Anthropic's Cyber Verification Program Turns One Claude Model Into Three Security Tools
The same Opus 5.5 blocks every offensive task or finishes 34 of 50, depending on which tier you verify into. Here is how to pick one and what it costs you.
The most interesting number Anthropic published on October 6 has nothing to do with a new model. It is a before-and-after table for a model that already exists. On a test of multi-stage offensive cyber operations, Claude Opus 5.5 with general access had "every task blocked on the first prompt." The same model, under a different access tier, hit "no blocks" and completed 34 of 50 tasks.
Same weights. Same API. A different answer about who you are.
That is what the expanded Cyber Verification Program actually ships. It folds Project Glasswing and the older CVP into three tiers, Defense Access, Red Team Access and Specialized Access, and each tier is a different security tool wearing the same model name. If your team does security work with Claude, the question you should be asking has changed. It used to be "which model is best at this?" Now it is "which tier do we qualify for, and what do we give up to get it?"
Why the tier is the spec now
Security teams have complained about refusals for as long as frontier models have had safety training. You ask for help reproducing a vulnerability in your own code, and the model treats you like an attacker. The usual workaround was prompt gymnastics or switching to a model with weaker guardrails.
Anthropic's answer is to stop pretending one policy fits every user. The CVP post spells out the gap with its own evaluation, CyScenarioBench, which it describes as a test that "measures whether models can plan and execute multi-stage cyber operations under realistic constraints":
- Without CVP: every task blocked on the first prompt.
- Defense Access: "46 of the 50 trials were blocked at some point in the challenge, while the remaining four tasks succeeded."
- Red Team Access: "no blocks occurred, and Claude Opus 5.5 successfully completed 34 of the 50 tasks."
Read that as a capability curve that has nothing to do with training. A security firm on Red Team Access and a hospital IT team on general access are, for offensive work, using different products. Any internal evaluation you ran on "Claude for security" last quarter measured the tier you were on, not the model.
Here is my position. This is the more honest design compared with the alternatives, and it shifts real work onto buyers. Mistral launched Mistral Large 4 the same day and reported that Claude Opus 5.5 and GPT-6 Astra "score near zero" on a vulnerability reproduction test "because they refuse to perform the task." That framing treats refusal as a weakness. The CVP table shows the refusal is a setting, and the setting depends on paperwork your team has or has not done.
What each tier actually covers
The three tiers are not a simple dial from "safe" to "unsafe." Each has its own eligibility, review time and hard limits.
Defense Access covers "security operations center and incident response tasks, reverse-engineering malware, and analyzing and validating vulnerabilities." The eligibility list is wide: security teams at companies, nonprofits, universities and government bodies "defending systems they own or maintain," critical infrastructure operators "of any size, such as regional hospitals or municipal utilities," smaller security firms, open-source maintainers, and "individual researchers with a track record of reported vulnerabilities." Anthropic says it aims to respond "within a few days."
This is the tier most readers should look at first. If you maintain an open-source project and want Claude to help validate incoming vulnerability reports, you are squarely the audience.
Red Team Access "adds authorized penetration testing and red-teaming to the defensive uses above." It is for in-house red teams, government red teams, and security and penetration testing firms. Two limits matter. "Currently, this tier is for organizations only; individual researchers are not eligible." And review takes "a few weeks."
Specialized Access is for organizations "authorized to test safety systems that could impact people's lives or disrupt markets, such as flight operating systems, power grids, telecom networks, interbank transfer infrastructure, and government administrative networks." Anthropic reviews "every organization in depth in collaboration with the US government." Existing Project Glasswing members move into it automatically.
All three tiers get Claude Opus 5.5, Claude Sonnet 5.5 and Claude Mythos 5.1, and Anthropic says new models will be added as they ship.
The Red Team description carries the limit worth memorizing: users "will still experience real-time blocks on actions that could cause physical harm or mass disruption, such as deploying ransomware, damaging physical systems, or pen testing high-risk safety systems." Specialized Access is pitched as the tier with the fewest cyber blocks, which is not the same as none.
The price is your data
The line that deserves the most attention from security leads is the retention clause. "Data retention is required for organizations enrolled in the program so that we can monitor for cyber misuse."
For a lot of security teams that is a real cost. The prompts you send during incident response contain internal hostnames, log excerpts, sometimes credentials that leaked into the logs you are triaging. Enrolling in CVP means Anthropic keeps that data to watch for misuse.
