---
title: "Anthropic's Cyber Verification Program Gets Three Tiers: Who Unlocks What, and Why Agents Care"
date: 2026-10-07
tags: ["anthropic","claude","security","cyber-verification-program","mythos","claude-code"]
categories: ["Industry"]
summary: "On October 6 Anthropic expanded its Cyber Verification Program into three tiers (Defense, Red Team, Specialized) covering Opus 5.5, Sonnet 5.5, Mythos 5.1 and future models. Defense Access is approved in days, yet Anthropic's own test shows most offensive tasks stay blocked (46 of 50) without a higher tier."
---


![Anthropic's Cyber Verification Program Gets Three Tiers: Who Unlocks What, and Why Agents Care](/images/anthropic-cyber-verification-program-three-tiers-defense-red-team.png)

Every security engineer who has asked a frontier model to explain a piece of malware knows the experience: a polite refusal, followed by thirty minutes of rephrasing. Anthropic's answer, announced on **October 6, 2026**, is to stop pretending one classifier setting fits a SOC analyst, a pentest shop and a power-grid operator. The expanded **Cyber Verification Program (CVP)** now has three tiers, each with different identity checks and different guardrails ([Anthropic](https://www.anthropic.com/news/cyber-verification-program)).

## The three tiers

| Tier | Who qualifies | What it unlocks | Approval speed |
|---|---|---|---|
| **Defense Access** | Security teams at companies, nonprofits, universities and government bodies; critical-infrastructure operators; smaller security firms; open-source maintainers; individuals with a vulnerability-disclosure track record | Defensive work: SOC tasks, incident response, malware reverse-engineering, vulnerability analysis | A few days |
| **Red Team Access** | In-house and government red teams, penetration-testing firms (individuals excluded) | Authorized penetration testing and red-teaming on systems the customer is permitted to test | Weeks |
| **Specialized Access** | A limited set of verified organizations testing critical safety systems: flight operating systems, power grids, telecom, interbank infrastructure, government networks | The fewest cyber blocks | Government-reviewed |

Covered models are **Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1**, and "new models moving forward". Existing members are evaluated automatically for new releases, and admins assign workspace access. Project Glasswing members move to Specialized Access without reapproval. Applications go through the Anthropic developer portal.

## The number that matters: 46 of 50

The most interesting detail is not the tiers themselves but the baseline. In Anthropic's own testing, Defense Access still leaves **46 of 50** test cyber-operation tasks blocked. That is deliberate. Defense Access is for reading and understanding attacks, not for running them. If you want a model to actually carry out an authorized engagement, you need Red Team Access, and even there Anthropic keeps "real-time blocks on actions that could cause physical harm or mass disruption, such as deploying ransomware".

Two practical consequences:

1. **The tier is a capability decision, not a trust badge.** Picking Defense Access because it clears in days, then discovering your pentest workflow is blocked, costs you weeks. Match the tier to the work before applying.
2. **Red Team Access keeps your Defense tier during review.** You are not left with nothing while the longer review runs.

## What you get without any enrollment

CVP is not a gate on ordinary security work. According to the announcement, code review, patching, vulnerability finding in code you own, and security alert triage remain available to everyone without enrolling. For most engineering teams that covers the daily reality: you want your agent to find the injection bug in your own repo and write the fix, and it already will.

If you run Claude Code in CI, this is the part to test. A review job that flags vulnerabilities in your own diff should work unchanged. A job that tries to build a proof-of-concept exploit against a third-party service is where you will hit the classifier.

## The trade-off: monitoring in exchange for latitude

Enrollment is not free. Anthropic says data retention is **required during enrollment for misuse monitoring**. A zero-data-retention option, **Enterprise Frontier Safeguards**, is slated for fall 2026 but has not launched yet. If your security team's policy forbids sending incident artifacts to a vendor that retains them, that gap is the real blocker, and it is worth raising with your account team before you build a workflow on top of the program.

This is the honest shape of the bargain: more capability, in exchange for knowing who is asking and watching what they do. I think it is the right trade. The alternative, tuning one classifier for the whole planet, either refuses defenders or arms attackers.

## Why this matters for spec-driven teams

Spec-Driven Development leans on agents that run autonomously for long stretches. Security work is where that autonomy collides hardest with safety policy: an agent mid-task cannot stop and explain to a classifier that this is an authorized engagement. Identity-scoped access moves that conversation to enrollment time, where a human at Anthropic can verify it once, rather than to every prompt.

Compare that with the editor-centric approach. A tool that keeps a human approving every step can paper over a refusal by letting the developer click around it. An autonomous agent cannot, so the vendor has to solve the problem properly: verified identity, tiered permissions, monitored usage. Anthropic is doing that work in the open, and the tier structure is more granular than anything I have seen from the other labs.

## What to do this week

- **Security teams:** apply for Defense Access now if you do any malware analysis or IR. It is the fast tier and costs nothing but the retention agreement.
- **Pentest and red-team firms:** apply for Red Team Access in parallel, and expect weeks. Individuals are excluded, so the application has to come from the organization.
- **Everyone else:** do nothing, but run your own-code vulnerability checks through your agent to confirm they work as described.
- **Compliance owners:** ask about the Enterprise Frontier Safeguards timeline before committing sensitive workflows.

## Caveats

The 46-of-50 figure comes from Anthropic's own test set, and the post does not publish the tasks or methodology, so treat it as directional. Approval timings ("a few days", "weeks") are Anthropic's estimates, not commitments. And the summary of what each tier unlocks is high-level; the exact classifier behavior will only become clear as practitioners report back.

## Sources

- [Expanding the Cyber Verification Program, Anthropic](https://www.anthropic.com/news/cyber-verification-program)

