Anthropic's Cyber Verification Program Now Has Three Tiers. Which One to Apply For

Anthropic split its Cyber Verification Program into Defense, Red Team and Specialized tiers. Who qualifies, review times, the retention catch and Bedrock.

Anthropic reorganized its Cyber Verification Program (CVP) on October 6 into three access tiers. Each turns down the cyber classifiers on Claude Opus 5.5, Claude Sonnet 5.5 and Claude Mythos 5.1 by a different amount. The company says it is “integrating” the CVP with Project Glasswing, the Mythos access program for organizations securing critical software, and members of either program move across without reapplying. Anthropic, Expanding the Cyber Verification Program Fable 5.1 is not on the list of covered models. It stays generally available with what Anthropic calls conservative cyber safeguards, which matches the split we described when Fable 5.1 and Mythos 5.1 launched as one model with two access policies.

The parts that decide whether a team can use the program sit in two Help Center articles, the program page and the security requirements. This guide draws on all three, plus a reading of the one evaluation Anthropic published to show how the tiers behave.

Which tier fits which job

TierWork it coversWho can applyStated review timeWhat still blocks
Defense AccessSOC and incident response, malware reverse-engineering, analyzing and validating vulnerabilitiesOperators of critical infrastructure of any size and open-source maintainers; individuals with “a track record of reported vulnerabilities”, on a paid plan“within a few days”Multi-stage offensive work; see the eval below
Red Team AccessDefense Access plus authorized penetration testing and red-teaming against systems you are authorized to testOrganizations only: in-house and government red teams, pentest firms“a few weeks”, with Defense Access granted while you waitReal-time blocks on deploying ransomware, damaging physical systems, pentesting high-risk safety systems
Specialized AccessTesting safety systems “that could impact people’s lives or disrupt markets”: flight operating systems, power grids, telecom, interbank transfer, government administrative networksA limited set of verified organizations, each reviewed “in collaboration with the US government”; Glasswing members transition here without reapproval for current modelsNot stated“the fewest cyber blocks”

Sources: Anthropic’s announcement and the Help Center program page.

Anthropic’s position is that the generally available models already handle “secure code review, threat modeling, patching known issues, finding vulnerabilities in your own source code, and triaging security alerts”, and that the work the classifiers interrupt is “malware analysis or exploit validation”. Help Center If your blocks come from source-code review, the program will not change much. If they come from reversing a sample or confirming an exploit against a known CVE, Defense Access is the tier built for that. Red Team Access is worth the longer review and heavier controls only if someone on the team is authorized to attack systems, and Anthropic will still stop the model at the actions it lists.

The review times do not quite agree between the two documents. The announcement gives “a few days” for Defense and “a few weeks” for Red Team; the Help Center says Anthropic aims to send a decision or a request for more information within seven business days, from a single application that is placed “at the highest tier based on the information we receive”. Anthropic Help Center Read the seven days as the target for a first reply, not for a Red Team decision. Mythos access on AWS, Google Cloud and Microsoft Foundry takes about five more business days after approval. Help Center

What each tier costs in controls

The security requirements article is where the tiers separate, and it reads like a contract because it is one: “Customer must meet and maintain” the controls for each access level held. CVP Security Requirements

Every tier requires a named security contact, incident reporting to Anthropic within 72 hours (24 for a security incident), investigation of any abuse Anthropic flags within 48 hours, personal sign-ins with no shared seats, and user profiles kept on so each request attributes to a named person or workload identity.

Defense Access adds a deadline. All accounts on the granted workspace need some form of MFA now, and by December 15, 2026 they need phishing-resistant MFA: a FIDO2/WebAuthn key, a passkey or a smartcard. Authenticator-app codes, push approvals, SMS and email magic links do not count. By the same date, long-lived API keys are out on every platform: no static Anthropic keys, no downloaded Vertex service-account JSON, no IAM access-key pairs on Bedrock beyond 12-hour session keys, no Azure API keys or exported client secrets. Until then a key is allowed only if it sits in a secrets manager, belongs to one person or workload, stays out of source code and is rotated at least every seven days, and Anthropic says it may enforce the seven-day lifetime itself. CVP Security Requirements The Help Center suggests moving to Workload Identity Federation now rather than in December.

