NVIDIA H200 confidential computing: NVL and HGX support

H200 brings larger Hopper memory capacity into NVIDIA’s supported confidential-computing stack, but named public-cloud CC products are not yet documented.

Abstract botanical artwork combining painted flowers with fine technical linework.

Direct answer

NVIDIA currently supports H200 NVL for single-GPU confidential passthrough and HGX H200 8-GPU 141 GB systems for confidential mode, including documented Protected PCIe multi-GPU support. NVIDIA documents the vendor stack, but cloud providers do not identify a generally available H200 confidential-GPU SKU.

Verified support scope

ProductVendor-supported modeAvailability conclusion
H200 NVLSingle-GPU passthrough CCSupported stack; no named cloud CC SKU confirmed
HGX H200 8-GPU 141 GBSingle-GPU passthrough and Protected PCIe multi-GPUSupported for qualifying on-premises/partner systems; verify exact matrix row
Ordinary H200 cloud or bare-metal listingNot established by the listing aloneRequire CC-On, supported host/device stack, and evidence
R595MATRIXPLATFORMS

H200 NVL

The current NVIDIA matrix lists H200 NVL for single-GPU passthrough confidential mode. It can fit memory-heavy inference, long-context serving, retrieval, and model workloads that outgrow an H100 configuration but do not need protected scale-out. Board availability at a provider remains separate from a verifiable confidential service.MATRIX

HGX H200 8-GPU

NVIDIA’s named HGX H200 8-GPU 141 GB system is supported in the current CC stack. R595 documents Protected PCIe multi-GPU mode, which assigns the supported GPU set to one confidential VM. Hopper’s GPU-to-GPU NVLink/NVSwitch traffic remains unencrypted, so the threat model must explicitly accept that peer path.R595MATRIX

Security boundary and operational limits

H200 uses NVIDIA’s Hopper confidential-computing architecture: a supported CPU confidential VM, measured GPU boot, device identity and attestation, protected driver session, hardware access controls, memory scrubbing, and encrypted/authenticated CPU–GPU transfers. As with H100, the relying party must verify evidence and gate secrets; enabling a mode is not sufficient.DEPLOYWHITEPAPER

  • CC-On is the production state; CC-DevTools should fail production policy.
  • Passthrough is required; MIG and vGPU are unsupported in the current Confidential Containers stack.
  • Multi-GPU assignment is one confidential VM, with no mixed CC/non-CC devices on the node.
  • Host/device data movement can create overhead; compute-heavy, memory-resident workloads are the better fit.
  • Pinned-memory limitations and collective-library versions can affect application compatibility and throughput.
R595PLATFORMS

Who should choose H200

H200 is most useful when Hopper’s established confidential stack is preferred and model or batch memory pressure is material. Procurement should compare delivered tokens, examples, or training steps per unit cost under CC-On—not only capacity or GPU-hour price. A team that needs encrypted peer links or newer multi-GPU semantics should separately evaluate documented B200/B300 Blackwell support.

Frequently asked questions

Does NVIDIA support H200 confidential computing?

Yes, for named H200 NVL and HGX H200 configurations in NVIDIA’s current matrix and release documentation. Exact firmware, driver, host and topology rows still govern deployment.

Which cloud offers H200 confidential GPU instances?

Official cloud documentation does not identify a generally available H200 confidential-GPU SKU as of 22 August 2026. Ordinary H200 availability is not proof of CC mode.

Does HGX H200 protect GPU-to-GPU NVLink traffic?

Hopper Protected PCIe mode protects CPU–GPU traffic, but NVIDIA documents that GPU-to-GPU NVLink/NVSwitch traffic is not encrypted.

Sources

  1. R595
  2. MATRIX
  3. PLATFORMS
  4. DEPLOY
  5. WHITEPAPER
    NVIDIA Hopper H100 GPU: Confidential Computing whitepaperNVIDIA — Hopper confidential-computing architecture used by the H200 family