Anthropic Splits the Cyber Verification Program into Three Tiers and Folds In Project Glasswing
On October 6, 2026, Anthropic reorganized its Cyber Verification Program for security professionals into Defense, Red Team, and Specialized tiers, and merged in Project Glasswing, which had been providing Claude Mythos. Existing Glasswing members move to Specialized, the tier with the fewest blocks. Expected review times differ by tier, and participants must accept data retention.
On October 6, 2026, Anthropic announced an expanded Cyber Verification Program (CVP)1. The program lets security professionals who meet its requirements use advanced cyber capabilities, with blocking classifiers that are less strict. It is now divided into three access tiers — Defense Access, Red Team Access, and Specialized Access — and every tier comes with the company’s top models — Claude Opus 5.5, Claude Sonnet 5.5, and Claude Mythos 5.1 among them — plus models released later. Anthropic is also merging Project Glasswing, the program through which it had been supplying Claude Mythos to organizations that protect critical software, into the CVP.
According to the Help Center, the previous CVP offered one level of access covering Claude Opus and Sonnet2. Under the new structure, applicants pick a tier that matches the scope of their work, and each tier comes with its own vetting requirements and security-control conditions.
Generally available models block most cyber work
The starting point is the restriction on the public models. Anthropic says publicly available models like Opus 5.5, Fable 5.1, and Sonnet 5.5 ship with conservative safeguards that stop the majority of cyber tasks1. Its reasoning is that the skills a team uses to locate and repair a flaw can just as easily be turned toward exploiting it. Wain has covered how most cybersecurity work on Opus 5.5, beyond fixing bugs during ordinary development, is rerouted to Opus 4.8, and how higher-risk cybersecurity work on Sonnet 5.5 falls back to Sonnet 5.
Even without the program, the public models remain usable for code review, fixing known issues, hunting for vulnerabilities in source code you own, and triaging security alerts. The Help Center adds that tasks like analyzing malware or validating exploits can be interrupted by the safety classifiers, and it points security professionals who are hitting those blocks to the CVP application2.
Who each tier is for, and how long review takes
Defense Access covers defensive work: SOC (security operations center) and incident-response tasks, reverse engineering of malware, and analysis and validation of vulnerabilities1. Anthropic’s list of example applicants includes in-house security staff at businesses, nonprofits, universities, and public agencies guarding systems under their own ownership or upkeep; critical-infrastructure operators large or small, a regional hospital or a municipal utility among them; small security companies; maintainers of open-source projects; and independent researchers who have reported vulnerabilities before. Anthropic anticipates that many organizations engaged in defensive security will be eligible, and it aims to reply to applicants in a matter of days.
Red Team Access extends those defensive uses with penetration testing and red-team exercises, provided they are authorized. Anthropic’s examples are corporate and government red teams along with penetration-testing and security companies, and adversarial testing may only target systems the organization is permitted to test. At this tier too, actions that could lead to physical harm or large-scale disruption are still blocked in real time; the examples given are launching ransomware, causing damage to physical equipment, and penetration tests against high-risk safety systems. Review is expected to take several weeks, and qualifying organizations are placed in Defense Access while it is underway. For now, only organizations can hold this tier; individual researchers cannot apply.
Specialized Access has the fewest cyber-related blocks of the three. Eligibility is restricted to a limited number of vetted organizations with authorization to test safety-critical systems whose failure could put people at risk or shake markets. The examples given are aircraft flight systems, electrical grids, telecommunications networks, the infrastructure banks use to move money between each other, and the networks that run government administration. At present, Anthropic reviews every organization in this tier in depth together with the US government. Glasswing’s existing members are moved into Specialized and need no fresh approval for the models they currently use.
Per the Help Center, individuals can apply only for Defense Access, and only on a paid plan; Red Team Access and Specialized Access are for organizations2. Specialized Access cannot be obtained through third-party platforms, such as coding tools built on Claude. Each organization applies once, and Anthropic assigns it to the highest tier the submitted information supports. According to the Help Center, Anthropic aims to send its decision, or ask for further details, by email within seven business days.
Data retention is mandatory; on Bedrock, only EFS-eligible customers
Organizations in the CVP must accept data retention so that Anthropic can watch for cyber misuse1. Anthropic says that when Enterprise Frontier Safeguards (EFS) becomes available later in the autumn, organizations that qualify for it can hold the retained data in cloud environments they manage themselves. EFS is meant to offer privacy comparable to ZDR, where no data is kept, while keeping misuse safeguards in place. Until EFS is out, organizations that can already use Claude Fable 5.1 or Claude Mythos 5.1 under ZDR may use the CVP under ZDR too.