Red Team Access has no grace period. Phishing-resistant MFA is required from the start, across the workspace, the identity provider, the cloud identities that can call the model and anything that issues model credentials. The tier also caps the workspace at 25 approved users (more on request), requires company-domain accounts and managed devices with scheduled OS updates, identity checks (and criminal-history checks where lawful) for every user including contractors, an off-host egress allow-list wherever the model does offensive or agentic work, 24-hour credential revocation and three-business-day offboarding. Specialized Access takes the same list and adds federated SSO plus application allow-listing or an EDR agent in block mode on every device. For government bodies, a FISMA Authority to Operate with an annual Inspector General assessment covers the device, background-check and incident-procedure items. CVP Security Requirements

A small pentest firm running on personal laptops and webmail will not pass Red Team Access as written, which is probably the intent.

Individuals are a separate case. They are eligible for Defense Access only, on a paid plan, must sign in through Google or an equivalent identity provider, get one API key until the cutoff, and the requirements are explicit on retention: “All traffic under the grant is retained and monitored. Zero data retention is not available.” CVP Security Requirements

The data-retention requirement, and who escapes it

Organizations in the program must retain data so Anthropic can “monitor for cyber misuse”. The one exception: until Enterprise Frontier Safeguards (EFS) ships, “organizations with access to Claude Fable 5.1 or Claude Mythos 5.1 with zero data retention can also use CVP with zero data retention.” The announcement dates EFS to “later this fall”; the Help Center says only that it is not yet available and will let eligible organizations keep data in infrastructure they control. Anthropic Help Center We covered what EFS is meant to do in the Fable 5.1 article: customer-controlled storage, with the customer doing human review by default.

That clause decides the Bedrock question. CVP is available on the Claude Platform, Vertex AI and Microsoft Foundry. On Amazon Bedrock it is “only available for customers eligible for Enterprise Frontier Safeguards”, and the FAQ explains why: “Amazon Bedrock does not yet support human review of automated safety flags, which CVP requires by default.” On Bedrock, then, CVP is limited to organizations that already hold a data-retention exemption for Fable 5.1; they can run it under ZDR now and move to EFS when it arrives. Anthropic says it is “working to expand CVP to all customers on Bedrock”. Help Center For a team whose Claude traffic goes through Bedrock without a negotiated Fable ZDR exemption, the program is closed for now. The Help Center lists “Claude Platform on AWS” as a separate route with no such restriction, which may be an option for some AWS shops.

One more line for people who build tools: approval covers your own security work. “Building a client-facing product on these capabilities is governed separately by our Cyber Productization Policy”, with that application “available to users in CVP shortly”. Help Center

How to read the 50-trial eval

Anthropic published one test of the tiers: Claude Opus 5.5 on CyScenarioBench, ten challenges with five attempts each, repeated with the safeguards tuned for each tier. Without CVP, every task was blocked on the first prompt. In Defense Access, “46 of the 50 trials were blocked at some point in the challenge, while the remaining four tasks succeeded”. In Red Team Access no blocks occurred and the model completed 34 of 50, which Anthropic calls “effectively equivalent to the model’s 67.6% success rate on this evaluation with no safeguards applied (representative of Specialized Access)”. Anthropic

Those numbers need context before anyone treats them as a product spec. CyScenarioBench is Irregular’s benchmark, not Anthropic’s. Irregular describes it as measuring “an LLM’s ability to plan and execute multi-stage cyber scenarios” and says “the evaluation set remains private to avoid contamination”. Irregular, CyScenarioBench The 67.6% comes from the Opus 5.5 system card, which runs a named 10-challenge subset with “cyber mitigations turned off” and reports the average solve rate; Mythos 5.1 scored 61.7% and Opus 5 scored 53.0% on the same subset. Claude Opus 5.5 System Card, section 3.3.2 Nobody outside the two companies can rerun it.

The test measures offensive work by design, which is why Anthropic says it expected heavy blocking in Defense Access. The 46 of 50 tells a Defense applicant that the tier will not run multi-stage attack scenarios. It says nothing about the number that applicant cares about: how often the classifier interrupts malware analysis or exploit validation the tier is supposed to allow. Anthropic has not published a false-positive rate for any tier. The Fable 5.1 launch gave a relative figure, about 60% fewer interventions per Claude Code session than the Fable 5 controls, and nothing absolute. There is a form for reporting blocks on work your tier should permit, which is where that data will accumulate.

“Blocked at some point” is also not “failed”. The sentence makes the four successes the trials with no block, but it does not say whether any of the 46 recovered after a block and finished. And with five attempts per challenge, one scenario the classifier never catches accounts for four or five of the fifty, so the four successes fit a single challenge slipping through as well as they fit an 8% leak spread across the set.

