NVIDIA B200 confidential computing: HGX support and multi-GPU mode

B200 adds NVIDIA’s Blackwell multi-GPU confidential mode with protected peer traffic, but no named cloud CC product is yet documented.

Abstract botanical artwork combining painted flowers with fine technical linework.

Direct answer

NVIDIA currently supports confidential computing on named HGX B200 180 GB air- and liquid-cooled systems and HGX B200-850 air-cooled systems. Blackwell multi-GPU passthrough supports up to eight GPUs and encrypts NVLink peer traffic, but production use still requires an exact compatible host, firmware, driver, topology, and attestation policy.

Verified B200 systems

SystemMatrix statusMode
HGX B200 180 GB air-cooledNamed supported rowSingle- and multi-GPU passthrough
HGX B200 180 GB liquid-cooledNamed supported rowSingle- and multi-GPU passthrough
HGX B200-850 air-cooledNamed supported rowSingle- and multi-GPU passthrough
Generic B200 listingInsufficient evidenceMust match an exact supported system/firmware row
R595MATRIX

Blackwell multi-GPU confidential mode

NVIDIA’s Blackwell multi-GPU passthrough architecture supports up to eight GPUs assigned to one confidential VM. Unlike Hopper Protected PCIe, the Blackwell design encrypts peer traffic over NVLink, closing an important link-level gap for sharded training and inference. Composite CPU/GPU attestation and the exact topology remain essential.R595DEPLOY

Security properties and limits

  • Hardware-rooted GPU identity, measured/signed firmware, device access controls, CPU/GPU composite attestation, and protected transport support the combined TEE.
  • CC-On plus a successful verifier decision is required before releasing model, data, or session keys.
  • Blackwell confidential multi-GPU mode protects NVLink peer traffic; verify the exact supported switch/topology row.
  • Denial of service, workload vulnerabilities, unsafe output, observability leakage, and every advanced physical/side-channel attack remain outside automatic protection.
  • CC-DevTools is a development state and should be rejected by production attestation policy.
DEPLOYR595

Workload fit and constraints

B200 is aimed at high-scale proprietary training, long-context or large-model inference, sensitive multimodal workloads, and distributed jobs that need protected peer links. It is not automatically the economical choice for smaller inference that fits an H100, H200, or RTX PRO 6000. Price delivered secure throughput and account for cluster availability, power, cooling, and recovery operations.

  • Passthrough is required; current NVIDIA Confidential Containers exclude MIG and vGPU.
  • All multi-GPU devices are assigned to one confidential VM; mixed CC and non-CC devices are unsupported.
  • Pinned host-memory restrictions can require software changes and affect transfer performance.
  • Collect and verify evidence for the entire device set and fail admission if membership or versions drift.
  • Benchmark model load, collectives, host/device transfers, steady-state compute, restart, and re-attestation.
PLATFORMSR595

Deployment availability

NVIDIA’s documentation establishes vendor support for qualifying HGX B200 systems. Cloud documentation does not expose a named generally available B200 instance with confidential mode enabled. Ask an on-premises or partner supplier for the precise supported system row, attestation evidence, RIM/firmware versions, and customer-verifiable key-release design.

Frequently asked questions

Does B200 support confidential multi-GPU workloads?

Yes, on named HGX B200 systems. NVIDIA documents Blackwell multi-GPU passthrough for up to eight GPUs assigned to one confidential VM.

Does B200 encrypt NVLink traffic?

NVIDIA’s current Blackwell confidential multi-GPU architecture protects peer traffic over NVLink, unlike Hopper Protected PCIe mode.

Which public cloud offers B200 confidential instances?

Official provider documentation does not identify a generally available B200 confidential-computing SKU as of 22 August 2026.

Sources

  1. R595
  2. MATRIX
  3. PLATFORMS
  4. DEPLOY