NVIDIA B300 confidential computing: supported systems and buyer checks

B300 is a current NVIDIA-supported Blackwell Ultra confidential target. Bind every claim to the live matrix because system and cooling rows continue to evolve.

Abstract botanical artwork combining painted flowers with fine technical linework.

Direct answer

NVIDIA currently supports confidential computing on named HGX B300 270 GB systems. R595 names the air-cooled system, while the newer live matrix also exposes liquid-cooled rows. Blackwell confidential passthrough supports single-GPU and up-to-eight-GPU operation with protected NVLink peer traffic; no named public-cloud CC SKU was confirmed.

Current supported scope

NVIDIA R595 names HGX B300 270 GB air-cooled systems for confidential operation. The live Secure AI Compatibility Matrix is newer and also includes liquid-cooled rows. Because those sources move at different cadences, procurement should cite the exact matrix row, GPU firmware/VBIOS, driver and RIM status selected for delivery.R595MATRIX

LayerPublication position
Hardware capabilityVerified on named HGX B300 systems
Vendor-supported CC modeSingle- and Blackwell multi-GPU passthrough, up to eight GPUs on supported rows
Protected peer trafficBlackwell mode encrypts NVLink peer traffic
Cloud availabilityNo named generally available B300 confidential-GPU product confirmed
Cooling/system varianceR595 names AC; current matrix also lists PC—use the live row
R595MATRIX

Why B300 multi-GPU protection matters

Large models and training jobs shard state across accelerators. Blackwell’s supported multi-GPU confidential mode can protect CPU–GPU and GPU-peer communication within the documented topology, avoiding Hopper’s unencrypted NVLink/NVSwitch limitation. The security outcome still depends on composite attestation, accepted device membership, and keys released only to the approved job.DEPLOYR595

Performance evidence—without a universal promise

NVIDIA published 2026 B300/Qwen measurements showing roughly 1–8% steady-state inference differences across the tested cases. That is vendor benchmark evidence for those configurations, not a guarantee for every model, context length, batch size, serving engine, topology, or data-transfer pattern. Buyers should reproduce the representative workload and include startup, model loading, attestation, and failure recovery.BENCH

  • Compute-dense inference or training with state resident on the GPUs is the strongest fit.
  • Frequent host/device transfers can make encryption and protected-I/O overhead more visible.
  • Pinned-memory restrictions can affect libraries and preprocessing pipelines.
  • Multi-GPU measurements must include collectives, topology, device membership and fail/restart behavior.
  • Capacity, power, cooling and node replacement can dominate delivered service even when kernel overhead is low.
PLATFORMSBENCH

Customer fit and procurement checks

B300 fits high-value, memory- and compute-intensive confidential training or inference where Blackwell peer-link protection is material. It is a poor requirement when a smaller supported GPU meets the threat model and throughput target more economically. Require measured workload economics and a current compatibility record rather than buying the newest name.

  1. Identify AC or PC HGX system, exact GPU count/topology, host CPU TEE, BIOS, VBIOS, firmware and driver.
  2. Obtain CPU and every-GPU evidence, reference measurements, revocation checks, debug-mode policy and session binding.
  3. Test fail-closed secret release for missing devices, stale evidence, version drift and CC-DevTools.
  4. Confirm passthrough constraints, no MIG/vGPU, no mixed-mode devices, and one-CVM multi-GPU assignment.
  5. Benchmark delivered tokens/training steps, model load, collectives, host/device transfer and recovery under CC-On.
R595MATRIXPLATFORMS

Frequently asked questions

Does NVIDIA support B300 confidential computing now?

Yes, on named HGX B300 systems in current NVIDIA release and compatibility documentation. Exact cooling, firmware, driver and host rows still govern deployment.

What is the B300 confidential-computing overhead?

NVIDIA published roughly 1–8% steady-state inference differences across selected B300/Qwen tests. That is not universal; benchmark the exact model, engine, transfers, topology and lifecycle operations.

Is Vera Rubin included in the supported GPU list?

Not yet. Hardware capability is announced, but Rubin is absent from the current production compatibility matrix and R595 deployment release as of 22 August 2026.

Sources

  1. R595
  2. MATRIX
  3. PLATFORMS
  4. DEPLOY
  5. BENCH
  6. RUBIN
    NVIDIA Rubin platform announcementNVIDIA Newsroom — Announced capability; excluded from current supported routes