Analysis

MCP Security, Version 2.0: From Threat Taxonomy to a Model You Can Actually Audit Against

Page published

Earliest dated coverage: 25 Sep 2026 · First observed: 8 Oct 2026 · Latest dated coverage: 25 Sep 2026

Coverage timeline

25 Sep 2026coalitionforsecureai.org

Single-source analysis — one report is available.

Why it matters

The CoSAI MCP Security assurance model gives defenders an auditable, proportionality-based framework for securing agentic MCP deployments against delegation, identity, and tool-abuse threats as the protocol rapidly changes.

The Coalition for Secure AI published version 2.0 of its Model Context Protocol (MCP) Security paper (August 12, 2026), evolving from a threat taxonomy of twelve categories and thirty-four threats into a set of four Security Assurance Profiles (Sandbox, Internal, Production, Regulated) with concrete MUST/SHOULD requirements across eight security dimensions. The update reflects the 2026-07-28 MCP release (which removed protocol-level sessions) and cross-references the OWASP MCP Top 10, with each control traced back to the threats it mitigates, including hard requirements like token binding at Level 3.