Skip to content

Build5 publishersWidely confirmed3 min readPublished

Anthropic puts Opus 5.5, Sonnet 5.5 and Mythos 5.1 behind three tiers of cyber verification

Anthropic's Cyber Verification Program now gives security teams three tiers of access to Claude Opus 5.5, Sonnet 5.5 and Mythos 5.1 for defensive work. Getting in takes organization verification and control attestations, and a team learns its tier only from its own admin view.

The Engineer · Build desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying Anthropic puts Opus 5.5, Sonnet 5.5 and Mythos 5.1 behind three tiers of cyber verification
Generated illustration

What happened

  • Participating organizations attest to their own security controls and agree to usage requirements that differ by tier.
  • Access works across cloud environments, with zero data retention offered only in some configurations.
  • Organizations already enrolled in the program have a path to transition into the tiered version.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • decision Pilot timelines for cyber use of Claude now start with organization verification and control attestations, so security leaders have to schedule that work before any model testing.
  • constraint A team cannot design a workflow around Mythos 5.1 or zero data retention until its admin view and its chosen cloud confirm both.
  • precedent Anthropic built the tiers to absorb more cyber-capable models, so later releases are likely to reach security teams through the same verification gate.
  • cost Enrollment leaves the security team to pay for its own workflow design: defined inputs, human review, escalation paths and limits on sensitive data.

The thing that gets verified is the organization. It completes verification through a dedicated CVP Verification Portal [3]. It then attests to its relevant security controls and agrees to usage requirements that differ by tier [4]. According to a dev.to write-up of Anthropic's program guidance, the program is aimed at defensive security work, and its safeguards and usage rules change from tier to tier [13].

The design follows from dual use. The same general class of capability that helps defenders needs careful controls, the write-up notes [16], and the tiered structure puts eligibility, access and guardrails into one process [18]. I think that is the right call for a vendor shipping this kind of model, because the check attaches to who is asking and what they have attested. Anthropic says the framework is built to take on more cyber-capable models as the program develops, so access is no longer one fixed entitlement [8]. The old arrangement was a single access level for Opus and Sonnet [2]. Existing participants have a path into the new structure [7].

Planning breaks at the next step. A company cannot work out its tier, its model limits or its configuration from the public model list; those come from its own CVP administration view and from platform or regional conditions, according to the write-up [9]. Public materials do not include a universal set of tier names or limits, and regional or platform restrictions may apply [10]. A security lead therefore cannot know, before enrolling, whether the attestations it is able to make reach Mythos 5.1 or stop at a lower tier [10]. Anthropic also indicates that model availability and tier capabilities will change over time [11].

Retention needs the same care. The program supports access across cloud environments [5], and zero data retention is available in some configurations [6]. The write-up says zero retention is not a universal program setting and should be confirmed for a specific environment before a workflow is designed around it [12]. For a team feeding security information into a model, the chosen cloud configuration determines how that data is retained [12].

For once, the hard part of adopting a model is the paperwork before the first prompt. The write-up says CVP should be judged as a controlled access program, not as a standard software subscription [14]. It lists four questions for buyers, and each depends on the answer before it [17]:

1. Can the organization complete the required verification and control attestations? 2. Which tier and models appear in its own administrative view? 3. Are those models, and the retention options it needs, available in its intended cloud or region? 4. Which narrowly defined defensive workflow can be tested with meaningful human oversight?

Enrollment gives a route to the models. Whether a given workflow is useful, secure or appropriate for its environment is left to the team [15]. That team still has to define inputs, human review, escalation paths and limits on sensitive information, according to the write-up [15].

What to watch

  • Anthropic publishing tier names, limits or entry criteria, especially which tier unlocks Mythos 5.1.
  • Confirmation of which cloud platforms and regions offer zero data retention for CVP models.
  • How existing CVP participants are placed into tiers when they transition.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories