Next upPhysical AI VC <> Founders Pitch Night #SFTechWeek @Mission Robotics
News

Anthropic Expands Cyber Verification Program Into Three Access Tiers

Anthropic’s expanded Cyber Verification Program sets three access tiers, with eligibility, permitted work and safeguards tied to cybersecurity risk.

D
Oct 6, 2026 · 2 min read

Anthropic has expanded its Cyber Verification Program, creating three tiers that give qualified cybersecurity professionals different levels of access to advanced models and reduced cyber safeguards. The least-restricted tier is reserved for a limited set of organizations; individuals can qualify only for the defensive tier.

All three tiers include Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1 and future models, Anthropic said. A single application covers the program. Anthropic then places applicants in the highest tier they qualify for, considering factors such as the proposed work, identity verification, legal environment, diversion risk, end customer and requested access.

The entry tier, Defense Access, covers security operations, incident response, malware reverse engineering, and vulnerability analysis and validation. Eligible applicants include security teams at companies, nonprofits, universities and government agencies; critical-infrastructure operators; smaller security firms; open-source maintainers; and individual researchers with a record of reporting vulnerabilities. Individuals cannot apply for either higher tier.

Red Team Access adds authorized penetration testing and red-teaming for systems an organization has permission to assess. Anthropic said real-time blocks remain for actions that could cause physical harm or mass disruption, including ransomware deployment, damage to physical systems and penetration testing of high-risk safety systems. Reviews are expected to take a few weeks, and qualifying applicants will receive Defense Access while a higher-tier review is pending, the company said.

Specialized Access has the fewest cyber blocks. Anthropic limits it to verified organizations authorized to test systems whose failure could endanger lives or disrupt markets, including flight operations, power grids, telecommunications, interbank transfers and government administrative networks. The company said every organization seeking this tier currently undergoes an in-depth review conducted in collaboration with the US government. Anthropic did not identify the participating agencies or say whether the government can independently approve, reject or veto an applicant.

Existing Project Glasswing members will move to Specialized Access for their current models without another approval. The expanded program combines Glasswing with Anthropic’s earlier Cyber Verification Program.

For organizations in all three tiers, Anthropic’s published security requirements call for a named security contact, personal sign-ins, attributable usage profiles, cooperation on incidents and misuse, and notice of material organizational or security changes. Red Team and Specialized Access impose additional controls including organization-domain accounts, managed devices, logged network egress for offensive or agentic work, background or equivalent identity checks, offboarding procedures and a default limit of 25 approved users. Those two tiers require phishing-resistant multifactor authentication and short-lived platform-managed credentials immediately; Defense Access has until December 15, 2026, to adopt those controls. Specialized Access also requires federated single sign-on and endpoint application control or endpoint detection and response in enforcement mode.

More news