Expanding the Cyber Verification Program

Expanding the Cyber Verification Program

扩展网络验证计划 (Cyber Verification Program)

Oct 6, 2026 2026年10月6日

We’re launching a new, expanded version of our Cyber Verification Program (CVP), which makes advanced cyber capabilities and reduced blocking classifiers available to qualifying security professionals. The program now consists of three access tiers, which allow security teams to apply for the level of access that best suits their work. Each tier includes access to our most capable models, including Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1, and new models moving forward. Interested customers can apply here. 我们正在推出全新升级版的网络验证计划(CVP),旨在为符合条件的网络安全专业人员提供先进的网络能力和降低拦截率的分类器。该计划现包含三个访问层级,允许安全团队申请最适合其工作需求的访问权限。每个层级均包含对我们最强模型的使用权限,包括 Claude Opus 5.5、Claude Sonnet 5.5、Claude Mythos 5.1 以及未来推出的新模型。感兴趣的客户可在此申请。

Cybersecurity is inherently dual use: the same capabilities that enable a security team to find and fix a vulnerability can also help a malicious actor exploit it. For this reason, our generally available models, such as Claude Opus 5.5, Claude Fable 5.1, and Claude Sonnet 5.5, have conservative cyber safeguards that block most cyber work. This is intended to limit the harmful activities malicious actors can carry out using our models, while we continue to work to reduce false positives for secure coding. 网络安全本质上具有双重用途:使安全团队能够发现并修复漏洞的相同能力,也可能帮助恶意行为者利用这些漏洞。因此,我们公开发布的模型(如 Claude Opus 5.5、Claude Fable 5.1 和 Claude Sonnet 5.5)采用了保守的网络安全防护措施,会拦截大多数网络操作。此举旨在限制恶意行为者利用我们的模型进行有害活动,同时我们也在持续努力减少安全编码方面的误报。

But defenders also need access to the best tools and most powerful capabilities to secure their systems. For the past six months, we’ve enabled trusted access through two programs: Project Glasswing and the CVP. The former gave a group of organizations securing the most critical software access to Claude Mythos; the latter gave vetted security teams access to reduced safeguards on Claude Opus and Claude Sonnet models. 但防御者同样需要最好的工具和最强大的能力来保护其系统。在过去的六个月里,我们通过两个项目实现了受信任的访问:Project Glasswing 和 CVP。前者为负责保护最关键软件的一组组织提供了 Claude Mythos 的访问权限;后者则为经过审查的安全团队提供了 Claude Opus 和 Claude Sonnet 模型中降低防护限制的访问权限。

Now, we’re integrating these programs into one expanded offering, designed to give more security organizations access to the capabilities they need to protect their systems. 现在,我们将这些项目整合为一个扩展方案,旨在让更多的安全组织能够获得保护其系统所需的各项能力。

New access tiers

新的访问层级

The updated access tiers make specific model capabilities available to security professionals based on the scope of their cyber work. Each has different verification requirements and security controls. 更新后的访问层级根据安全专业人员的网络工作范围,为其提供特定的模型能力。每个层级都有不同的验证要求和安全控制措施。

Defense Access is for defensive work, including security operations center and incident response tasks, reverse-engineering malware, and analyzing and validating vulnerabilities. Examples of qualifying organizations include security teams at companies, nonprofits, universities, and government bodies who are defending systems they own or maintain; operators of critical infrastructure of any size, such as regional hospitals or municipal utilities; smaller security firms; open-source maintainers; and individual researchers with a track record of reported vulnerabilities. 防御访问 (Defense Access) 适用于防御性工作,包括安全运营中心 (SOC) 和事件响应任务、恶意软件逆向工程,以及漏洞分析与验证。符合条件的组织示例包括:企业、非营利组织、大学和政府机构中负责保护其自有或维护系统的安全团队;各类规模的关键基础设施运营商(如区域医院或市政公用事业机构);小型安全公司;开源维护者;以及有漏洞报告记录的个人研究人员。

We expect many organizations conducting defensive cybersecurity work to qualify for this tier. We aim to respond to applications within a few days. 我们预计许多从事防御性网络安全工作的组织都将符合此层级的资格。我们力求在几天内回复申请。

Red Team Access adds authorized penetration testing and red-teaming to the defensive uses above. Examples of qualifying organizations include in-house red teams, government red teams, and security and penetration testing firms. Organizations in this tier can only perform adversarial testing against systems they are authorized to test, including IT systems in critical industries. Users will still experience real-time blocks on actions that could cause physical harm or mass disruption, such as deploying ransomware, damaging physical systems, or pen testing high-risk safety systems. 红队访问 (Red Team Access) 在上述防御用途的基础上,增加了授权的渗透测试和红队演练。符合条件的组织示例包括:内部红队、政府红队以及安全与渗透测试公司。此层级的组织仅能针对其获得授权的系统进行对抗性测试,包括关键行业的 IT 系统。对于可能导致人身伤害或大规模破坏的操作(如部署勒索软件、破坏物理系统或对高风险安全系统进行渗透测试),用户仍会遇到实时拦截。

