Skip to main content
Commerce Security logo, "All 12 PCI DSS Requirements in Plain English," "Get it now for free," "Complete Survival Guide" and a button toclick to get it
Category: TCF and Vendors

CMP Registration

Also known as: CMP, Consent Management Platform Registration, CMP ID Registration
Simply put

CMP registration is the process by which a consent management platform formally signs up with IAB Europe to participate in its Transparency and Consent Framework (TCF). As part of registering, the platform receives an identifier and agrees to follow the Framework's technical specifications and policies. This registration is specific to the IAB Europe Framework and is a matter of contractual participation rather than a legal certification of compliance.

Formal definition

In the context of the IAB Europe Transparency and Consent Framework (TCF), CMP registration refers to the procedure through which a consent management platform enrolls with IAB Europe and is assigned a CMP ID. According to IAB Europe, registering CMPs contractually agree to adhere to the Framework's technical specification and Policies. Registration establishes the CMP's recognized status within the TCF ecosystem and enables it to generate and transmit standardized consent signals (such as a TC string) that Framework participants can interpret. It should be noted that participation in the TCF is a private, contractual arrangement operated by IAB Europe; registration does not by itself confer compliance with the ePrivacy Directive, the GDPR, the UK regime, or US state privacy laws, and the legal validity of any consent collected depends on facts and requirements beyond the scope of registration. The acronym 'CMP' is also used for unrelated concepts (for example, Certificate Management Protocol and Certified Meeting Professional), which fall outside this entry.

Why it matters

CMP registration matters because it determines whether a consent management platform can operate within the IAB Europe Transparency and Consent Framework (TCF), which many publishers, advertisers, and ad-tech vendors rely on to exchange standardized consent signals. A registered CMP receives a CMP ID and can generate and transmit signals (such as a TC string) that other Framework participants recognize and interpret. Without registration, a platform cannot participate in this particular ecosystem, so for organizations that have chosen the TCF as their interoperability mechanism, registration is a practical prerequisite for that supply chain to function.

At the same time, it is important not to overstate what registration achieves. Participation in the TCF is a private, contractual arrangement operated by IAB Europe, and registration is a matter of enrolling and agreeing to follow the Framework's technical specifications and policies rather than a legal certification. Registering does not by itself confer compliance with the ePrivacy Directive, the GDPR, the UK regime, or US state privacy laws. The legal validity of any consent collected through a registered CMP depends on facts and requirements that fall outside the scope of registration, including whether the consent obtained is freely given, specific, informed, and unambiguous under EU standards.

Because of this gap between contractual participation and legal compliance, privacy and compliance teams should treat CMP registration as one component of a broader consent management strategy rather than as evidence that their cookie practices are lawful. Tools and framework membership can support compliance efforts, but they do not replace the legal judgment required to assess whether a given implementation meets the applicable obligations in the jurisdictions where an organization operates.

Who it's relevant to

Consent management platform providers
Vendors building or operating a CMP need to understand that registration with IAB Europe assigns a CMP ID and requires contractual agreement to follow the TCF's technical specifications and policies. This is the gateway to interoperability within the TCF ecosystem, but providers should be clear with their customers that registration supports, rather than guarantees, legal compliance.
Publishers and ad-tech participants
Organizations that rely on the TCF to exchange consent signals across the advertising supply chain depend on registered CMPs to generate and transmit standardized signals such as the TC string. For these participants, whether a CMP is registered affects whether its signals will be recognized by other Framework members.
Privacy officers and data protection professionals
Compliance teams should recognize that CMP registration is a private, contractual arrangement operated by IAB Europe and does not by itself confer compliance with the ePrivacy Directive, the GDPR, the UK regime, or US state privacy laws. The legal validity of consent collected depends on facts and requirements beyond registration and requires independent legal assessment.
Legal counsel advising on cookie consent
Lawyers evaluating an organization's consent posture should treat participation in the TCF as one element among many. Registration establishes recognized status within the Framework but does not resolve questions about whether consent is freely given, specific, informed, and unambiguous, or how obligations differ across the EU, the UK, and individual US states.

Inside CMP

Framework Registration
The process by which a consent management platform (CMP) applies to be listed as an approved vendor within a specific framework, most notably the IAB Europe Transparency and Consent Framework (TCF). Registration typically involves committing to the framework's technical specifications and policies. Registration under one framework does not by itself establish compliance with the ePrivacy Directive or GDPR.
Technical Conformance Requirements
Registered CMPs are generally expected to implement the framework's technical specifications, such as generating and storing consent strings, exposing standardized APIs, and signaling user choices to downstream vendors. These requirements are technical in nature and do not, on their own, resolve the underlying legal question of whether valid consent has been obtained.
Vendor Identification
Registration typically assigns the CMP a unique identifier within the framework, allowing publishers and ad-tech participants to recognize and interoperate with it. Within the TCF, vendors that process personal data are also registered separately from CMPs, so a CMP identifier and a vendor identifier serve distinct roles.
Policy and Ongoing Obligations
Registered CMPs generally agree to abide by the framework operator's policies, which may include audit provisions, use of approved user interface patterns, and continued conformance to updated specifications. Non-compliance can, in principle, result in removal from the register, though specific enforcement mechanisms depend on the framework operator.
Scope Limitations
CMP registration addresses interoperability and participation within a defined framework. It does not determine the lawfulness of consent under the ePrivacy Directive (which governs storing or accessing information on a device) or the GDPR (which governs subsequent processing of personal data), nor does it address obligations under the UK regime or US state privacy laws such as the CCPA/CPRA.