For Red Team Access, 34 of 50 is 68%, so the match to 67.6% is arithmetic rather than a separate measurement, and Specialized Access was not tested; the no-safeguards run stands in for it. What the test establishes, on Anthropic’s own terms, is that the Red Team classifier configuration did not intervene across 50 offensive trials. That is the claim a red team wants, and the data supports it.

Against OpenAI’s Daybreak

OpenAI’s equivalent is Daybreak, which it split into Blue and Red tiers on August 10. The structures look alike and differ at the model layer. Daybreak Blue lifts the platform cyber guardrails on the public GPT-5.6 Sol, which on OpenAI’s internal advanced-cyber benchmark moved completion from 1.5% to 2.0%; Daybreak Red provides GPT-5.6-Cyber, a separately trained checkpoint that completes 95%. Anthropic’s tiers use the same three models throughout and vary the classifiers around them, and its eval shows zero to 34 of 50 between the GA model and Red Team Access on one model. In OpenAI’s design the permissiveness lives in a different checkpoint; in Anthropic’s it lives in the gate.

The administrative controls have converged. OpenAI required hardware security keys on individual Daybreak accounts from September 1; Anthropic requires phishing-resistant MFA on Defense Access by December 15 and on the two higher tiers from day one. Both programs have separate application paths for individuals and organizations. The clearest difference is at the top: Anthropic reserves its highest tier for operators of safety-critical systems and reviews each with the US government, with pentest firms stopping at Red Team Access, while OpenAI’s Red tier is where it places its offensive model for vetted customers under contract.

The Glasswing numbers, kept apart

The announcement also reports what Glasswing produced, and the figures are easy to run together, so here they are separately. Glasswing partners “uncovered at least 129,000 verified software vulnerabilities between April and July 2026”. Separately, Anthropic’s own open-source scanning “found an additional 5,500 verified software vulnerabilities between April and October 2026”. Of the verified findings across both, more than 33,000 are rated critical or high severity so far. Anthropic The two counts cover different periods and different scanners, and the page does not add them into one headline.

Anthropic attaches its own caveats: the data is survey-based, from 33 partner reports and a subset of partners; organizations triaged differently; and fewer than half disclosed patch counts, often because fixes were still in progress. It calls the totals a lower bound and expects “the true impact to be at least five times higher”. Anthropic Those caveats cut both ways. When the first Glasswing update reported 10,000 findings in May, the independent review sample showed about 62% of confirmed findings holding up as high or critical on human grading, and patching was the bottleneck. A 129,000 figure with an undisclosed patch rate is the same shape at larger scale, and opening the program to more defenders adds to the discovery side of that ledger, not the fixing side.

What to do this week

If classifiers interrupt defensive work, apply once for the organization through the Verification Portal, describe the work, and let Anthropic place you. The application asks for an attestation to the controls of the tier you want, so read the requirements article first and decide which attestation you can honestly sign. Existing CVP and Glasswing members are evaluated automatically for the three new models and need an admin to assign the grant to workspaces or a custom role; Team, Max and Pro plans need no action. Help Center

Start the MFA and credential migration now regardless of tier. The December 15 cutoff applies to Defense Access, and Anthropic has reserved the right to shorten API-key lifetimes to seven days before then. If your Claude traffic is on Bedrock without a Fable ZDR exemption, the thing to watch is EFS, which Anthropic has promised for this fall. Anthropic is holding a CVP webinar on October 14 at 9am PT, which is the obvious place to ask for the tier comparison the Help Center embeds as an image and does not publish as text. Help Center

Continue reading.

Insight14 min read

Claude Haiku 5.5: A 90% List-Price Cut, a 75% Real One, and Five Ways to Get a 400

Haiku 5.5 lists at a tenth of Haiku 4.5's price; Anthropic says about 75% less in practice. The gap, the 400s after switching, and Sonnet 5.5 vs Luna.

Insight15 min read

Gemini API Preview Shutdowns: Veo 3.1 Moves to Omni, Voice Follows in November

Veo 3.1 and Omni previews may end from October 22, TTS and Live previews from November 17. Cost per clip, voice replacements and the January price rise.

Insight14 min read

Mistral Large 4: What Is Confirmed Before the Weights Drop, and What Is Not

Mistral Large 4 is a 1T-parameter MoE you can call today at a half-price preview. Weights, license and independent scores are still due. What to check.