Anthropic Expands Cyber Verification Program Into Three Access Tiers
The vendor has separated defensive, authorized red-team and specialized critical-system work, while eligibility, monitoring and effectiveness remain defined by Anthropic.
Edited by Tyronne Panaino
Anthropic expanded its Cyber Verification Program on October 6 into three access tiers for security professionals, combining the earlier program with Project Glasswing. The change affects defenders seeking access to Claude models with fewer cyber blocks, because the permitted work, verification process and controls now differ across Defense Access, Red Team Access and Specialized Access.
The official announcement says all three tiers can include Claude Opus 5.5, Claude Sonnet 5.5 and Claude Mythos 5.1. That is a meaningful access-policy change, but it is not independent evidence that the models improve security outcomes or that the tier controls prevent misuse.
How the three access tiers differ
Defense Access is aimed at defensive work such as security-operations and incident-response tasks, malware reverse engineering, and vulnerability analysis and validation. Anthropic lists potential applicants across companies, nonprofits, universities, government bodies, critical-infrastructure operators, smaller security firms, open-source maintainers and individual researchers with an established vulnerability-reporting record.
Red Team Access adds authorized penetration testing and red-team work. Anthropic says users in this tier may test only systems they are authorized to assess, and it limits eligibility to organizations rather than individual researchers. The company also says some actions associated with physical harm or mass disruption remain blocked.
Specialized Access has the fewest cyber blocks and is reserved for a smaller set of verified organizations testing safety-sensitive systems, including infrastructure whose failure could affect people or markets. Anthropic says it reviews organizations in this tier in depth with the US government. Existing Project Glasswing members are being moved into Specialized Access without reapproval for their current models.
The operational trade-off is access for monitoring
Anthropic requires data retention for organizations enrolled in the program so it can monitor for cyber misuse. The company says a planned Enterprise Frontier Safeguards option, expected later in the fall, is intended to let eligible organizations keep data in cloud infrastructure they control while retaining safeguards. Until then, Anthropic describes a narrower zero-retention path for some organizations using Claude Fable 5.1 or Claude Mythos 5.1.
Availability also varies by platform. Anthropic lists the Claude Platform, Google Cloud Vertex AI and Microsoft Foundry as supported channels. Amazon Bedrock access is limited to customers eligible for Enterprise Frontier Safeguards. Those boundaries matter because a program approval does not automatically establish identical deployment or privacy options across every hosting route.
What security teams should verify
Applicants should treat the tier name as the start of a control review, not as a blanket authorization. The useful questions are which work is permitted, which systems the organization is authorized to test, how access is assigned to workspaces, what data is retained and which actions remain blocked. Teams also need their own escalation, review and incident-handling processes around model use.
The strongest public evidence is still first-party. Anthropic defines the tiers, controls, review process and supported platforms, but the fetched source does not provide independent validation of the access model or comparative evidence showing better real-world defensive outcomes. Future evidence should distinguish successful vulnerability discovery from safe remediation, false positives, duplicated findings and misuse prevention.
Evidence quality and next checkpoint
The launch and tier structure are confirmed by Anthropic's dated announcement. Internal confidence is medium because the evidence comes from the vendor operating the program. The next verifiable checkpoints are published eligibility details, the release and independent assessment of Enterprise Frontier Safeguards, and outcome evidence that separates vendor measurements from external evaluation.
Status
Confirmed. Anthropic has launched the expanded three-tier program; effectiveness and misuse-prevention claims remain independently unverified.
Sources
Update note: Last reviewed 2026-10-06. We will revise this post if Anthropic changes tier eligibility, platform availability, retention controls or publishes independently testable outcome evidence.
Sources
Drafted with AI assistance from source briefs; reviewed for citation completeness and label accuracy.