Anthropic Merges Cybersecurity Programs Into Three Access Tiers
The system sets different safeguards for defensive work, authorized red-team testing and critical infrastructure, covering Claude Opus 5.5, Sonnet 5.5 and Mythos 5.1.

Anthropic merged its cybersecurity access programs into a three-tier system that sets different levels of Claude access for defenders, authorized red teams and organizations testing critical infrastructure.
The system, announced Oct. 6, covers Claude Opus 5.5, Claude Sonnet 5.5 and Claude Mythos 5.1. Eligibility depends on an applicant’s role, authorization and security controls.
Defense Access is intended for security operations, incident response, malware reverse engineering, vulnerability analysis and validation. Eligible applicants include companies, nonprofits, universities, government bodies, critical-infrastructure operators, open-source maintainers and individual researchers with a record of reporting vulnerabilities.
Red Team Access is limited to organizations conducting authorized penetration tests or red-team operations. Testing is restricted to systems the organization is authorized to assess. Ransomware deployment, physical-system damage and penetration testing of high-risk safety systems remain blocked.
Specialized Access imposes the fewest cybersecurity restrictions and is available only to a small number of vetted organizations testing authorized systems whose failure could endanger lives or disrupt markets, including aviation, energy, telecommunications, interbank-transfer and government networks. Anthropic reviews applicants in depth with the U.S. government.
Existing Project Glasswing members will move into Specialized Access without reapproval for current models.
An Anthropic-run CyScenarioBench evaluation tested Claude Opus 5.5 on 10 challenges, with five attempts per challenge and 50 trials in each access setting. Without Cyber Verification Program access, every task was blocked at the first prompt. Defense Access blocked 46 trials, while four succeeded. Red Team Access produced no blocks and completed 34 trials.
The no-safeguard setting produced a 67.6% completion rate, which Anthropic uses as representative of Specialized Access. The evaluation measured Anthropic’s own model and safeguards.
From April through July 2026, Project Glasswing partners identified no fewer than 129,000 confirmed software vulnerabilities. Anthropic’s open-source scanning found another 5,500 between April and October. More than 33,000 were rated critical or high severity, a lower-bound estimate based on partial data from 33 partner reports and open-source partnerships. Fewer than 50% of partners disclosed patched-vulnerability figures because fixes were still underway.
The Cyber Verification Program is available through the Claude Platform, Google Cloud Vertex AI and Microsoft Foundry. Amazon Bedrock access is limited to customers eligible for Enterprise Frontier Safeguards.