Skip to main content
Promotional banner ad for the Penetration Testing Report Kit
Category: TCF and Vendors

CMP List

Also known as: CMP, List of Consent Management Platforms, Registered CMPs
Simply put

A CMP List generally refers to a compilation of Consent Management Platforms, which are software tools that help websites and apps collect, manage, and store user consent for processing personal data. Such a list may be used to compare or select vendors that support cookie and consent compliance. The available evidence describes what a Consent Management Platform is but does not detail the specific structure, maintainer, or authority behind any particular 'CMP List,' so those aspects are out of scope here.

Formal definition

In the context of cookie consent management, a 'CMP List' typically denotes a catalog or register of Consent Management Platforms (CMPs), the software solutions that facilitate the collection, management, and storage of user consent for the processing of personal data on websites and mobile applications. CMPs are commonly deployed to support compliance with data privacy obligations, though a tool's inclusion on any list does not itself guarantee legal compliance, which depends on configuration and jurisdiction-specific requirements (for example, the opt-in consent standards typical of EU/UK frameworks versus opt-out models under certain US state laws). The evidence provided does not identify a specific governing body, framework (such as an IAB TCF registered-CMP list), or eligibility criteria for any particular 'CMP List'; where such a list is maintained by a specific framework or authority, its scope and requirements should be confirmed against that source directly. This distinction is noted because contested or framework-specific interpretations are not resolvable from the evidence packet.

Why it matters

Selecting a Consent Management Platform is one of the more consequential technical decisions an organization makes when operationalizing cookie and consent compliance, and a CMP List, understood as a compilation of available platforms, can serve as a starting point for comparing vendors. Because CMPs are the software layer through which user consent is collected, managed, and stored across websites and apps, the choice of platform affects how consent signals are captured, how records are retained, and how well the deployment can be aligned with jurisdiction-specific requirements.

It is important to treat any CMP List as a reference for vendor evaluation rather than as a compliance assurance. Inclusion of a platform on a list does not, by itself, establish that a given deployment is lawful. Compliance generally depends on how the CMP is configured, the categories of cookies and technologies in use, and the applicable legal regime, for example, the opt-in consent standards typical of EU and UK frameworks versus the opt-out models common under certain US state privacy laws. A well-regarded tool configured incorrectly can still produce non-compliant outcomes.

The evidence available describes what a Consent Management Platform is but does not identify a specific governing body, framework, or eligibility criteria behind any particular 'CMP List.' Where a list is maintained by a specific framework or authority, such as a registered-CMP list under a particular consent framework, its scope, criteria, and legal significance should be confirmed directly against that source rather than assumed.

Who it's relevant to

Privacy Officers and Data Protection Professionals
Those responsible for consent management may use a CMP List to identify and compare platforms during vendor selection. They should treat inclusion on a list as a starting point for evaluation and confirm that any chosen platform can be configured to meet the specific consent standards applicable to their jurisdictions, since a tool alone does not guarantee compliance.
Legal and Compliance Counsel
Counsel advising on cookie and consent obligations may reference a CMP List when assessing vendor options, while recognizing that a platform's presence on a list does not establish lawfulness. Where a list is maintained by a specific framework or authority, counsel should verify its scope, criteria, and legal significance directly against that source, as these details are not resolvable from general definitions of a CMP.
Web Developers and Technical Implementers
Teams deploying consent tooling may consult a CMP List to shortlist candidate platforms, but the effectiveness of any CMP for capturing, managing, and storing consent depends heavily on configuration. Developers should coordinate with privacy and legal stakeholders to ensure the deployment aligns with the applicable opt-in or opt-out requirements rather than relying on vendor listing alone.
Marketing Compliance Teams
Teams managing analytics, advertising, and other non-essential tracking technologies may use a CMP List when evaluating platforms to govern consent for those tools. They should note that similar technologies such as pixels, SDKs, and local storage fall within the same consent rules, and that platform selection is only one part of achieving a compliant configuration.

Inside CMP

Registered CMP identifiers
A CMP List, in the context of the IAB Transparency and Consent Framework (TCF), typically enumerates the consent management platforms that have registered with the framework, each generally assigned a unique identifier used to signal which CMP captured a given consent record.
CMP status information
Such a list may indicate the operational status of each CMP, for example whether it is active, or has been suspended or removed, which can affect whether consent signals attributed to that CMP are treated as valid within the framework.
Framework version compatibility
Entries may reference the framework version or technical specifications a CMP supports, since the TCF has evolved through versions and a CMP's conformance is generally tied to the specification it implements.
Metadata supporting the consent string
The CMP identifier recorded in a list typically corresponds to information encoded in the TCF consent string, allowing downstream parties to attribute a consent record to the CMP that generated it. This is an organizational and technical component of consent management, not itself a legal determination of validity.

