On 2026-10-06 Anthropic merged Project Glasswing and the original Cyber Verification Program into one three-tier program: Defense Access (SOC, incident response, malware reversing, vuln validation), Red Team Access (authorized pentesting) and Specialized Access (safety-critical systems such as power grids, flight systems and telecom, vetted with the US government). All tiers get Claude Opus 5.5, Sonnet 5.5 and Mythos 5.1 with reduced cyber blocking. On CyScenarioBench, GA models were blocked on the first prompt of every task, Defense tier blocked 46/50 trials, and Red Team tier had zero blocks and completed 34/50 (matching the 67.6% no-safeguard rate). Glasswing partners reported at least 129,000 verified vulnerabilities from April to July 2026.

Key Takeaways

  • ✓3 tiers: Defense (decisions in days), Red Team (weeks, organizations only), Specialized (in-depth review with the US government); Glasswing members move to Specialized automatically (announcement)
  • ✓3 models in every tier: Claude Opus 5.5, Sonnet 5.5 and Mythos 5.1, plus future models
  • ✓CyScenarioBench (10 tasks x 5 attempts): GA blocked on first prompt; Defense tier blocked 46/50; Red Team tier 0 blocks and 34/50 completed, matching the 67.6% no-safeguard rate
  • ✓Impact: at least 129,000 verified vulns found by Glasswing partners (Apr-Jul 2026) plus 5,500 from Anthropic's own OSS scanning (Apr-Oct), over 33,000 rated critical/high (Project Glasswing)
  • ✓Available on Claude Platform, Vertex AI and Microsoft Foundry; Bedrock only for Enterprise Frontier Safeguards customers; data retention required
Anthropic expands its Cyber Verification Program into three access tiers with Opus 5.5, Sonnet 5.5 and Mythos 5.1; Red Team tier completes 34/50 CyScenarioBench tasks with zero blocks
🖼️Official Media
Click to view high-res
🧭

Turn your technical choice into a development budget

Compare 40 dev plans & simulate token costs vs $20/mo subscriptions

🔬

In-Depth Technical Analysis

Anthropic's 2026-10-06 post folds Project Glasswing (Mythos access for organizations securing critical software) and the original Cyber Verification Program (reduced safeguards on Opus/Sonnet) into one program with three tiers. Defense Access covers SOC work, incident response, malware reverse engineering and vulnerability validation, and is open to company/nonprofit/university/government security teams, critical-infrastructure operators of any size, small security firms, open-source maintainers and individual researchers with a disclosure track record; Anthropic aims to answer in days. Red Team Access adds authorized penetration testing for organizations only (weeks to review), while still blocking actions like ransomware deployment or damaging physical systems. Specialized Access, with the fewest blocks, is for verified organizations testing safety-critical systems such as power grids, flight systems, telecom and interbank transfer networks, reviewed in collaboration with the US government; Glasswing members transfer automatically. Every tier includes Claude Opus 5.5, Sonnet 5.5 and Mythos 5.1. Data retention is required until Enterprise Frontier Safeguards ships later this fall. On CyScenarioBench (10 challenges x 5 attempts), GA models were blocked on the first prompt every time, Defense tier blocked 46 of 50 trials, and Red Team tier had zero blocks and completed 34 of 50, equivalent to the 67.6% no-safeguard success rate. Anthropic also reports Glasswing partners found at least 129,000 verified vulnerabilities between April and July 2026, plus 5,500 from its own open-source scanning, with more than 33,000 rated critical or high. CVP is available on Claude Platform, Vertex AI and Microsoft Foundry; Bedrock only for EFS-eligible customers.

Action HubReady to adopt this in production?

Benchmark side-by-side against alternatives, or calculate monthly token cost vs subscription break-even.