The Tiered Access Model: What Changes at Each Level
Anthropic's Cyber Verification Program (CVP) now sorts applicants into three tiers, each unlocking a different degree of freedom from the company's default safety restrictions. Defense Access, the entry tier, is open to corporate security teams, nonprofits, universities, government bodies, critical infrastructure operators, small security firms, open-source maintainers, and even individual researchers who can point to a track record of vulnerability disclosures; it covers SOC and incident-response work, malware reverse-engineering, and vulnerability analysis, with review taking 'a few days.'[1]Red Team Access goes further, adding authorized penetration testing and red-teaming, but it is restricted to organizations rather than individuals and takes a few weeks to clear - real-time blocks still trigger for anything resembling physical harm, mass disruption, ransomware deployment, or attacks on high-risk safety systems.[1]The top tier, Specialized Access, is reserved for organizations cleared to test safety-critical infrastructure - flight systems, power grids, telecom networks, interbank transfer rails, and government networks - vetted in direct collaboration with the U.S. government; existing Project Glasswing members, the coalition Anthropic quietly built with partners including AWS, Cisco, JPMorganChase, Microsoft, and Nvidia, transition into this tier automatically.[1]All three tiers currently include Claude Opus 5.5, Claude Sonnet 5.5, and Claude Mythos 5.1, with more models promised over time.[1]



