NVIDIA H200 confidential computing: NVL and HGX support
H200 brings larger Hopper memory capacity into NVIDIA’s supported confidential-computing stack, but named public-cloud CC products are not yet documented.

Direct answer
NVIDIA currently supports H200 NVL for single-GPU confidential passthrough and HGX H200 8-GPU 141 GB systems for confidential mode, including documented Protected PCIe multi-GPU support. NVIDIA documents the vendor stack, but cloud providers do not identify a generally available H200 confidential-GPU SKU.Verified support scope
| Product | Vendor-supported mode | Availability conclusion |
|---|---|---|
| H200 NVL | Single-GPU passthrough CC | Supported stack; no named cloud CC SKU confirmed |
| HGX H200 8-GPU 141 GB | Single-GPU passthrough and Protected PCIe multi-GPU | Supported for qualifying on-premises/partner systems; verify exact matrix row |
| Ordinary H200 cloud or bare-metal listing | Not established by the listing alone | Require CC-On, supported host/device stack, and evidence |
H200 NVL
The current NVIDIA matrix lists H200 NVL for single-GPU passthrough confidential mode. It can fit memory-heavy inference, long-context serving, retrieval, and model workloads that outgrow an H100 configuration but do not need protected scale-out. Board availability at a provider remains separate from a verifiable confidential service.MATRIX
HGX H200 8-GPU
NVIDIA’s named HGX H200 8-GPU 141 GB system is supported in the current CC stack. R595 documents Protected PCIe multi-GPU mode, which assigns the supported GPU set to one confidential VM. Hopper’s GPU-to-GPU NVLink/NVSwitch traffic remains unencrypted, so the threat model must explicitly accept that peer path.R595MATRIX
Security boundary and operational limits
H200 uses NVIDIA’s Hopper confidential-computing architecture: a supported CPU confidential VM, measured GPU boot, device identity and attestation, protected driver session, hardware access controls, memory scrubbing, and encrypted/authenticated CPU–GPU transfers. As with H100, the relying party must verify evidence and gate secrets; enabling a mode is not sufficient.DEPLOYWHITEPAPER
- CC-On is the production state; CC-DevTools should fail production policy.
- Passthrough is required; MIG and vGPU are unsupported in the current Confidential Containers stack.
- Multi-GPU assignment is one confidential VM, with no mixed CC/non-CC devices on the node.
- Host/device data movement can create overhead; compute-heavy, memory-resident workloads are the better fit.
- Pinned-memory limitations and collective-library versions can affect application compatibility and throughput.
Who should choose H200
H200 is most useful when Hopper’s established confidential stack is preferred and model or batch memory pressure is material. Procurement should compare delivered tokens, examples, or training steps per unit cost under CC-On—not only capacity or GPU-hour price. A team that needs encrypted peer links or newer multi-GPU semantics should separately evaluate documented B200/B300 Blackwell support.
Frequently asked questions
Does NVIDIA support H200 confidential computing?
Yes, for named H200 NVL and HGX H200 configurations in NVIDIA’s current matrix and release documentation. Exact firmware, driver, host and topology rows still govern deployment.
Which cloud offers H200 confidential GPU instances?
Official cloud documentation does not identify a generally available H200 confidential-GPU SKU as of 22 August 2026. Ordinary H200 availability is not proof of CC mode.
Does HGX H200 protect GPU-to-GPU NVLink traffic?
Hopper Protected PCIe mode protects CPU–GPU traffic, but NVIDIA documents that GPU-to-GPU NVLink/NVSwitch traffic is not encrypted.
Sources
- R595
- MATRIX
- PLATFORMS
- DEPLOY
- WHITEPAPERNVIDIA Hopper H100 GPU: Confidential Computing whitepaperNVIDIA — Hopper confidential-computing architecture used by the H200 family
