On October 6, 2026, Anthropic announced that it is expanding its "Cyber Verification Program (CVP)" for cybersecurity professionals into three tiers and folding in "Project Glasswing," its effort to defend critical software. Every tier can use high-capability models such as Claude Mythos 5.1, but the work each tier permits and the controls it requires differ. Capabilities that Glasswing offered to a limited set of organizations will now extend to community hospitals, open-source maintainers, and established individual researchers. To decide whether to adopt it, it is not enough to ask what the model can find. You also need to look at who will test which targets, and how verification and remediation will proceed after findings come in.
What separates the three tiers is the permitted work, not the model name
All tiers of the new CVP include access to Claude Opus 5.5, Claude Sonnet 5.5, and Claude Mythos 5.1. Previously, Glasswing gave Mythos to organizations protecting critical software, while CVP relaxed safeguards on Opus and Sonnet for vetted teams. The restructuring handles model access and the scope of permitted cyber work under a single program.
Comparing the October 6 announcement with the Defense, Red Team, and Specialized sections of the security requirements by scope of work and user-side conditions gives the following. These are the new program's requirements as of October 7, 2026; existing users keep their current conditions for current access.
| Tier | Main work and targets | Authentication and credential requirements | Default seat allotment |
|---|---|---|---|
| Defense Access | Defense of one's own organization and similar, malware analysis, vulnerability analysis and verification. Open to organizations and to established individuals | Multi-factor authentication from the start. Must move to phishing-resistant methods and short-lived credentials by December 15 | No default headcount cap for organizations. An individual's access covers only that person |
| Red Team Access | Penetration testing and red-team activity on systems where permission has been granted. Organizations only | Phishing-resistant MFA and short-lived credentials from the start | Default of 25 people. Additional seats can be requested |
| Specialized Access | Authorized testing of safety systems that affect human life or markets. Limited organizations undergoing detailed review jointly with the U.S. government | Phishing-resistant MFA and short-lived credentials from the start. Organizational single sign-on also required | Default of 25 people. Additional seats can be requested |
The new CVP widens access to the same high-capability models while separating permitted work and user-side control requirements into three tiers. The 25 seats in the table are the default allotment for people who actually do the work or supervise it, and do not include IDs used for automated processing. Specialized is the tier with the fewest blocks on cyber work, but Anthropic does not describe it as one that lets every request through unconditionally.
Examples of Defense targets include defense teams at companies and universities, as well as community hospitals, municipal utilities, and open-source maintainers. Individuals can apply on a paid plan. Anthropic aims to respond to Defense applications within a few days, while it expects Red Team review to take several weeks; eligible organizations receive Defense access during that review.
The boundaries are not determined by industry alone. In Red Team, IT systems in critical industries can also be targets of authorized penetration testing. However, deploying ransomware, damaging physical systems, and penetration testing of high-risk safety systems remain blocked. Examples of Specialized targets include testing of aviation operations systems, power grids, and interbank payment infrastructure. Existing Glasswing participants will move to this tier and do not need to be reapproved for current models.
What 50 trials show about blocking versus capability
Anthropic evaluated each tier's safeguards using Claude Opus 5.5 on "CyScenarioBench," which plans and executes multi-stage attack operations. The setup was 10 tasks, 5 runs each, for 50 trials in total. With the generally available model, without CVP participation, every trial was blocked at the first input.
In Defense, 46 of 50 trials were blocked, including partway through, and the remaining 4 succeeded. In Red Team, nothing was blocked and 34 trials completed the task. 34÷50 is 68%, which the company says is essentially equivalent to the 67.6% success rate obtained without safeguards. For authorized attack validation, the result indicates that safeguards can substantially reduce limits on capability.
However, not being blocked is not the same as succeeding at an attack. This evaluation covers specific attack tasks for Opus 5.5; it does not show Mythos's real-world attack success rate or the probability of preventing every dangerous action. Nor does the figure tell us how often legitimate defensive work is wrongly blocked.
Even with the generally available models, searching one's own source code for vulnerabilities, fixing known issues, and prioritizing security alerts remain possible. CVP participation gives specialists who are stopped by safeguards, for example in malware analysis or vulnerability verification, a way to apply for the scope of work they need.
From finding vulnerabilities to verifying and fixing them
Anthropic reports that Glasswing partners found at least 129,000 verified software vulnerabilities between April and July 2026. In its own scanning of open-source software, the company found another 5,500 between April and October. More than 33,000 of these were rated "critical" or "high" severity.
This tally draws on data from only some participating organizations, including 33 partner reports. Fewer than half of partners disclosed their fix counts, and the company explains that many cases are still being fixed, so the remediation rate is undercounted. It also suggests the real impact is at least five times larger, but this is the company's own estimate. The number of findings alone cannot measure how many fixes have been completed or how much harm has been reduced.
