Article

Anthropic’s Cyber Verification Program: Choose a Tier and Check Retention

Compare Anthropic’s expanded CVP tiers, security requirements, cloud access and retention rules before applying for Claude cyber capabilities.

Editorial illustration for Anthropic’s Cyber Verification Program: Choose a Tier and Check Retention: a document and lock represent artifact protection. Not documentary evidence.

On October 6, 2026, Anthropic expanded its Cyber Verification Program (CVP) for verified security professionals. It brings reduced cyber blocking and access to Claude Opus 5.5, Sonnet 5.5 and Mythos 5.1 under one program, combining earlier CVP access with Project Glasswing.

The three tiers—Defense, Red Team and Specialized—match different security tasks and carry different operating requirements. For buyers, the immediate decision is whether the work, identities, cloud route and data handling qualify—not simply which model to select.

Choose by the work, not the organization’s industry

Routine code review, patching and vulnerability discovery in your own source code remain supported without CVP. The program FAQ directs professionals toward verification when safeguards interrupt other legitimate security work.

The announcement’s tier definitions distinguish the following scopes:

Tier

Work it covers

Admission boundary

Defense

Incident response, malware analysis and vulnerability validation.

Verified defensive work.

Red Team

Defense plus authorized penetration testing and red-teaming.

Organizations only; target authorization still matters.

Specialized

Authorized testing of high-risk safety systems.

Limited organizations, reviewed with the US government.

Red Team still blocks ransomware, physical damage and high-risk safety-system testing. Working in a critical industry does not automatically make ordinary IT testing Specialized work.

Our recommendation: describe the exact systems and actions in the application. Ask Anthropic to resolve borderline scope; do not treat a broader tier as a substitute for the system owner’s authorization.

Check authentication readiness before applying

These are selected requirements from Anthropic’s security-control specification, not a complete compliance checklist:

  • Defense: MFA is required immediately. By December 15, 2026, use phishing-resistant MFA and stop using long-lived static credentials. Interim keys need secure storage, individual person/workload assignment and replacement at least weekly.

  • Red Team: Phishing-resistant MFA and short-lived credentials apply immediately. Organization identities, managed devices, screened users and logged, externally enforced egress allowlists for offensive or agentic work are required.

  • Specialized: Adds federated organizational SSO and enforced application controls or preventive endpoint protection.

  • People and response: Red Team and Specialized default to 25 approved people per workspace; workload identities do not count. Customer-issued credentials expire within 12 hours, compromised access must be revocable within 24 hours, and offboarding is due within three business days.

All tiers carry incident-reporting and cooperation obligations. Read the full specification with the security owner, including its platform-specific credential rules.

For first-party API workloads, Workload Identity Federation exchanges an identity-provider token for a short-lived Anthropic token tied to a service account and workspace. Inventory each caller and its workspace before migrating. Federation does not establish that the upstream identity or workspace membership is appropriately scoped.

Resolve retention before sending investigation material

Organizational CVP normally requires retention. Existing Fable/Mythos retention exemptions can temporarily extend to CVP; an ordinary ZDR agreement is not enough to establish eligibility. See the current program terms. Individual Defense grants retain and monitor traffic and do not support ZDR.

Anthropic’s workspace-retention documentation describes enabling 30-day retention for covered models in a specific Console workspace. Turning it off removes a retention-dependent program; a workspace using customer-managed encryption keys cannot switch retention off. Treat that setting as a substantive data-handling choice, not a troubleshooting shortcut.

Enterprise Frontier Safeguards (EFS), announced September 1, is still described as a phased rollout planned for later this fall. Its design places monitoring data in customer-controlled cloud storage, offers customer-managed keys and sends automated flags to the customer’s reviewers. It changes custody and review responsibility; it does not eliminate monitoring.

Anthropic says EFS has no separate charge, but customers pay their cloud storage, operations and egress costs. Confirm account eligibility and availability before making EFS a deployment dependency.

For a proposed pilot, list the source code, incident logs and investigation artifacts that would leave your environment, their destinations and who may review them. RohitAI’s guide to mapping agent data flows explains this review separately from vendor enrollment.

Check the cloud route and the actual grant

The launch lists Claude Platform, Google Cloud’s Vertex AI and Microsoft Foundry. Bedrock is conditional, not a general-access alternative.

The FAQ’s Bedrock explanation currently restricts CVP to organizations with the applicable Fable 5.1 retention exemption, pending EFS. Third-party-cloud Mythos provisioning can trail approval by about five business days. Foundry requires a Claude deployment before enrollment; cloud accounts must be linked.

In Console, program access depends on the qualifying workspace. Some grants apply automatically when requirements are met; others need explicit assignment. An Admin or Owner should inspect Programs, workspace status and Qualifications, then confirm that API calls use that workspace. Some programs cannot use the default workspace. Follow the actual grant’s instructions rather than assuming that organization approval enables every caller.

Client-facing products follow a separate Cyber Productization Policy; the FAQ does not make internal enrollment a resale entitlement. Participating third-party apps support Defense and Red Team, not Specialized.

Budget for the model separately from the tier

The published base API prices are $2 input/$10 output for Sonnet 5.5, $4/$20 for Opus 5.5 and $10/$50 for Mythos 5.1, per million tokens in USD.

Illustrative calculation: 1 million uncached input tokens plus 100,000 output tokens costs $3, $6 or $15 respectively. The formula is input price + 0.1 × output price.

This assumes identical billable token counts at ordinary base rates. It excludes caching, discounts, cloud-route differences, tools, retries, storage and human review. It is not a cost-per-investigation estimate or evidence that the more expensive model performs better.

What to prepare next

Individuals can apply for Defense on a paid plan; higher tiers require organizations. Apply once per organization through the verification portal. The FAQ targets a decision or information request within seven business days—not guaranteed final approval. Existing members need not reapply for the expanded program.

Our suggested readiness packet separates four decisions:

  1. Work scope: Identify the task, target systems and the owner who authorized it. Explain why ordinary access is insufficient.

  2. Access controls: Name the users and workloads, their authentication route, and who can suspend access. Resolve control gaps before relying on enrollment.

  3. Data handling: Record what material may be submitted and which retention arrangement is actually approved for the destination.

  4. Provisioning and evaluation: Confirm the grant, workspace and model availability. Propose a limited evaluation using authorized fixtures, recording classifier interruptions, task completion and human validation separately.

A successful application is one milestone. Do not commit to a production workflow until the grant is usable and its data-handling conditions fit the actual investigation.

Methodology: This AI-assisted decision guide uses Anthropic’s announcement and official documentation checked on October 6, 2026. The readiness framework and token calculation are analysis, not measured deployment results. No hands-on testing was performed.