Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Confidential computing protects data while it is being processed, using a hardware-based trusted execution environment (TEE) that isolates code and data from the host operating system or hypervisor and can provide cryptographic evidence of its security state. IDC’s November 2025 white paper argues that this “encryption in use” layer complements encryption at rest and in transit; it does not replace them.

What IDC means by confidential computing

IDC defines confidential computing as “the protection of data that is actively in use by performing computation in a hardware-based, attested trusted execution environment (TEE).” The definition is attributed to Philip Bues in IDC’s November 2025 white paper, Unlocking the Future of Data Security: Confidential Computing as a Strategic Imperative (IDC #US53866125).

The key distinction is the stage of the data lifecycle being protected. Stored information can be encrypted at rest, and information moving across networks can be encrypted in transit. But an application generally needs usable data in CPU and memory to process it. Confidential computing is intended to protect that processing stage by isolating sensitive workloads in a TEE and providing an attestation of the environment’s security state.

IDC presents the three protections as additive: encryption at rest, encryption in motion, and encryption in use. A TEE is not a cure-all, and the white paper says confidential computing is meant to work alongside storage and network encryption rather than replace those controls.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What the 2025 adoption figures show

The figures below come from an IDC study fielded in July 2025 and reported in the November white paper. The survey covered 600 manager-level-or-higher IT leaders across 15 industries at organizations with 500 to 10,000 employees. Respondents were involved weekly in specifying or developing systems that process confidential or regulated data. The study was sponsored by the Confidential Computing Consortium, and its findings describe this respondent sample—not every organization.

Measure Reported result
Organizations using confidential computing 75% of surveyed organizations, according to IDC’s 2025 study.
Deployment stage 18% of surveyed organizations had workloads in production and 57% were actively piloting, according to IDC’s 2025 study.
Familiarity 73% of surveyed respondents were familiar with confidential computing, including 31% who were very familiar, according to IDC’s 2025 study.

The distinction between use, piloting, and production matters: the reported 75% using the technology includes organizations at different stages, and the 57% piloting figure is not a production-deployment rate. The results indicate broad experimentation in this sample, alongside a smaller share reporting production use.

Where confidential computing can help

Protecting AI workloads and intellectual property

For AI training and inference, a TEE can be used to protect sensitive code and data from the external execution environment. During inference, for example, an organization may want to protect its model while another party’s data is being processed. The same pattern can matter for proprietary datasets, model outputs, and other intellectual property. Confidential computing is one part of the security design; the exact protections depend on the workload and implementation.

Collaborating across organizations

Multiparty data collaboration and privacy-preserving analytics can involve parties that want to derive value from combined or shared data without exposing it to the surrounding infrastructure. Confidential computing may help protect the computation environment in those scenarios. Other privacy-enhancing technologies, including secure multiparty computation and homomorphic encryption, may be a better fit for different risk profiles; they should be evaluated against the specific use case rather than treated as interchangeable.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Supporting regulated and distributed workloads

IDC identifies financial-services compliance and audit, healthcare data collaboration, and workloads spanning cloud, hybrid, on-premises, and edge environments among the use cases. Deployment location alone does not establish that a workload is protected: the TEE, its attestation, key handling, and operational controls still need to be assessed.

How attestation and trust fit together

Attestation is the evidence that a TEE is in a particular security state. It matters because isolation claims need to be checked rather than simply assumed. An organization must understand how an attestation is produced, what is being attested, how the evidence is validated, and what happens if validation fails or the environment changes.

IDC’s survey highlights this operational challenge: 84.5% of surveyed respondents cited validating attestation chains of trust as a challenge in the 2025 study. That finding makes attestation validation a deployment requirement to test, not a detail to leave solely to a product’s marketing claims.

What to evaluate before choosing an approach

Confidential-computing implementations differ, so compare the actual deployment and operating model rather than relying on the category label. IDC’s discussion points to several decision factors:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Deployment environment: Identify whether the workload must run in a public cloud, hybrid or on-premises environment, or at the edge.
  • TEE and attestation model: Determine how the execution environment isolates workloads and how its security state is attested and validated.
  • Workload and data sensitivity: Match the protection to the data, code, models, and outputs that need to remain confidential during processing.
  • Interoperability and lock-in: Check whether the approach works across required cloud providers and how difficult it would be to move workloads or evidence between them.
  • Key lifecycle: Assess how keys are managed across setup, operation, access changes, and retirement.
  • Regulatory and residency needs: Verify that the implementation fits the organization’s applicable requirements and where data must be processed.
  • Performance and skills: Measure the impact on the actual workload and confirm the team can operate and validate the system.

IDC’s 2025 study also reports that 77.7% of respondents saw the technology as niche with limited proof points, 74.7% cited a lack of skilled personnel, 62.2% cited inconsistent public-cloud approaches and vendor lock-in, and 21.3% cited compute-performance deterioration. These are reported challenge rates among survey respondents, not independent product benchmarks or a guarantee of performance impact for a particular deployment.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Confidential computing, DORA, and compliance

IDC says 77% of surveyed organizations were more likely to consider confidential computing because of the EU Digital Operational Resilience Act (DORA), according to the 2025 study. The white paper connects DORA’s focus on availability, authenticity, integrity, and confidentiality across data at rest, in use, and in transit with confidential computing’s focus on protecting data during processing.

That alignment can make confidential computing relevant to a resilience and data-protection program, but adopting a TEE does not by itself establish DORA compliance. Organizations still need to assess their obligations and demonstrate that their overall technical and operational controls meet them.

Is confidential computing ready for production?

The evidence supports a qualified answer: it is already in production for some organizations, but adoption is uneven and many surveyed organizations were still piloting. IDC’s sample reported 18% with workloads in production and 57% actively piloting. Separately, the Confidential Computing Consortium’s 2025 announcement of the IDC study reported full-production deployment rates of 37% in financial services, 29% in healthcare, and 21% in government. Those sector-specific figures are attributed to the Consortium’s announcement and should not be read as a universal rate across industries.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Production readiness therefore depends on whether a specific implementation can meet the workload’s security, operational, performance, interoperability, and regulatory needs. IDC’s recommended path is to begin with pilots that demonstrate measurable value, use open standards and vendor-agnostic frameworks where possible, and invest in third-party attestation and interoperability testing. Its recommendations also include engagement with industry initiatives such as the Confidential Computing Consortium.

The Consortium’s announcement reports that 88% identified improved data integrity as the primary benefit, 73% cited confidentiality with proven technical assurances, and 68% cited better regulatory compliance, according to the Consortium’s 2025 account of the study. These are reported perceptions of benefits, not proof that every implementation delivers them automatically.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.