What happened
On Oct 6, Anthropic restructured its Cyber Verification Program into three tiers — Defense, Red Team, and Specialized Access — giving vetted security teams reduced-blocking access to Claude Opus 5.5, Sonnet 5.5, Mythos 5.1 and future models. Defense/RTT tiers are in-scope for SOC/IR/malware-reversing and authorized pentesting respectively; Specialized Access (ex-Glasswing) allows testing of life/safety-critical systems with US-government collaboration and data-retention monitoring. Upcoming Enterprise Frontier Safeguards (EFS) will allow zero-data-retention capability into customer-controlled cloud infra.
Why it matters
This is the mainstreaming of safe weak-safeguard model access: previously restricted to a handful of Glasswing orgs, expanded CVP now lets SOC teams, critical-infrastructure operators, universities and open-source maintainers run frontier models on defensive and authorized offensive work — validated on CyScenarioBench (Defense tier blocks 46/50 attempts; Red Team tier 0 blocks, 34/50 completions).
Applicability
Defensive SOC/incident-response teams and authorized red teams should apply to the Defense/Red Team tiers now (Defense response in days, Red Team weeks); plan for EFS when it ships later this fall if data-retention privacy is a blocker.