Anthropic announced on October 6, 2026, that its Cyber Verification Program (CVP) had expanded into three tiers: Defense Access, Red Team Access and Specialized Access. The expansion brings the earlier CVP and Project Glasswing arrangements together. Qualifying participants can access Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1 and future models, subject to tier-specific verification and controls.

The new structure builds on the restricted access to Mythos 5.1 covered in NeoTeo’s earlier report.

What each access tier covers

Access tierWork coveredWho may apply
Defense AccessSecurity operations, incident response, malware reverse engineering, and vulnerability analysis and validationEligible security teams and individual researchers with a record of reported vulnerabilities
Red Team AccessAuthorized penetration testing and red-team exercisesOrganizations only
Specialized AccessTesting safety-critical systems, including flight operating systems, power grids, telecom networks, interbank transfer infrastructure and government administrative networksA limited set of verified organizations authorized to test those systems, with review involving the U.S. government

Individuals can apply for Defense Access, but not for Red Team or Specialized Access. Individual Defense applicants must have a paid plan. All applicants provide details about themselves and, where applicable, their organization; describe their security work; and attest to the controls required for the requested tier. Anthropic says it assigns applicants to the highest tier their application supports.

Safety limits and data retention

CVP access does not remove every safeguard. Anthropic says real-time blocks remain for actions that could cause physical harm or mass disruption, including deploying ransomware, damaging physical systems and penetration testing high-risk safety systems. Its Usage Policy also remains in effect.

The program requires data retention for misuse monitoring, with an exception for organizations that have an applicable zero-data-retention exemption for Claude Fable or Mythos. On October 6, Anthropic described Enterprise Frontier Safeguards (EFS) as a planned later-fall 2026 option that would let eligible organizations store program data in cloud infrastructure they control.

Vulnerability findings and the Opus 5.5 evaluation

Anthropic said Project Glasswing partners identified at least 129,000 verified software vulnerabilities from April through July 2026. Separately, Anthropic says its own open-source scans have found another 5,500 verified vulnerabilities from April through October 2026. The company also reported that more than 33,000 verified vulnerabilities were rated high or critical. Its partner tally draws on partial data from 33 reports, and Anthropic said it expects the overall impact to be at least five times higher.

In its CyScenarioBench evaluation of Claude Opus 5.5, Anthropic reported that Defense Access blocked 46 of 50 trials at some point; the other four succeeded. Red Team Access had no blocks and completed 34 of 50 tasks. These are results from Anthropic’s own evaluation, with trials blocked and tasks completed reported as separate measures.

Applications, review timing and platform access

Anthropic’s Help Center says it aims to notify applicants of a decision or request for more information within seven business days. Its announcement estimates a few days for Defense reviews and a few weeks for Red Team reviews.

Anthropic lists the Claude Platform, Google Cloud and Microsoft Foundry as CVP access channels. Amazon Bedrock access is limited to customers eligible for EFS. Anthropic described EFS on October 6 as planned for later in fall 2026.