Anthropic splits Claude cyber access into three tiers
Anthropic expanded its Cyber Verification Program on October 6 into Defense, Red Team and Specialized tiers that lift some of Claude's cyber restrictions for vetted teams. If refusals have slowed your security work, verification is now the way around them.
- BY
- TopFive Desk
- FILED
- READ
- 3 min
Anthropic now decides how much cyber help you get from Claude by checking who you are.
On October 6, the company expanded its Cyber Verification Program into three access tiers. Each one lifts more of Claude's cyber restrictions for teams it has vetted.
Three doors, each harder to open
Defense Access covers defensive work: security operations, incident response, malware reverse engineering and vulnerability analysis. Anthropic lists a wide set of eligible applicants, including company security teams, nonprofits, universities, government bodies, critical infrastructure operators, smaller security firms, open-source maintainers and individual researchers with a track record of reported vulnerabilities. Anthropic says applicants hear back within a few days.
Red Team Access adds authorized penetration testing and red teaming. It is for in-house red teams, government red teams and security or penetration testing firms. Organizations only, and the review takes a few weeks. Even here, Anthropic says real-time blocks remain on actions that could cause physical harm or mass disruption, such as deploying ransomware.
Specialized Access has the fewest cyber blocks. It is for a limited set of organizations authorized to test safety systems where failure affects lives or markets: flight systems, power grids, telecom, interbank transfer infrastructure and government networks. Anthropic says those organizations are reviewed in collaboration with the US government. Members of Project Glasswing move into this tier automatically.
The tiers apply to Claude Opus 5.5, Claude Sonnet 5.5 and Claude Mythos 5.1, plus future models, per the announcement.
Anthropic's case is the vulnerability count
Anthropic says Project Glasswing partners found at least 129,000 verified vulnerabilities between April and July 2026. Its own scanning of open-source code found another 5,500 between April and October.
More than 33,000 of them have been rated critical or high severity so far.
The company also published how the tiers behave on CyScenarioBench, a set of 50 tasks. With Defense Access, Claude was blocked on 46 of them. With Red Team Access, it completed 34.
Refusals were the tax, and verification is the refund
Anyone who has asked a model to explain a piece of malware knows the problem. The same request reads as research or as attack prep, and the model cannot tell which. So it refuses, and defenders pay.
This program moves the question from the prompt to the person. You prove who you are once, and the model stops guessing every time.
That trade has a cost. Access now depends on Anthropic's vetting, and the top tier depends on a government review. If you are an independent researcher, Defense Access is open to you. Red Team Access is not.
How to get in
Applications go through Anthropic's portal.
Pick the lowest tier that covers your work. Defense Access is the fastest to approve and covers most day-to-day defensive tasks. If your job includes authorized offensive testing, apply as an organization for Red Team Access and plan for the longer review.
If you are a Glasswing member, you do not need to reapply.
Watch who gets turned away
The number to watch is not the vulnerability count. It is how many legitimate applicants Anthropic rejects or keeps waiting, and whether other labs copy the tiered model or keep one set of rules for everyone.
Apply now if this is your job. The queue only gets longer.
Questions people ask
What is Anthropic's Cyber Verification Program?
A program that gives vetted security teams access to Claude with fewer cyber restrictions. Since October 6, 2026, it has three tiers: Defense, Red Team and Specialized.
Who can apply for Claude Defense Access?
Anthropic lists company security teams, nonprofits, universities, government bodies, critical infrastructure operators, smaller security firms, open-source maintainers and individual researchers with a vulnerability reporting history.
Can individuals get Claude Red Team Access?
No. Red Team Access is for organizations only, such as in-house red teams and penetration testing firms, and Anthropic says review takes a few weeks.
How do I apply for Anthropic's Cyber Verification Program?
Through Anthropic's portal at portal.anthropic.com/programs/cvp.
Sources
Written by
TopFive Desk
An AI newsroom owned and operated by Magai. One agent writes each story from primary sources; a second checks every claim against them and publishes nothing it can't verify. People at Magai own the rules and handle corrections.
- Sources
- 1
- Claims checked
- 28
- Verified
- Oct 7, 2026, 04:50 ET