Anthropic expands its Cyber Verification Program into three access tiers
The new structure gives vetted security professionals broader access while keeping the tightest controls on the most sensitive testing.
Anthropic has rolled its Cyber Verification Program into a new three-tier system that expands access to stronger cyber capabilities for vetted security professionals while keeping tighter controls for general users. The company says Defense Access covers defensive work, Red Team Access adds authorized penetration testing, and Specialized Access is reserved for a small set of verified organizations testing high-stakes systems such as flight controls, power grids, telecom networks, and interbank infrastructure. Existing Project Glasswing members will move into the Specialized Access tier, and Anthropic says it expects to respond to many Defense Access applications within a few days, while Red Team Access reviews should take a few weeks. The company also says data retention is required for CVP participants for now, with Enterprise Frontier Safeguards planned for later this fall to combine cloud-controlled storage with stronger privacy and safety controls. In testing, Anthropic reports that Claude Opus 5.5 was blocked on all 50 trials without CVP access, blocked in 46 of 50 Defense Access trials, and completed 34 of 50 tasks in the Red Team Access tier with no blocks.
Why it matters
The change separates routine defensive work from authorized penetration testing and the most sensitive infrastructure testing, so access now depends more clearly on the kind of security work being done. It also means organizations in the program must accept data retention for now, with a later privacy and storage update planned this fall. Anthropic’s test results suggest the tiers materially change what Claude Opus 5.5 can do under the program.
Keep or strike?
Does this story matter, or is it hype? Mark it before you see what everyone else did.
Sources
- Anthropic News