Common questions

Answers to the questions practitioners most commonly ask about CMP.

Does registration on a CMP list mean a consent management platform is legally compliant?
No. Inclusion on a CMP list, such as the register of CMPs approved to operate under the IAB Transparency and Consent Framework (TCF), generally indicates that the platform has met the technical and procedural criteria set by the list's administrator. It does not certify that any given deployment of that CMP produces valid consent under the GDPR, the ePrivacy Directive as implemented nationally, or non-EU regimes. Compliance depends on how the CMP is configured and used on a specific website, and on legal judgment that no list can replace.
Is a CMP list an official regulatory or government-maintained register?
Not typically. CMP lists are generally maintained by industry bodies or framework administrators, such as the organization that governs the IAB TCF, rather than by data protection authorities. Being on such a list reflects participation in a private framework and adherence to its rules; it does not constitute regulatory approval or a finding by any supervisory authority that the platform is lawful in a particular jurisdiction.
How do I check whether a particular CMP is on the TCF list?
The administrator of the IAB Transparency and Consent Framework publishes the register of CMPs that have been assigned an identifier under the framework. You can generally consult that published register to confirm whether a CMP appears and what status it holds. Because the contents, format, and access method of such lists can change over time, verify against the current source rather than relying on cached or secondhand information.
What should I look for beyond a CMP appearing on a list when selecting a platform?
List membership is only a starting point. Consider whether the CMP supports the consent standards relevant to your jurisdictions, for example prior opt-in consent with clear affirmative action for most EU contexts and opt-out mechanisms such as Global Privacy Control signals for certain US state laws. Also assess consent logging and record-keeping features, granularity of purposes, handling of non-cookie technologies like pixels and SDKs, and configurability. Whether these features are used correctly remains a matter of implementation and legal review.
If our CMP is on the TCF list, do we still need our own compliance review?
Yes. A CMP being listed under a framework does not remove the controller's responsibility to ensure that consent collected on its properties is freely given, specific, informed, and unambiguous where EU law applies, or that opt-out rights are honored where US state laws apply. The tool supports compliance but does not substitute for your own legal assessment of configuration, banner design, purposes, and record-keeping.
What happens if a CMP is removed from a list after we have deployed it?
The consequences depend on the rules of the framework administrator and on why the CMP was removed. Removal may affect the CMP's ability to interoperate within that framework, which can have downstream effects on how consent signals are transmitted to vendors. Because the specific implications turn on framework rules and facts not covered by this definition, monitor communications from your CMP provider and the framework administrator, and seek legal advice on any impact to your consent operations.

Common misconceptions

Using a CMP that appears on the CMP List guarantees that a site's cookie consent practices are lawful.
Registration on such a list generally reflects participation in and technical conformance with a framework such as the IAB TCF; it does not by itself establish that consent is freely given, specific, informed, and unambiguous as required under the GDPR, nor that ePrivacy obligations regarding placing or accessing information on a device are met. Tools support compliance but do not replace legal judgment, and enforcement positions of data protection authorities continue to evolve.
The CMP List and its associated framework apply the same way in every jurisdiction.
Cookie consent obligations vary between the EU, the UK, and individual US states such as under the CCPA and CPRA in California, among other regimes. Frameworks like the TCF are primarily oriented toward EU-style opt-in consent, whereas several US state laws rely more on opt-out mechanisms. A CMP's presence on a list does not resolve these jurisdictional differences.
The CMP List is a list of approved cookies or a substitute for maintaining consent records.
A CMP List identifies consent management platforms, not the cookies or similar technologies (such as pixels, local storage, SDKs, or fingerprinting) that fall within the same rules. It also does not replace an organization's own consent logging and record-keeping obligations, which are distinct components of a consent management program.

Best practices

Confirm that any CMP you rely on is currently and actively registered with the relevant framework, since status can change and a suspended or removed CMP may affect how consent signals are treated.
Treat framework participation as a technical foundation only, and separately verify that your consent flow meets applicable legal standards, including the GDPR's requirement for a clear affirmative action and the ePrivacy rules on placing or accessing information on a device.
Map your obligations to each jurisdiction you operate in, recognizing that EU, UK, and US state requirements differ and that opt-in and opt-out models are not interchangeable.
Maintain your own consent logs and record-keeping independent of the CMP List, so you can demonstrate the basis on which each consent was collected.
Verify that the framework version your CMP implements matches your technical integration and that consent strings are correctly attributed to the registered CMP identifier.
Seek qualified legal advice for contested or unresolved questions, as guidance from data protection authorities continues to evolve and no tool or list can by itself confirm lawfulness.
Application Security Isn’t Optional Anymore.