Supported platforms are Microsoft Foundry, Vertex AI on Google Cloud, and the Claude Platform; on Amazon Bedrock the program is restricted to customers eligible for EFS. The Help Center’s explanation is that the CVP by default relies on people reviewing safety flags raised automatically, and Bedrock cannot support that yet2. Mythos access through cloud providers arrives roughly five business days after approval.
Current CVP members keep their existing settings for earlier models and will be evaluated automatically for Opus 5.5, Sonnet 5.5, and Mythos 5.1 under the updated program1. Admins still need to assign the program to particular workspaces using the documented procedure.
Anthropic’s own CyScenarioBench results
To check that the tier protections work, Anthropic published results from running Opus 5.5 on CyScenarioBench1. CyScenarioBench tests whether a model can plan and run cyber operations spanning several stages, within realistic constraints. With safeguards tuned for each tier, Anthropic ran each of the benchmark’s 10 challenges five times. All of the figures below come from Anthropic’s own evaluation.
- No CVP access: all tasks were blocked on the very first prompt
- Defense Access: 46 of 50 runs were blocked partway through, and the other 4 succeeded
- Red Team Access: nothing was blocked, and Opus 5.5 finished 34 of 50 runs
Anthropic regards the Red Team outcome as practically equal to the 67.6% that Opus 5.5 scores on this benchmark with safeguards switched off. It treats that no-safeguards condition as representative of Specialized Access, and the announcement does not show a separate run for the Specialized tier itself. Because the benchmark involves offensive scenarios, Anthropic says it expected heavy blocking for the public model and Defense Access and no blocking for Red Team and Specialized Access. It plans to keep tuning the tier-specific classifiers.
Glasswing’s six months, and why it is being merged
Anthropic says that over the past six months it has offered trusted access through two separate programs1. Project Glasswing provided Claude Mythos to a set of organizations responsible for the most important software, while the CVP gave vetted security teams relaxed safeguards on Opus and Sonnet models. Wain noted in its June article on Fable 5 and Mythos 5 that in April 2026 Claude Mythos Preview was released on a limited basis through Glasswing to cyber defenders and critical-infrastructure providers. SiliconANGLE reports that Glasswing was extended to another 150 organizations in June3.
Anthropic also shared outcome figures. By its count, Glasswing partners turned up no fewer than 129,000 vulnerabilities that were verified, from April through July 2026, and Anthropic’s own open-source scanning found another 5,500 from April through October1. So far, over 33,000 of them carry a critical or high severity rating. Anthropic calls the numbers a lower bound, because only 33 partners’ reports and its open-source collaborations feed into them and the data is incomplete; it estimates the true effect is five or more times higher. Under half of the partners reported how many issues they had patched.
The CVP expansion was signaled in September. When Fable 5.1 and Mythos 5.1 were announced on September 1, the CVP was providing access to certain Opus- and Sonnet-class models and was expected to add Mythos-class models soon. At the Opus 5.5 launch on September 22, Anthropic said the new program would have three levels and include access to Mythos models. This announcement fills in those details, and Anthropic says the goal is to bring Glasswing’s benefits to a much wider pool of cyber defenders. On the biology side, applications for the Life Sciences Verification Program (LSVP) opened in beta on September 17. Relaxing domain-specific safeguards only for vetted parties appears to be the common approach across both fields.
Conditions to check before applying
If you use Claude for security work and keep running into blocks on the public models, the first step is to work out which tier your work falls under. SOC work, incident response, malware analysis, and vulnerability validation point to Defense Access; authorized penetration testing or red-teaming points to Red Team Access. Red Team review is expected to take several weeks, but qualifying organizations are enrolled in Defense Access in the meantime.
Defense Access comes with a deadline. According to the Help Center, Defense Access users must move to phishing-resistant multi-factor authentication and stop using API keys by December 15, 20262. Until then, some form of MFA is mandatory and API keys expire every seven days. The Help Center recommends switching to Workload Identity Federation now. For teams whose automation depends on API keys, a seven-day expiry is likely to affect day-to-day operations directly.
Data handling is the other decision point. An organization that has relied on ZDR will need to decide whether to accept data retention until EFS arrives, unless it can already use Fable 5.1 or Mythos 5.1 under ZDR. If you run on Bedrock, EFS eligibility is the first question. After approval, if work your tier should permit is still blocked, Anthropic provides a form for reporting it1.
Sources
- Expanding the Cyber Verification Program - Anthropic announcement (October 6, 2026)
- Cyber Verification Program - Anthropic Help Center (updated October 2026)
- Anthropic folds Project Glasswing into an expanded three-tier Cyber Verification Program - SiliconANGLE (October 6, 2026)
Was this article helpful?
Thank you!
Received. Thank you!