RTX PRO 6000 Blackwell confidential computing: Server Edition scope
The Server Edition and its liquid-cooled variant are supported for single-GPU passthrough. That support does not extend to similarly named workstation or consumer cards.

Direct answer
NVIDIA currently supports single-GPU confidential passthrough on RTX PRO 6000 Blackwell Server Edition, including the liquid-cooled Server Edition. Google Cloud offers a generally available g4-standard-48 Confidential VM with one RTX PRO 6000 and AMD EPYC Turin/AMD SEV. Multi-GPU confidential mode, MIG, vGPU, workstation variants, and RTX PRO 4500 are not in this scope.Exact supported products
| Product | Status | Scope |
|---|---|---|
| RTX PRO 6000 Blackwell Server Edition | Named supported | Single-GPU passthrough CC |
| RTX PRO 6000 Blackwell Server Edition, liquid-cooled | Named supported | Single-GPU passthrough CC |
| RTX PRO 6000 workstation/other similarly named products | Not established | Do not infer Server Edition support |
| RTX PRO 4500 and consumer RTX | Not in operational matrix | Excluded |
| Multi-GPU RTX PRO 6000 CC | Not supported in current scope | Use one GPU per confidential VM |
Google Cloud G4 availability
Google Cloud documents g4-standard-48 Confidential VM as generally available with one RTX PRO 6000, AMD EPYC Turin, and AMD SEV. Google documents standard, Spot, and flex-start provisioning and a broad zone set. Exact zone, quota and provisioning availability remain live procurement checks.GCPGCP-CREATEGCP-NOTES
Customer fit
This family is well suited to single-GPU confidential inference, retrieval and embedding pipelines, smaller fine-tunes, secure visualization, and enterprise AI applications that value a generally available confidential VM over rack-scale topology. It is not the right page for large distributed training or models that require many accelerators.
- Best when the model and working set fit one 96 GB-class Server Edition GPU.
- Useful for isolated customer endpoints and regionally distributed confidential inference.
- Less suitable for multi-GPU sharding, NVLink-heavy work, or MIG/vGPU density models.
- Benchmark host/device transfers, preprocessing, model load and serving latency under CC-On.
- Confirm that observability and support tooling do not export prompts, intermediate state or outputs.
Security and operational constraints
The Server Edition participates in NVIDIA’s Blackwell confidential-computing architecture with a supported CPU confidential VM, measured GPU state, device attestation, protected transport, and policy-gated release. The production state is CC-On. As with every page in this guide, the claim applies to a complete supported stack rather than the board name in isolation.DEPLOYMATRIX
- Current mode is single-GPU passthrough; do not advertise confidential vGPU or MIG.
- CC-DevTools is not a production confidentiality state.
- The guest application, model behavior, tool permissions, logs and outputs remain security responsibilities.
- The provider can still deny service and controls capacity availability.
- Verify evidence freshness, expected firmware/RIM, security versions, mode, workload binding and secret-release failure behavior.
Frequently asked questions
Does RTX PRO 6000 Blackwell support confidential computing?
Yes, for the named Server Edition and liquid-cooled Server Edition in single-GPU passthrough mode. Do not generalize that support to workstation or consumer products.
Which cloud offers a confidential RTX PRO 6000 VM?
Google Cloud documents the generally available g4-standard-48 Confidential VM with one RTX PRO 6000 and AMD EPYC Turin/AMD SEV.
Can it run confidential multi-GPU workloads?
Not in the current supported scope. The documented product uses single-GPU passthrough; B200 or B300 are the current NVIDIA routes for supported Blackwell multi-GPU confidential mode.
Sources
- R595
- MATRIX
- PLATFORMS
- DEPLOY
- GCPSupported configurations for Confidential VMGoogle Cloud
- GCP-CREATECreate a Confidential VM instance with GPUGoogle Cloud
- GCP-NOTESConfidential VM release notesGoogle Cloud
