Skip to main content
green gradient background, "The Future of Application Security Is Already Here." and a read the report button.
Category: TCF and Vendors

IAB-approved CMP

Also known as: CMP, IAB Europe registered CMP, TCF-registered CMP, IAB Europe TCF Consent Management Platform
Simply put

An IAB-approved CMP is a consent management platform (the software behind cookie banners that informs users and records their choices) that has completed IAB Europe's registration and approval process to operate within its Transparency and Consent Framework (TCF). Being approved means IAB Europe has verified the provider's identity and registered it to signal user consent choices in a standardized way that advertising partners can read. Approval indicates participation in the framework and does not by itself guarantee that any given implementation meets legal requirements.

Formal definition

An IAB-approved CMP is a Consent Management Platform that has been vetted and registered by IAB Europe under the Transparency & Consent Framework (TCF) policies, receiving a unique CMP ID that appears on the official CMP List. Under the TCF policies, IAB Europe will not approve an application until it can verify to its satisfaction the identity of the parties controlling the CMP. Such a CMP develops user-facing notices (e.g., cookie banners) to inform users and capture their preferences, then encodes those choices into standardized TC Strings that vendors participating in the framework can consume. Google Ad Manager requires a certified CMP integrated with the TCF when serving personalized ads to users in the EEA and UK, a requirement stated as applying from 16 January 2024, with support for TCF v2.3 among the current specifications. Scope note: IAB approval and Google certification are related but distinct programs; registration signals participation in the TCF and technical conformance to its specifications, but it is not a determination that a deployment satisfies the ePrivacy Directive's national implementations governing storage and access on a device, or the GDPR standards for valid consent. Legal compliance depends on configuration, disclosures, and facts outside the scope of framework registration, and enforcement positions on the TCF have been contested in some EU jurisdictions.

Why it matters

For publishers and advertisers operating in the EEA and UK, working with an IAB-approved CMP has become a practical gatekeeper for participation in programmatic advertising. Google's Ad Manager requires a certified CMP integrated with the TCF when serving personalized ads to users in the EEA and UK, a requirement stated as applying from 16 January 2024. This means that the choice of CMP is not merely a technical detail but a condition of access to major advertising infrastructure, giving IAB approval commercial significance beyond its role in signaling user choices.

Approval also matters because it standardizes how consent choices are communicated across the advertising supply chain. An approved CMP encodes user preferences into standardized TC Strings that participating vendors can read, which allows a large ecosystem of parties to act on the same signal. IAB Europe verifies the identity of the parties controlling a CMP before approval, which introduces a baseline of accountability about who operates the software behind a cookie banner.

At the same time, readers should be careful not to overread what approval means. IAB approval and Google certification are related but distinct programs, and registration signals participation in the TCF and technical conformance to its specifications rather than a determination that any deployment satisfies the law. A CMP can be approved and still be configured in ways that fall short of the ePrivacy Directive's national implementations governing storage and access on a device, or the GDPR standards for valid consent. Enforcement positions on the TCF have been contested in some EU jurisdictions, so legal compliance remains a separate assessment that depends on configuration, disclosures, and facts outside the scope of framework registration.

Who it's relevant to

Publishers and website operators
Publishers that monetize through programmatic advertising in the EEA and UK are directly affected, because a certified CMP integrated with the TCF is required for serving personalized ads through Google Ad Manager to those users as of the stated 16 January 2024 requirement. Selecting an approved CMP is therefore part of both their advertising operations and their consent workflow, though they remain responsible for configuring disclosures and consent capture to meet applicable law.
AdTech vendors and advertising partners
Vendors that participate in the TCF rely on standardized TC Strings produced by approved CMPs to determine what processing they may carry out. The consistency of these signals across approved CMPs allows partners to consume consent and preference data in a common format, making CMP approval relevant to how they design integrations.
Privacy and compliance professionals
Data protection officers, legal counsel, and compliance teams need to understand that IAB approval and Google certification signal participation and technical conformance, not legal compliance. They should assess whether a CMP's configuration, notices, and consent mechanisms meet the ePrivacy Directive's national implementations and GDPR consent standards, particularly given that enforcement positions on the TCF have been contested in some EU jurisdictions.
Web developers and implementation teams
Teams responsible for deploying cookie banners work with the CMP ID and TC String mechanics of an approved platform and need to ensure support for the relevant specifications, such as TCF v2.3, where required. Their implementation choices affect whether the underlying legal requirements are met, since approval alone does not guarantee a compliant deployment.