There are two partial exits. Anthropic says "organizations with access to Claude Fable 5.1 or Claude Mythos 5.1 with zero data retention can also use CVP with zero data retention." And once Enterprise Frontier Safeguards is "available later this fall, eligible organizations will be able to store data in cloud infrastructure they control." Until then, most teams face a straight trade: fewer blocks in exchange for retention.
Platform matters too. CVP is available on the Claude Platform, Google Cloud's Vertex AI and Microsoft Foundry, but "only available on Amazon Bedrock for customers eligible for Enterprise Frontier Safeguards." If your security tooling runs on Bedrock, check eligibility before you assume the tier follows you.
The scale argument behind it
Anthropic justifies loosening blocks with the results from Project Glasswing. Per the post, partners "uncovered at least 129,000 verified software vulnerabilities between April and July 2026," and Anthropic's own open-source scanning "found an additional 5,500 verified software vulnerabilities between April and October 2026."
Notice the two different windows. The partner figure stops in July, while Anthropic's own scanning runs to October. Both are Anthropic's own numbers about its own program, and "verified" is Anthropic's word. They make a reasonable case that defenders get real value from fewer blocks. They do not tell you what your team will find.
Put this into practice
If you run security work through Claude, here is the lowest-friction path through the new program.
-
Find out what tier you are on today. Most teams are on general access without knowing it is a tier at all. Ask whoever administers your Claude organization whether you are enrolled in CVP. If you were an existing member, Anthropic says existing members keep their current settings for previous models and will be "automatically evaluated" for the new ones, but "admins will need to assign access to specific workspaces." An existing enrollment does nothing until someone assigns it.
-
Apply for Defense Access first, even if you want Red Team. It reviews in days, accepts individuals and maintainers, and covers most of what blue teams do. Red Team review takes weeks and is organizations only. Get the fast tier while the slow one is pending.
-
Read the retention clause with your data owner before you apply. Decide in advance what classes of data are allowed into a CVP workspace. A separate workspace for CVP work, with its own access list, keeps retained data from spreading across your org's other projects.
-
Re-run your evaluations per tier. If you benchmarked Claude for security tasks, those numbers are tied to the tier you used. Keep a small, fixed set of your own tasks and run it again after any tier change. The CVP table shows the difference can run from zero to 34 of 50.
-
Write down your authorization scope. Red Team Access assumes you only test systems you are authorized to test. Keep that scope in writing and in the workspace instructions, so an agent working at a higher tier does not wander into a system your contract does not cover.
Where this falls short
Several things in the program should make you cautious.
The benchmark is Anthropic's own. CyScenarioBench is described in the post, not published as an open suite you can rerun. The 34 of 50 figure is the vendor grading the vendor. Treat it as a direction, not a guarantee.
Defense Access still blocks a lot. 46 of 50 trials hit a block at some point. For many defensive tasks that will not matter, but if your incident response involves reproducing an attacker's chain, expect friction on this tier.
Individuals hit a ceiling. Independent researchers can reach Defense Access with a track record, but not Red Team Access. A lot of real-world offensive research comes from individuals, and this tier structure leaves them on the lower rung.
Retention is the default, and ZDR is narrow. Zero data retention works only for organizations that already have it on Fable 5.1 or Mythos 5.1, or that later qualify for Enterprise Frontier Safeguards. Everyone else pays in data.
Blocks are still opaque. The post explains categories of what stays blocked, such as ransomware deployment and pen testing high-risk safety systems, but a block in the middle of a task does not come with an appeal path described in the post. You will find the edges by hitting them.
The decision is yours now
For years the security community argued about whether frontier models should help with offensive work at all. Anthropic's answer is a ladder, and the ladder puts the decision partly in your hands. You choose whether to apply, which tier to chase, what data you accept leaving the building, and how tightly you scope what an agent may touch.
That is more control than a single policy gave you. It is also more responsibility. Pull up your admin console, find out which rung you are standing on, and decide whether the next one is worth its price.
Sources: Anthropic, Expanding the Cyber Verification Program (October 6, 2026); Anthropic, Project Glasswing; Mistral, Mistral Large 4 (October 6, 2026).
Medium metadata
- SEO title: Anthropic Cyber Verification Program: Three Tiers, One Claude Model
- Meta description: Anthropic's expanded CVP splits Claude's security capability into Defense, Red Team and Specialized Access. What each tier allows, what it costs in data retention, and how to apply.
- Tags: Anthropic, Cybersecurity, AI Safety, Claude, Penetration Testing
- Canonical: import from the fervorai.dev URL