NVIDIA H100 confidential computing: supported SKUs, modes, and availability
H100 is NVIDIA’s first production confidential-computing GPU and the strongest deploy-now option—but support is SKU, topology, firmware, and provider specific.

Direct answer
NVIDIA currently supports confidential-computing mode on named H100 PCIe, H100 NVL, and HGX H100 variants. Single-GPU confidential H100 products are generally available on Azure with AMD SEV-SNP and Google Cloud with Intel TDX. Protected multi-GPU Hopper mode is limited to documented HGX 8-GPU variants and does not encrypt NVLink/NVSwitch peer traffic.Support status at a glance
| Scope | Verified status | Meaning |
|---|---|---|
| Hardware capability | Yes, on NVIDIA’s named H100 products | H100 introduced NVIDIA’s hardware GPU confidential-computing architecture |
| Vendor-supported CC mode | Yes, exact SKUs and system rows only | Use R595 plus the live Secure AI Compatibility Matrix for firmware/driver details |
| Public-cloud availability | Yes, named Azure and Google Cloud single-GPU products | Ordinary H100 instances at other providers are not automatically confidential |
| Multi-GPU protected mode | Yes, on named HGX H100 8-GPU variants | CPU–GPU traffic is protected; Hopper NVLink/NVSwitch peer traffic is not encrypted |
H100 PCIe
NVIDIA’s current matrix lists H100 PCIe for single-GPU passthrough confidential mode. A provider exposing the board through ordinary passthrough is not enough: the host CPU TEE, system firmware, VBIOS, driver branch, guest software, and reference measurements must match a supported row.MATRIXPLATFORMS
H100 NVL
H100 NVL is supported for single-GPU confidential passthrough. Azure’s GA NCCadsH100v5 product uses one 94 GB H100 NVL with AMD EPYC Genoa and SEV-SNP. Azure documents no live migration, memory-preserving updates, resizing, or accelerated networking for this series; regional SKU availability should be queried at procurement time.AZUREAZURE-SKU
HGX H100 variants
The live matrix names HGX H100 4-GPU configurations in 64 GB, 80 GB, and 94 GB variants, and HGX H100 8-GPU 80 GB and 96 GB configurations. NVIDIA’s R595 release supports Protected PCIe multi-GPU confidential mode on the named 8-GPU configurations. Check the current row for cooling and board/system specifics rather than generalizing from the HGX label.R595MATRIX
Confirmed cloud products
| Provider product | Host TEE and GPU | Documented constraints |
|---|---|---|
| Azure Standard_NCC40ads_H100_v5 | AMD EPYC Genoa / SEV-SNP + one 94 GB H100 NVL | GA; no live migration, memory-preserving updates, resize, or accelerated networking; verify region/quota |
| Google Cloud a3-highgpu-1g | Intel Sapphire Rapids / TDX + one H100 | GA in documented zones; no reservations or multi-node confidential cluster support |
AWS, Oracle Cloud, CoreWeave, Nebius, and other providers may list H100 hardware. Their product documentation does not establish a named H100 service with NVIDIA confidential mode enabled. Keep “H100 available” separate from “H100 CC-On with verifiable evidence.”
Security properties and limits
- Secure/measured GPU boot, device identity, hardware access controls, memory scrubbing, a protected session to the CPU confidential VM, and GPU attestation establish the intended device boundary.
- Hopper uses AES-GCM-protected bounce buffers for CPU–GPU traffic through host-visible shared memory.
- H100 HBM is not encrypted. NVIDIA treats on-package placement as protection against common physical interposers in its published threat model.
- Denial of service, sophisticated physical attacks, unsafe code inside the workload, unprotected logs, and disclosure through outputs remain outside the automatic protection.
- CC-DevTools exposes counters/debug-related capability and is not equivalent to production CC-On; attestation policy should reject it.
Customer fit and performance considerations
H100 is a strong option for sensitive inference, fine-tuning, analytics, and proprietary model serving where a single GPU or a documented HGX topology provides enough memory and throughput. Compute-dense work fits better than workloads that repeatedly transfer small buffers across the CPU–GPU boundary. Pinned host-memory restrictions and unsupported cudaHostRegister behavior can affect existing pipelines; test the real runtime and libraries.R595PLATFORMS
- Confidential Containers currently require passthrough; MIG and vGPU are unsupported.
- Mixed confidential and non-confidential GPUs on one node are unsupported.
- For supported multi-GPU mode, all devices are assigned to one confidential VM.
- Pinned host memory is slower, and software such as NPP that assumes pinned memory may fail.
- R595 reports an NCCL performance issue with 2.26.2 in Protected PCIe mode and recommends 2.26.3 or newer.
Frequently asked questions
Is every NVIDIA H100 capable instance confidential?
No. The exact board/system, host CPU TEE, firmware, VBIOS, driver, GPU mode, topology, and provider service must match supported documentation, and the customer must verify evidence.
Does H100 confidential mode encrypt HBM?
NVIDIA documents that H100 HBM is not encrypted. It is on-package and treated as protected against common physical interposers within NVIDIA’s threat model.
Can H100 run a confidential multi-GPU workload?
NVIDIA supports Protected PCIe mode on named HGX H100 8-GPU variants. CPU–GPU traffic is protected, but Hopper NVLink/NVSwitch peer traffic is not encrypted.
Sources
- R595
- MATRIX
- PLATFORMS
- DEPLOY
- WHITEPAPER
- AZUREGPU options for Azure confidential VMsMicrosoft Azure
- AZURE-SKUNCCads H100 v5 VM sizesMicrosoft Azure
- GCPSupported configurations for Confidential VMGoogle Cloud
