Analysis
MCP Security, Version 2.0: From Threat Taxonomy to a Model You Can Actually Audit Against
First reported · Discovered coalitionforsecureai.org
Page published
Earliest dated coverage: 25 Sep 2026 · First observed: 8 Oct 2026 · Latest dated coverage: 25 Sep 2026
Coverage timeline
Single-source analysis — one report is available.
Why it matters
The CoSAI MCP Security assurance model gives defenders an auditable, proportionality-based framework for securing agentic MCP deployments against delegation, identity, and tool-abuse threats as the protocol rapidly changes.
The Coalition for Secure AI published version 2.0 of its Model Context Protocol (MCP) Security paper (August 12, 2026), evolving from a threat taxonomy of twelve categories and thirty-four threats into a set of four Security Assurance Profiles (Sandbox, Internal, Production, Regulated) with concrete MUST/SHOULD requirements across eight security dimensions. The update reflects the 2026-07-28 MCP release (which removed protocol-level sessions) and cross-references the OWASP MCP Top 10, with each control traced back to the threats it mitigates, including hard requirements like token binding at Level 3.