NVIDIA H100 confidential computing: supported SKUs, modes, and availability

H100 is NVIDIA’s first production confidential-computing GPU and the strongest deploy-now option—but support is SKU, topology, firmware, and provider specific.

Abstract botanical artwork combining painted flowers with fine technical linework.

Direct answer

NVIDIA currently supports confidential-computing mode on named H100 PCIe, H100 NVL, and HGX H100 variants. Single-GPU confidential H100 products are generally available on Azure with AMD SEV-SNP and Google Cloud with Intel TDX. Protected multi-GPU Hopper mode is limited to documented HGX 8-GPU variants and does not encrypt NVLink/NVSwitch peer traffic.

Support status at a glance

ScopeVerified statusMeaning
Hardware capabilityYes, on NVIDIA’s named H100 productsH100 introduced NVIDIA’s hardware GPU confidential-computing architecture
Vendor-supported CC modeYes, exact SKUs and system rows onlyUse R595 plus the live Secure AI Compatibility Matrix for firmware/driver details
Public-cloud availabilityYes, named Azure and Google Cloud single-GPU productsOrdinary H100 instances at other providers are not automatically confidential
Multi-GPU protected modeYes, on named HGX H100 8-GPU variantsCPU–GPU traffic is protected; Hopper NVLink/NVSwitch peer traffic is not encrypted
R595MATRIXAZUREGCP

H100 PCIe

NVIDIA’s current matrix lists H100 PCIe for single-GPU passthrough confidential mode. A provider exposing the board through ordinary passthrough is not enough: the host CPU TEE, system firmware, VBIOS, driver branch, guest software, and reference measurements must match a supported row.MATRIXPLATFORMS

H100 NVL

H100 NVL is supported for single-GPU confidential passthrough. Azure’s GA NCCadsH100v5 product uses one 94 GB H100 NVL with AMD EPYC Genoa and SEV-SNP. Azure documents no live migration, memory-preserving updates, resizing, or accelerated networking for this series; regional SKU availability should be queried at procurement time.AZUREAZURE-SKU

HGX H100 variants

The live matrix names HGX H100 4-GPU configurations in 64 GB, 80 GB, and 94 GB variants, and HGX H100 8-GPU 80 GB and 96 GB configurations. NVIDIA’s R595 release supports Protected PCIe multi-GPU confidential mode on the named 8-GPU configurations. Check the current row for cooling and board/system specifics rather than generalizing from the HGX label.R595MATRIX

Confirmed cloud products

Provider productHost TEE and GPUDocumented constraints
Azure Standard_NCC40ads_H100_v5AMD EPYC Genoa / SEV-SNP + one 94 GB H100 NVLGA; no live migration, memory-preserving updates, resize, or accelerated networking; verify region/quota
Google Cloud a3-highgpu-1gIntel Sapphire Rapids / TDX + one H100GA in documented zones; no reservations or multi-node confidential cluster support
AZUREAZURE-SKUGCP

AWS, Oracle Cloud, CoreWeave, Nebius, and other providers may list H100 hardware. Their product documentation does not establish a named H100 service with NVIDIA confidential mode enabled. Keep “H100 available” separate from “H100 CC-On with verifiable evidence.”

Security properties and limits

  • Secure/measured GPU boot, device identity, hardware access controls, memory scrubbing, a protected session to the CPU confidential VM, and GPU attestation establish the intended device boundary.
  • Hopper uses AES-GCM-protected bounce buffers for CPU–GPU traffic through host-visible shared memory.
  • H100 HBM is not encrypted. NVIDIA treats on-package placement as protection against common physical interposers in its published threat model.
  • Denial of service, sophisticated physical attacks, unsafe code inside the workload, unprotected logs, and disclosure through outputs remain outside the automatic protection.
  • CC-DevTools exposes counters/debug-related capability and is not equivalent to production CC-On; attestation policy should reject it.
WHITEPAPERDEPLOY

Customer fit and performance considerations

H100 is a strong option for sensitive inference, fine-tuning, analytics, and proprietary model serving where a single GPU or a documented HGX topology provides enough memory and throughput. Compute-dense work fits better than workloads that repeatedly transfer small buffers across the CPU–GPU boundary. Pinned host-memory restrictions and unsupported cudaHostRegister behavior can affect existing pipelines; test the real runtime and libraries.R595PLATFORMS

  • Confidential Containers currently require passthrough; MIG and vGPU are unsupported.
  • Mixed confidential and non-confidential GPUs on one node are unsupported.
  • For supported multi-GPU mode, all devices are assigned to one confidential VM.
  • Pinned host memory is slower, and software such as NPP that assumes pinned memory may fail.
  • R595 reports an NCCL performance issue with 2.26.2 in Protected PCIe mode and recommends 2.26.3 or newer.
R595PLATFORMS

Frequently asked questions

Is every NVIDIA H100 capable instance confidential?

No. The exact board/system, host CPU TEE, firmware, VBIOS, driver, GPU mode, topology, and provider service must match supported documentation, and the customer must verify evidence.

Does H100 confidential mode encrypt HBM?

NVIDIA documents that H100 HBM is not encrypted. It is on-package and treated as protected against common physical interposers within NVIDIA’s threat model.

Can H100 run a confidential multi-GPU workload?

NVIDIA supports Protected PCIe mode on named HGX H100 8-GPU variants. CPU–GPU traffic is protected, but Hopper NVLink/NVSwitch peer traffic is not encrypted.

Sources

  1. R595
  2. MATRIX
  3. PLATFORMS
  4. DEPLOY
  5. WHITEPAPER
  6. AZURE
  7. AZURE-SKU
  8. GCP