Common questions

Answers to the questions practitioners most commonly ask about CMP.

Does registering a CMP with a framework such as the IAB TCF make my cookie consent setup compliant?
No. Registration is an administrative and technical step that allows a CMP to participate in a framework such as the IAB Transparency and Consent Framework; it does not by itself establish that your consent practices satisfy legal requirements. Valid consent under the GDPR must still be freely given, specific, informed, and unambiguous, and the ePrivacy rules on placing or accessing information on a device apply independently. A registered CMP supports compliance but does not replace the legal judgment needed to assess whether your particular implementation meets the applicable standards. Enforcement positions from data protection authorities also continue to evolve, so registration status should not be treated as a compliance guarantee.
Is CMP registration a legal requirement for using cookies or a consent banner?
Generally no. There is typically no standalone legal obligation to register a CMP in order to deploy cookies or a consent interface. Registration is usually a condition imposed by a specific framework or vendor ecosystem (for example, to participate in the IAB TCF), not a statutory requirement under the GDPR, the ePrivacy Directive as implemented in EU member states, the UK regime, or US state privacy laws. Organizations can seek and record consent without joining such a framework. Whether framework participation is appropriate depends on your advertising and vendor relationships rather than on a general legal mandate.
What information is typically needed to complete a CMP registration?
Requirements vary by framework and vendor, but registration processes commonly ask for organizational identification details, technical information about the CMP implementation, and acknowledgment of the framework's policies and specifications. Where a framework such as the IAB TCF is involved, this may include committing to its technical and policy rules. Because specific fields and criteria differ between frameworks and change over time, you should consult the current documentation of the relevant framework rather than assume a fixed set of inputs.
How does CMP registration relate to consent logging and record-keeping obligations?
These are distinct matters. Registration concerns a CMP's participation in a framework or vendor ecosystem, while consent logging concerns maintaining records that demonstrate valid consent was obtained, which supports accountability expectations under the GDPR. Registering a CMP does not automatically satisfy record-keeping needs, and adequate logging can be maintained independently of any framework. You should confirm that your CMP captures and retains the evidence appropriate to your jurisdiction, and treat the logging configuration as a separate implementation task from registration.
Do we need to re-register or update our CMP registration when frameworks or configurations change?
Frameworks periodically update their technical specifications and policies, and continued participation may require conforming to current versions. Whether a formal re-registration, revalidation, or configuration update is needed depends on the specific framework's rules at the time. Because these requirements evolve, it is prudent to monitor the relevant framework's announcements and documentation and to review your CMP configuration when material changes occur. This entry does not cover the procedural details of any particular framework's update cycle.
How does CMP registration interact with signals like Global Privacy Control or with US opt-out regimes?
Registration within an EU-oriented framework does not by itself address obligations under US state privacy laws such as the CCPA and CPRA in California, which often rely on opt-out mechanisms and may require honoring signals such as Global Privacy Control. Support for such signals is typically a separate configuration and legal consideration from framework registration. Because obligations differ across the EU, the UK, and individual US states, you should confirm that your CMP is configured to handle the specific mechanisms required in each jurisdiction where you operate, rather than assume registration covers them.

Common misconceptions

A registered CMP guarantees that a website's cookie consent is legally compliant.
Registration confirms participation in and technical conformance with a particular framework, such as the IAB TCF. It does not by itself establish that consent meets the GDPR standard of being freely given, specific, informed, and unambiguous, nor that ePrivacy requirements for placing or accessing information on a device are satisfied. Tools support compliance but do not replace legal judgment, and how a CMP is configured and deployed remains the deploying organization's responsibility.
CMP registration under the TCF makes a consent solution valid everywhere.
Frameworks such as the TCF are oriented toward EU/EEA requirements, and the underlying legal obligations differ across jurisdictions. The UK follows its own regime, and US state laws such as the CCPA/CPRA generally rely on opt-out rather than opt-in models. Registration in one framework does not automatically map onto the requirements of other regions, so geographic scope should be assessed separately.
Once a CMP is registered, no further obligations apply.
Registration typically carries ongoing obligations, including maintaining technical conformance as specifications evolve and adhering to the framework operator's policies. Separately, deploying organizations generally retain independent duties such as maintaining consent records and honoring signals like Global Privacy Control where applicable. These obligations are continuous rather than resolved at the point of registration.

Best practices

Treat CMP registration as one component of a broader compliance program rather than as evidence of compliance in itself, and document how consent is actually obtained, logged, and honored.
Verify that the CMP's registration and technical configuration reflect the frameworks and jurisdictions relevant to your audience, since EU, UK, and US state requirements differ and a single framework registration may not cover all of them.
Confirm that the CMP is configured to seek prior consent for non-essential technologies (such as analytics, advertising, and functional cookies, as well as pixels, SDKs, and similar mechanisms) and to allow essential cookies to operate without consent where exempt.
Review the consent user interface for alignment with the GDPR standard of a clear affirmative action, avoiding pre-ticked boxes, reliance on continued browsing, or cookie walls that may be considered non-compliant in EU jurisdictions.
Ensure the CMP maintains adequate consent logging and records to support accountability and demonstrate the choices users made, and confirm these records are retained consistently with your record-keeping obligations.
Monitor updates to the relevant framework specifications and to data protection authority guidance, and re-assess the CMP deployment periodically, since enforcement positions and technical requirements evolve over time.
Promotional banner for the Pentest Readiness checklist download