 5.5 and Claude Mythos 5.1. Quote: "The program now consists of three access tiers"

    The program now consists of three access tiers, which allow security teams to apply for the level of access that best suits their work. Each tier includes access to our most capable models, including Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1, and new models moving forward.
  3. Anthropic says Defense Access is for defensive work such as security operations center and incident response tasks, reverse-engineering malware, and analyzing and validating vulnerabilities. Quote: "Defense Access is for defensive work, including security operations center and incident response tasks, reverse-engineering malware, and analyzing and validating vulnerabilities."

    Defense Access is for defensive work, including security operations center and incident response tasks, reverse-engineering malware, and analyzing and validating vulnerabilities.
  4. Anthropic says it aims to respond to Defense Access applications within a few days. Quote: "We aim to respond to applications within a few days."

    We aim to respond to applications within a few days.
  5. Anthropic says Red Team Access adds authorized penetration testing and red-teaming to the defensive uses, and that users still face real-time blocks on actions that could cause physical harm or mass disruption. Quote: "Red Team Access adds authorized penetration testing and red-teaming to the defensive uses above."

    Red Team Access adds authorized penetration testing and red-teaming to the defensive uses above.
  6. Anthropic says it expects Red Team Access applications to take a few weeks to review, and that the tier is currently for organizations only, with individual researchers not eligible. Quote: "Currently, this tier is for organizations only; individual researchers are not eligible."

    we expect applications in this tier to take a few weeks to review. Qualifying organizations will be enrolled in the Defense Access tier while we review their Red Team Access applications. Currently, this tier is for organizations only; individual researchers are not eligible.
  7. Anthropic says Specialized Access, which has the fewest cyber blocks, is reserved for a limited set of verified organizations authorized to test safety systems such as flight operating systems, power grids and telecom networks. Quote: "Specialized Access , which has the fewest cyber blocks, is reserved for a limited set of verified organizations"

    Specialized Access , which has the fewest cyber blocks, is reserved for a limited set of verified organizations that are authorized to test safety systems that could impact people’s lives or disrupt markets, such as flight operating systems, power grids, telecom networks,
  8. Anthropic says that for Specialized Access it currently reviews every organization in depth in collaboration with the US government, and existing Project Glasswing members transition to this tier without reapproval for current models. Quote: "we currently review every organization in depth in collaboration with the US government. Existing members of Project Glasswing will transition to this tier and do not require reapproval for current models."

    For this tier, we currently review every organization in depth in collaboration with the US government. Existing members of Project Glasswing will transition to this tier and do not require reapproval for current models.
  9. Anthropic reports that on CyScenarioBench with Defense Access safeguards, 46 of 50 trials were blocked at some point and four succeeded. Quote: "In the Defense Access tier, 46 of the 50 trials were blocked at some point in the challenge, while the remaining four tasks succeeded"

    In the Defense Access tier, 46 of the 50 trials were blocked at some point in the challenge, while the remaining four tasks succeeded
  10. Anthropic reports that in the Red Team Access tier no blocks occurred and Claude Opus 5.5 completed 34 of the 50 tasks. Quote: "In the Red Team Access tier, no blocks occurred, and Claude Opus 5.5 successfully completed 34 of the 50 tasks"

    In the Red Team Access tier, no blocks occurred, and Claude Opus 5.5 successfully completed 34 of the 50 tasks
  11. Anthropic says Project Glasswing partners uncovered at least 129,000 verified software vulnerabilities between April and July 2026 and its own scanning found 5,500 more between April and October 2026; of these together, more than 33,000 have so far been rated critical- or high-severity, a figure based on survey data from a subset of partners.

    Toned down to what the source says
    our partners uncovered at least 129,000 verified software vulnerabilities between April and July 2026. And through our own open-source scanning efforts, we found an additional 5,500 verified software vulnerabilities between April and October 2026. Of these verified vulnerabilities, more than 33,000 have so far been rated as critical- or high-severity. This is likely an undercount, as it is based on survey data from only a subset of Glasswing partners.

Topics

The morning email

On the mornings we publish: the three top stories and up to four short ones. Free.

We email you a link to confirm. An issue may include one sponsor, always labelled Sponsored · Advertisement. Our emails count opens and clicks, not who made them. Unsubscribe in one click. What we keep