Anthropic has expanded its Cyber Verification Program into three tiers, giving qualifying security professionals access to advanced cyber capabilities with fewer automated blocks. All three include Claude Mythos 5.1 alongside Claude Opus 5.5 and Claude Sonnet 5.5, plus future models. Anthropic aims to review Defense Access applications within days, while Red Team Access reviews are expected to take weeks.
Customers can use the program through Microsoft Foundry, the Claude Platform and Google Cloud’s Vertex AI. Access through Amazon Bedrock is restricted to customers eligible for Enterprise Frontier Safeguards. Applicants must pass verification and provide evidence that they meet their tier’s security requirements.
Read more: Anthropic Splits Claude Subscribers into Two Tiers as Fable 5 Promotional Limbo Ends July 20
Defense Access covers work such as investigating incidents, examining malware and checking vulnerabilities. Potential applicants include individual researchers with a history of reporting vulnerabilities, open-source maintainers and teams protecting systems their organizations own or maintain. Red Team Access adds permission for penetration testing and red-teaming, but applicants must be organizations and may test only systems they are authorized to assess.
Applicants qualifying for Red Team Access receive Defense Access while their reviews proceed. Red Team Access retains real-time blocking for actions that could harm people or cause widespread disruption, including ransomware deployment. Specialized Access has the fewest cyber restrictions and is limited to verified organizations authorized to test safety systems, with Anthropic conducting detailed reviews alongside the US government.
The expanded program combines the earlier CVP with Project Glasswing, whose existing members will move into Specialized Access without another approval for current models. Organizations must generally accept data retention so Anthropic can monitor misuse, although an interim exception covers organizations already using Claude Fable 5.1 or Claude Mythos 5.1 with zero data retention. Anthropic says Enterprise Frontier Safeguards, expected later this fall, will let eligible organizations keep data in cloud infrastructure under their control.
Anthropic’s testing illustrates how sharply the tiers differ: Defense Access blocked 46 of 50 trials on CyScenarioBench, while Red Team Access blocked none. Claude Opus 5.5 completed 34 of those 50 Red Team Access trials, compared with a 67.6% success rate when safeguards were removed. Without CVP access, every task was blocked at the initial prompt.
Anthropic previously introduced identity checks for some Claude users accessing certain capabilities, requiring government photo identification and sometimes a live selfie. Those checks ran through Persona Identities, and Anthropic said identity information would not be used for model training. Existing CVP members will retain their settings for older models and undergo automatic evaluation for the newly covered models.













