One programme instead of two
Anthropic merged its two trusted-access cybersecurity programmes into a single Cyber Verification Program on 6 October, with three tiers that security teams apply to separately. Each tier gives access to Claude Opus 5.5, Claude Sonnet 5.5 and Claude Mythos 5.1, and to new models as they ship.
The company’s framing is that its generally available models are deliberately over-cautious. “Our generally available models … have conservative cyber safeguards that block most cyber work,” Anthropic wrote, describing the restriction as intended to limit what malicious actors can do while the company works to reduce false positives for secure coding.
For the past six months, two programmes handled the exceptions. Project Glasswing gave organisations securing the most critical software access to Claude Mythos. The earlier Cyber Verification Program gave vetted security teams reduced safeguards on Opus and Sonnet. Those are now one thing.
What each tier allows
Defense Access covers security operations centre and incident response work, reverse-engineering malware, and analysing and validating vulnerabilities. Anthropic expects many defensive organisations to qualify — company, nonprofit, university and government security teams defending systems they own, critical infrastructure operators “of any size, such as regional hospitals or municipal utilities”, smaller security firms, open-source maintainers and individual researchers with a track record of reported vulnerabilities. Applications are answered in a few days.
Red Team Access adds authorised penetration testing. It is open to in-house and government red teams and to testing firms, organisations only — individual researchers are not eligible — and review takes a few weeks. Real-time blocks remain on actions that could cause physical harm or mass disruption, including deploying ransomware and pen testing high-risk safety systems.

Specialized Access has the fewest blocks and is reserved for organisations authorised to test systems that could cost lives or disrupt markets: flight operating systems, power grids, telecom networks, interbank transfer infrastructure and government administrative networks. Anthropic says it reviews every organisation in this tier in depth in collaboration with the US government. Existing Glasswing members move across without reapproving for current models.
The company published its own block rates
Anthropic ran Claude Opus 5.5 through CyScenarioBench, an evaluation of whether a model can plan and execute multi-stage cyber operations under realistic constraints, five times against each of ten challenges in each tier. Without CVP access, every task was blocked on the first prompt. In Defense Access, 46 of the 50 trials were blocked at some point and four succeeded. In Red Team Access, nothing was blocked and Opus 5.5 completed 34 of 50 — which Anthropic says is effectively equivalent to the model’s 67.6% success rate with no safeguards applied at all.
These are Anthropic’s own figures on Anthropic’s own model, not an independent evaluation.

The number behind the pitch
The case Anthropic makes for widening access rests on Glasswing’s output. Partners uncovered at least 129,000 verified software vulnerabilities between April and July 2026, and the company’s own open-source scanning found a further 5,500 between April and October. More than 33,000 of those have been rated critical or high severity.
Anthropic is explicit that this is a floor, not a count: the figures come from 33 partner reports and partial survey data, organisations triaged differently, and fewer than half disclosed patched numbers because fixes were still in progress. The company says it expects the true impact to be at least five times higher — a claim it cannot show.
What to watch
Enrolled organisations must accept data retention so Anthropic can monitor for misuse. That changes later this autumn, when Enterprise Frontier Safeguards is due to let eligible organisations store data in cloud infrastructure they control. Until then, only customers already running Claude Fable 5.1 or Mythos 5.1 with zero data retention can use CVP without it.