The Comcast and Booz Allen case studies that Anthropic published show the work behind the numbers. In an assessment covering 258 business-critical systems and about 170 million lines of code, Comcast reported finding a serious authentication problem in an externally exposed service. It was less a defect in an individual component than a problem arising from the interaction of multiple systems. Engineers verified it in a running application, traced the cause, and fixed it. No evidence of exploitation before the fix was found, according to the report.
Comcast's Chief Information Security Officer Noopur Davis explains that as large numbers of candidate findings began to appear, verifying them became the new bottleneck. Receiving a candidate report, confirming that the problem is real, and checking whether it can be exploited in the target environment are separate jobs.
In the Booz Allen case, a setting meant to protect the security key used at device startup was left disabled and was passed across two programs written in different languages. A separate downstream protection that pins the key was also not functioning, which led to a problem that could prevent a device from being locked or its data from being wiped. The AI followed a single setting and linked code, permissions, and runtime conditions. According to the company, one analyst examined eight production systems spanning 138 repositories in 12 days. The estimate is that a larger team would previously have needed several months.
In Japan, Hitachi announced on July 28 that it had applied Mythos Preview to more than 100 use cases. It said it cut the creation of a "threat model", which identifies the paths through which threats could enter millions of lines of code, from several weeks to a few hours. It also reported that the AI generated reproduction steps and verification code, easing the verification burden on specialists. Note, however, that this reduction applies to threat model creation and does not mean that fixing and deploying to products is also completed in hours.
The results from each company should be read as cases reported by participants. What Comcast and Booz Allen evaluated was not only the speed of reading large volumes of code but the ability to trace weaknesses across system boundaries. When Glasswing was expanded in June, Anthropic also indicated that it would shift its support emphasis from discovery to verification, disclosure, remediation, and deployment of fixed software. The more organizations that use these tools, the more the process of confirming candidates, handing them to owners, and delivering fixes to the field will be tested.
Wider use comes with authentication and communications controls
Under the new Defense access requirements, multi-factor authentication is required from the start of use. By December 15, 2026, users must also move to phishing-resistant MFA, such as passkeys or security keys supporting FIDO2/WebAuthn. These methods make it harder to hand credentials to a fake login destination. Numeric codes shown by SMS or authenticator apps, and ordinary push approvals, do not meet the requirement.
By the same deadline, long-lived fixed credentials must also be eliminated and replaced with short-lived credentials issued and managed by the platform in use. Targets include Anthropic's fixed API keys and service account keys downloaded from Google Cloud. Amazon Bedrock's short-term API keys are an exception, but their validity may not exceed 12 hours or the session duration, whichever is shorter. During the transition period, Defense API keys must also be managed in a secrets store and rotated at least every 7 days.
Red Team and Specialized require phishing-resistant authentication and short-lived credentials from the start. In environments for attack validation or where the model works autonomously, outbound communication destinations are restricted with an allowlist and communication records are kept. As a rule, that restriction must be enforced outside the host where the work runs. Some exceptions exist for terminals used only for interactive input, on the condition that the environment doing the autonomous work cannot rewrite the allowlist.
In addition, access from organization-managed devices and a setup that can revoke compromised credentials within 24 hours are required. In gaining authority over the model, users also take on responsibility for protecting their accounts and execution environments. Because existing customers keep their current access under the earlier conditions, anyone introducing new permissions should check the requirements that apply to their organization.
Where the data is kept, and who monitors it
CVP generally requires data retention in order to monitor for misuse. For companies handling confidential code, where conversation and activity data is stored becomes an adoption condition alongside performance and eligibility. Under individual Defense, all communications are retained and monitored, and zero data retention is not available.
Enterprise Frontier Safeguards (EFS), which Anthropic announced on September 1, is designed to meet this condition. It lets customers place monitoring activity data in their own cloud environment and manage it with their own encryption keys and access permissions. Signs of misuse spanning multiple sessions or accounts are detected automatically, and human review of detections is handled by the customer. The configuration does not require human review by Anthropic employees.
In other words, zero data retention here does not mean that data is stored nowhere. It is an option in which the customer keeps the logs and continues monitoring for misuse while avoiding retention by the model provider. EFS itself carries no additional fee, but the customer bears storage, read/write, and data transfer costs incurred in its own cloud account.
EFS is scheduled to roll out in stages from later this fall, and has not already been provided to all eligible parties with this CVP expansion. Until then, an interim measure allows organizations that can use Fable 5.1 or Mythos 5.1 with zero data retention to receive the same terms under CVP.
Delivery channels also differ. CVP is available on Claude Platform, Google Cloud's Vertex AI, and Microsoft Foundry, while Amazon Bedrock is limited to EFS-eligible customers. According to the Help Center, Bedrock does not yet support human review of automatically detected safety issues, so it cannot meet the review that CVP generally requires. It also explains that Mythos on external clouds is delayed by about 5 business days from application approval to availability.
What organizations need to decide now is which tier their work requires, and the authentication, communications, and log-management setup to support it. If they have the people and processes to turn large numbers of candidate findings into verified fixes, this expansion of access will be easier to connect to defending systems that are actually running.
