GPU families with current, documented confidential-computing support

As of 22 August 2026, the operationally supported scope is NVIDIA-only and SKU-specific. These pages separate hardware capability, vendor-supported confidential mode, and an actual cloud product. A100, GH200/GB200/GB300, AMD Instinct, Intel Gaudi, and announced Rubin are excluded until a current model-specific production matrix supports them.

NVIDIA Hopper

The deploy-now generation. Hopper single-GPU support is broad across named SKUs; protected multi-GPU mode is limited and peer NVLink traffic is not encrypted.

  1. NVIDIA H100 confidential computing: supported SKUs, modes, and availability

    Verified H100 confidential-computing support across PCIe, NVL, and HGX variants, with Azure and Google Cloud availability and deployment constraints.

    Open
  2. NVIDIA H200 confidential computing: NVL and HGX support

    Verified confidential-computing support for H200 NVL and HGX H200, including multi-GPU constraints, customer fit, and cloud-availability limits.

    Open
  3. NVIDIA H800, H20, and H20A confidential-computing support

    The verified model-by-model confidential-computing scope for regional NVIDIA Hopper H800, H20, and H20A products.

    Open

NVIDIA Blackwell

Named B200, B300, and RTX PRO 6000 Server Edition systems. B200/B300 add supported encrypted peer traffic for up to eight GPUs; RTX PRO 6000 is single-GPU only.

  1. NVIDIA B200 confidential computing: HGX support and multi-GPU mode

    Verified HGX B200 and B200-850 confidential-computing support, Blackwell multi-GPU protections, constraints, and deployment availability.

    Open
  2. NVIDIA B300 confidential computing: supported systems and buyer checks

    Verified HGX B300 confidential-computing support, up-to-eight-GPU Blackwell mode, performance evidence, and deployment caveats.

    Open
  3. RTX PRO 6000 Blackwell confidential computing: Server Edition scope

    Verified confidential-computing support for RTX PRO 6000 Blackwell Server Edition, including Google Cloud G4 availability and limitations.

    Open

Selection and deployment

Start with the trust model and exact compatibility row, then measure the workload on the full CPU, GPU, firmware, driver, and attestation stack.

  1. Confidential GPU infrastructure buyer guide

    Architecture, workload fit, performance constraints, and the evidence to request.

    Open
  2. Find confidential compute capacity

    Translate model, topology, region, term, and security requirements into a capacity request.

    Open