Security teams can now apply for Defense, Red Team, or Specialized Access to advanced Claude models, with prohibited uses still blocked across the board
Anthropic wants to give security professionals sharper tools without handing the same tools to the people they’re defending against.
On October 6, 2026, the company expanded its Cyber Verification Program (CVP) with three new access tiers. Qualifying security organizations can now use advanced Claude models for both defensive and offensive cyber work, as long as they clear a verification process and stay inside the lines.
The models on offer are Claude Opus 5.5, Sonnet 5.5, and Mythos 5.1.
Three doors, three sets of keys #
The new structure splits access into Defense Access, Red Team Access, and Specialized Access. Each tier unlocks a different slice of capability.
Defense Access covers the blue-team staples: security operations center work, incident response, and reverse-engineering malware.
Red Team Access is for authorized penetration testing. Anthropic is limiting this tier to organizations only, so individual freelancers looking to moonlight as hackers-for-hire will need to look elsewhere.
Specialized Access sits at the top. It involves testing critical systems and comes with US government review baked in.
AI, tech, and the markets they move—in one daily briefing.
Daily. Free. Join 34,000+ readers across crypto, finance, and policy.
The dual-use problem, in tiers #
Under the expanded program, Anthropic will relax some of its high-risk dual-use classifiers for verified users. Classifiers are the automated filters that scan requests and block ones that look dangerous.
Prohibited activity stays blocked for everyone, verified or not.
Getting in requires an application with tier-specific requirements centered on proof of security controls. Processing times scale with risk. Basic tiers can take a few days. Red Team Access applications can take a few weeks.
Putting the tiers to the test #
Anthropic pointed to results from an evaluation using CyScenarioBench to show the tiers work as intended.
Defense Access blocked the majority of complex offensive scenarios. Red Team Access, by contrast, performed on par with unrestricted use, successfully completing 34 out of 50 assessed tasks.
From a select group to a wider field #
The CVP expansion builds on earlier efforts, including Project Glasswing. Previous support focused on a select group of critical infrastructure defenders. Now the program reaches a broader range of organizations doing legitimate cybersecurity work.
Existing participants won’t need to start over. Prior CVP members, including Forescout and Ridge Security, are transitioning into the new program automatically.
Disclosure: This article was edited by Diego Almada Lopez. For more information on how we create and review content, see our