NVIDIA B200 confidential computing: HGX support and multi-GPU mode
B200 adds NVIDIA’s Blackwell multi-GPU confidential mode with protected peer traffic, but no named cloud CC product is yet documented.

Direct answer
NVIDIA currently supports confidential computing on named HGX B200 180 GB air- and liquid-cooled systems and HGX B200-850 air-cooled systems. Blackwell multi-GPU passthrough supports up to eight GPUs and encrypts NVLink peer traffic, but production use still requires an exact compatible host, firmware, driver, topology, and attestation policy.Verified B200 systems
| System | Matrix status | Mode |
|---|---|---|
| HGX B200 180 GB air-cooled | Named supported row | Single- and multi-GPU passthrough |
| HGX B200 180 GB liquid-cooled | Named supported row | Single- and multi-GPU passthrough |
| HGX B200-850 air-cooled | Named supported row | Single- and multi-GPU passthrough |
| Generic B200 listing | Insufficient evidence | Must match an exact supported system/firmware row |
Blackwell multi-GPU confidential mode
NVIDIA’s Blackwell multi-GPU passthrough architecture supports up to eight GPUs assigned to one confidential VM. Unlike Hopper Protected PCIe, the Blackwell design encrypts peer traffic over NVLink, closing an important link-level gap for sharded training and inference. Composite CPU/GPU attestation and the exact topology remain essential.R595DEPLOY
Security properties and limits
- Hardware-rooted GPU identity, measured/signed firmware, device access controls, CPU/GPU composite attestation, and protected transport support the combined TEE.
- CC-On plus a successful verifier decision is required before releasing model, data, or session keys.
- Blackwell confidential multi-GPU mode protects NVLink peer traffic; verify the exact supported switch/topology row.
- Denial of service, workload vulnerabilities, unsafe output, observability leakage, and every advanced physical/side-channel attack remain outside automatic protection.
- CC-DevTools is a development state and should be rejected by production attestation policy.
Workload fit and constraints
B200 is aimed at high-scale proprietary training, long-context or large-model inference, sensitive multimodal workloads, and distributed jobs that need protected peer links. It is not automatically the economical choice for smaller inference that fits an H100, H200, or RTX PRO 6000. Price delivered secure throughput and account for cluster availability, power, cooling, and recovery operations.
- Passthrough is required; current NVIDIA Confidential Containers exclude MIG and vGPU.
- All multi-GPU devices are assigned to one confidential VM; mixed CC and non-CC devices are unsupported.
- Pinned host-memory restrictions can require software changes and affect transfer performance.
- Collect and verify evidence for the entire device set and fail admission if membership or versions drift.
- Benchmark model load, collectives, host/device transfers, steady-state compute, restart, and re-attestation.
Deployment availability
NVIDIA’s documentation establishes vendor support for qualifying HGX B200 systems. Cloud documentation does not expose a named generally available B200 instance with confidential mode enabled. Ask an on-premises or partner supplier for the precise supported system row, attestation evidence, RIM/firmware versions, and customer-verifiable key-release design.
Frequently asked questions
Does B200 support confidential multi-GPU workloads?
Yes, on named HGX B200 systems. NVIDIA documents Blackwell multi-GPU passthrough for up to eight GPUs assigned to one confidential VM.
Does B200 encrypt NVLink traffic?
NVIDIA’s current Blackwell confidential multi-GPU architecture protects peer traffic over NVLink, unlike Hopper Protected PCIe mode.
Which public cloud offers B200 confidential instances?
Official provider documentation does not identify a generally available B200 confidential-computing SKU as of 22 August 2026.
Sources
- R595
- MATRIX
- PLATFORMS
- DEPLOY
