Anthropic has expanded its Cyber Verification Program (CVP), giving verified security professionals a three-tier route to use Claude Opus 5.5, Claude Sonnet 5.5, and Claude Mythos 5.1 for defensive security work. The change broadens the program beyond its earlier single-level access approach for Opus and Sonnet, while retaining controls intended to govern cyber-related use.
For businesses assessing AI for security operations, the important development is not unrestricted model access. It is a more formal way to obtain and manage access to Anthropic's cyber-capable models through organization verification, security-control attestations, tier-specific rules, and a dedicated Verification Portal. Anthropic describes the program and its safeguards in its official Cyber Verification Program guidance.
What Anthropic's expanded CVP changes
The updated CVP is structured around three access tiers and explicitly includes Opus 5.5, Sonnet 5.5, and Mythos 5.1. Anthropic says the tiered framework is designed to accommodate multiple cyber-capable models as the program develops, rather than treating access as a single, fixed entitlement.
The verified materials establish several practical components of the program:
- Organizations must complete verification through the CVP Verification Portal.
- Participants attest to relevant security controls and agree to tier-specific usage requirements.
- The program supports access across cloud environments.
- Enterprise safeguards and data-retention controls remain part of the offering, including zero data retention options in some configurations.
- Existing CVP participants have a path to transition into the updated program.
That structure matters because it makes eligibility, access, and guardrails part of the same process. A company cannot infer its available tier, model limits, or configuration simply from the public model list. Those details depend on its CVP administration view and the applicable platform or regional conditions.
Previous scope and updated program
| Program element | Earlier CVP scope | Expanded CVP scope |
|---|---|---|
| Access structure | Single access level for Opus and Sonnet | Three-tier access model |
| Models explicitly included | Opus and Sonnet | Claude Opus 5.5, Claude Sonnet 5.5, and Claude Mythos 5.1 |
| Enrollment approach | CVP participation | Verification Portal, organization verification, and control attestations |
| Program direction | Single-level access model | Tiered framework intended to support future cyber-capable models |
Why the safeguards are central to the announcement
Cyber-capable AI can be valuable for defenders, but the same general class of capability requires careful controls. Anthropic's expansion is therefore defined as much by its verification and policy framework as by the inclusion of new models. The program is aimed at defensive security work, with safeguards and usage rules that vary by tier.
For a buyer, this means CVP should be evaluated as a controlled access program, not as a standard software subscription. Security teams need to establish who will use the models, what defensive workflows they will support, which data can be supplied to them, and how the organization's chosen cloud configuration handles retention.
The availability of zero data retention in some configurations may be relevant for organizations that need stronger handling rules for security information. However, this is not a universal program setting. Teams should confirm the option for their specific environment before designing a workflow around it.
What businesses can realistically take from the expansion
The broader model coverage could help eligible security teams explore AI assistance in defensive processes without building their own model infrastructure. In practical terms, that may include incorporating approved AI tools into existing investigation, analysis, or security documentation workflows, subject to the organization's controls and the program's permitted use.
The operational opportunity is paired with implementation work. An AI-assisted security process still needs defined inputs, human review, escalation paths, and clear boundaries for sensitive information. CVP enrollment establishes a route to the models, but it does not itself determine whether a team's workflow is useful, secure, or appropriate for its environment.
Businesses considering the program should focus on four questions:
- Is the organization eligible and able to complete the required verification and control attestations?
- Which CVP tier and models are shown in its own administrative view?
- Are the required models and retention options available in its intended cloud or region?
- Which narrowly defined defensive workflow can be tested with meaningful human oversight?
Some details remain dependent on Anthropic's continuing program updates. Public materials do not provide a universal set of tier names or limits for every organization, and regional or platform-specific restrictions may apply. Anthropic also indicates that model availability and tier capabilities will evolve, so prospective participants should treat the portal and current documentation as the operational reference point.
Security teams do not need to turn an expanded AI access program into an unstructured experiment. Scalevise can help assess suitable defensive AI use cases, define data and review boundaries, and plan an implementation that fits existing processes. A focused AI consultancy engagement can clarify whether CVP-enabled workflows can save analyst time without creating avoidable operational risk. Request an AI consultation to map a practical security workflow.
Frequently Asked Questions
What is Anthropic's Cyber Verification Program?
Anthropic's Cyber Verification Program is a controlled access program for verified security professionals using certain Claude models for defensive security work. It includes organization verification, security-control attestations, and tier-specific usage rules.
Which Claude models are included in the expanded CVP?
The expanded program explicitly includes Claude Opus 5.5, Claude Sonnet 5.5, and Claude Mythos 5.1 across its three-tier access model.
Does every CVP participant receive the same model access and limits?
No. The program uses tiers, and the exact tier names, limits, and available models should be confirmed in an organization's CVP administrative view and applicable platform configuration.
Does CVP offer zero data retention?
Anthropic indicates that zero data retention is available in some configurations. Organizations should confirm whether that option applies to their intended cloud environment and program setup.
Conclusion
Anthropic's expanded Cyber Verification Program creates a more structured path for verified security professionals to access Claude Opus 5.5, Sonnet 5.5, and Mythos 5.1 for defensive work. Its significance lies in the combination of broader model coverage and continuing verification, usage, and data-handling safeguards. Organizations considering CVP should validate their specific tier, configuration, and permitted workflow before moving from evaluation to operational use.
Top comments (0)