Anthropic · 2026-10-06 · major
Cyber Verification Program — Anthropic opens three tiers of cyber access to Claude
Anthropic merged Project Glasswing and its Cyber Verification Program into one program with three tiers: Defense, Red Team and Specialized Access. Verified security teams get Claude models with fewer cyber blocks.
Verified defenders and red teams can now get Claude with fewer cyber blocks, sorted into three access levels.
Quick facts
| Maker | Anthropic |
|---|---|
| Tiers | Defense, Red Team, Specialized Access |
| Models | Claude Opus 5.5, Sonnet 5.5, Mythos 5.1 and future models |
| Replaces | Project Glasswing + the old CVP, merged |
| Review time | Days (Defense), weeks (Red Team) |
| How to join | Apply in the Anthropic portal |
What is it?
Anthropic's expanded Cyber Verification Program, announced on October 6, 2026, merges Project Glasswing and the earlier CVP into one offering with three access tiers. Defense Access covers incident response, malware reverse engineering and vulnerability validation. Red Team Access adds authorized penetration testing, and Specialized Access is for verified organizations allowed to test safety systems.
How does it work?
Organizations apply through the Anthropic portal and are reviewed per tier; an admin then assigns the program to specific Claude Console workspaces. Inside those workspaces Anthropic turns down its real-time cyber classifiers, with Specialized Access having the fewest blocks. Existing Glasswing and CVP members keep their settings and are evaluated automatically for the new models.
Why does it matter?
General Claude models block many requests that look like attacks, which also stops legitimate defenders. A tiered program gives security teams, open-source maintainers and individual researchers a clear path to the full cyber capability of Opus 5.5 and Mythos 5.1. Anthropic says Glasswing partners found at least 129,000 verified vulnerabilities between April and July 2026.
Who is it for?
security teams, pentesters and open-source maintainers
Frequently asked questions
- Who can apply to Anthropic's Cyber Verification Program?
- Anthropic's Cyber Verification Program is open to security teams at companies, nonprofits, universities and government bodies, critical infrastructure operators, security firms and open-source maintainers. Individual researchers can apply too, but only for Defense Access. Specialized Access is limited to verified organizations authorized to test safety systems, reviewed with the US government.
- How long does Cyber Verification Program approval take?
- Anthropic says Defense Access applications to the Cyber Verification Program take a few days to review, and Red Team Access takes a few weeks. After approval, an organization admin has to assign the program to specific workspaces in the Claude Console before the reduced cyber blocks apply.
- What happens to existing Project Glasswing members?
- Project Glasswing and earlier CVP members keep their current settings for previous Claude models. Anthropic evaluates them automatically for the new models — Claude Opus 5.5, Sonnet 5.5 and Mythos 5.1 — under the merged Cyber Verification Program, so they do not need to start over.
- What if Claude blocks a legitimate security request?
- Anthropic runs a form for reporting cyber false positives and appealing a rejected Cyber Verification Program application. Its Help Center article on real-time cyber safeguards for Claude Opus and Sonnet explains which requests the classifiers block and how CVP changes that.
Try it
https://portal.anthropic.com/programs/cvp