Given the increased eligibility requirements and security controls, we expect applications in this tier to take a few weeks to review. Qualifying organizations will be enrolled in the Defense Access tier while we review their Red Team Access applications. Currently, this tier is for organizations only; individual researchers are not eligible. 鉴于更高的资格要求和安全控制,我们预计此层级的申请审核需要几周时间。在审核红队访问申请期间,符合条件的组织将被纳入防御访问层级。目前,此层级仅面向组织开放;个人研究人员暂不具备资格。

Specialized Access, which has the fewest cyber blocks, is reserved for a limited set of verified organizations that are authorized to test safety systems that could impact people’s lives or disrupt markets, such as flight operating systems, power grids, telecom networks, interbank transfer infrastructure, and government administrative networks. 专业访问 (Specialized Access) 拥有最少的网络拦截限制,仅预留给少数经过验证的组织。这些组织必须获得授权,能够测试可能影响人们生活或扰乱市场的安全系统,例如飞行操作系统、电网、电信网络、银行间转账基础设施和政府行政网络。

For this tier, we currently review every organization in depth in collaboration with the US government. Existing members of Project Glasswing will transition to this tier and do not require reapproval for current models. 对于此层级,我们目前正与美国政府合作,对每个组织进行深入审查。Project Glasswing 的现有成员将过渡到此层级,无需针对当前模型重新申请批准。

Our generally available models can continue to be used for tasks such as code review, patching known issues, vulnerability finding in owned source code, and triage of security alerts. 我们的公开发布模型可继续用于代码审查、修补已知问题、自有源代码中的漏洞查找以及安全警报分类等任务。

Data retention is required for organizations enrolled in the program so that we can monitor for cyber misuse. Once Enterprise Frontier Safeguards (EFS)—a new solution that combines the privacy of zero data retention with robust safeguards—is available later this fall, eligible organizations will be able to store data in cloud infrastructure they control. Until EFS is available, organizations with access to Claude Fable 5.1 or Claude Mythos 5.1 with zero data retention can also use CVP with zero data retention. To register interest in EFS, fill out this form. 加入该计划的组织必须保留数据,以便我们监控是否存在网络滥用行为。今年秋季晚些时候,我们将推出“企业前沿防护”(EFS)——这是一种结合了零数据保留隐私性和强大防护功能的新解决方案。届时,符合条件的组织将能够在其控制的云基础设施中存储数据。在 EFS 可用之前,拥有 Claude Fable 5.1 或 Claude Mythos 5.1 零数据保留访问权限的组织,也可以在零数据保留的情况下使用 CVP。如需登记对 EFS 的兴趣,请填写此表格。

Below, we share an overview of what’s available at each CVP access level, as well as requirements for security and privacy controls: 以下是我们分享的各 CVP 访问层级的功能概览,以及安全和隐私控制的要求:

Overview of the Cyber Verification Program tiers. 网络验证计划层级概览。

Testing the efficacy of our tiers

测试层级的有效性

To assess the efficacy of our CVP protections, we ran Claude Opus 5.5 through CyScenarioBench—an evaluation that measures whether models can plan and execute multi-stage cyber operations under realistic constraints—with safeguards tuned for our different CVP tiers. Because this evaluation involves complex, interactive, offensive scenarios, we would expect Claude to experience significant blocks both on the generally available model and in the Defense Access tier, while experiencing no blocks in the Red Team Access and Specialized Access tiers. 为了评估 CVP 防护措施的有效性,我们使用 CyScenarioBench 对 Claude Opus 5.5 进行了测试。该评估旨在衡量模型在现实约束下规划和执行多阶段网络操作的能力,并针对我们不同的 CVP 层级调整了防护措施。由于该评估涉及复杂的交互式攻击场景,我们预计 Claude 在公开发布模型和防御访问层级中会遇到显著拦截,而在红队访问和专业访问层级中则不会遇到拦截。

Across five attempts at each of the 10 CyScenarioBench challenges in each access tier, we found that: 在每个访问层级的 10 项 CyScenarioBench 挑战中,经过五次尝试,我们发现:

  • Without CVP access, every task was blocked on the first prompt; 在没有 CVP 访问权限的情况下,每项任务在第一个提示词时即被拦截;
  • In the Defense Access tier, 46 of the 50 trials were blocked at some point in the challenge, while the remaining four tasks succeeded; and 在防御访问层级中,50 次试验中有 46 次在挑战过程中的某个环节被拦截,其余 4 项任务成功完成;以及
  • In the Red Team Access tier, no blocks occurred, and Claude Opus… 在红队访问层级中,未发生任何拦截,且 Claude Opus…