Inside CMP

CMP (Consent Management Platform)
The software layer that presents consent notices to users, captures their choices, and communicates those choices to vendors and tags. A CMP supports compliance workflows but does not by itself guarantee compliance, which depends on how it is configured and on underlying legal judgment.
IAB Europe TCF (Transparency and Consent Framework)
A voluntary industry framework maintained by IAB Europe that standardizes how consent and other legal bases for online advertising are collected, signaled, and passed between publishers and vendors. An 'IAB-approved' or TCF-registered CMP is one that IAB Europe has validated as conforming to the framework's technical and policy specifications.
TC String (Transparency and Consent String)
The encoded record generated by a TCF-compliant CMP that captures a user's consent and objection choices across registered purposes and vendors, and is shared with participants in the advertising supply chain.
Global Vendor List (GVL)
The registry of vendors and declared purposes that a TCF CMP references so users can be informed about, and make choices regarding, the specific third parties involved.
Purposes and legal bases
The standardized set of processing purposes (and the legal bases relied on, such as consent or, where used, legitimate interest) that the framework requires CMPs to surface to users. Whether a given legal basis is appropriate remains a legal question outside the CMP's technical role.
Approval and registration status
Confirmation that IAB Europe has registered the CMP against the current framework version. Approval reflects conformance with the framework's specifications, not a determination of lawfulness under the ePrivacy rules or the GDPR.

Common questions

Answers to the questions practitioners most commonly ask about CMP.

Does using an IAB-approved CMP mean my cookie consent is automatically compliant?
No. Registration or approval by the IAB indicates that a consent management platform conforms to the technical specifications of the Transparency and Consent Framework (TCF), not that its deployment on your site is lawful. Compliance depends on how you configure and implement the CMP, the categories of cookies and technologies you deploy, the information you provide, and whether the consent you collect meets the applicable legal standard. In most EU jurisdictions that means consent must be freely given, specific, informed, and unambiguous under the GDPR, alongside the ePrivacy requirements for placing or accessing information on a device. A tool can support these obligations but does not replace legal judgment or guarantee compliance.
Is the IAB Transparency and Consent Framework a legal requirement I have to adopt?
No. The TCF is an industry-developed standard, primarily aimed at the digital advertising ecosystem, that provides a common technical way to communicate consent signals between publishers, CMPs, and vendors. It is not itself a law and is not mandated by the GDPR, the ePrivacy Directive, the UK regime, or US state privacy laws. Organizations can manage consent without participating in the TCF. Where the framework is used, its own status has at times been the subject of regulatory scrutiny in the EU, so adopting it does not settle the question of legal compliance, which continues to depend on the applicable rules and how consent is actually obtained.
How do I choose an IAB-approved CMP for my website?
Selection generally involves confirming that the CMP appears on the relevant IAB registration or approved list for the version of the TCF you intend to use, and then assessing whether its features fit your legal and operational needs. Practical considerations typically include the geographic scope of your users, the cookie and vendor categories you rely on, whether the CMP supports the consent standards required in your jurisdictions, and how it handles logging and record-keeping. Because approval reflects technical conformance rather than lawful use in your specific context, the choice should be made together with privacy or legal input rather than on approval status alone. This entry does not endorse or evaluate specific vendors.
How should I configure an IAB-approved CMP to align with EU consent standards?
Configuration generally focuses on ensuring that non-essential cookies and similar technologies, such as analytics and advertising cookies, pixels, SDKs, or local storage, are not set before a clear affirmative action by the user. In most EU jurisdictions that means avoiding pre-ticked boxes, implied consent from continued browsing, and designs widely regarded as non-compliant. Configuration typically also covers the granularity of choices, the clarity of the information presented, and the ease of refusing or withdrawing consent. Specific settings depend on the cookies and vendors you use and on guidance from the relevant data protection authorities, which continues to evolve, so configuration choices should be reviewed against your own circumstances.
Can an IAB-approved CMP handle both EU opt-in consent and US opt-out requirements?
Many CMPs are built to support different regimes, but the requirements differ and should not be treated as interchangeable. EU and UK rules generally rely on prior opt-in consent for non-essential cookies, whereas several US state privacy laws, such as those in California, often rely on an opt-out model and may recognize signals such as Global Privacy Control. A CMP may be able to apply different logic based on a user's location or applicable law, but whether it does so correctly depends on how it is configured. Confirming that a platform supports the specific frameworks you are subject to, and testing that behavior, is a practical implementation step rather than an assumption.
What consent records should a CMP retain, and does approval affect this?
Consent logging and record-keeping are generally treated as part of demonstrating that valid consent was obtained, which is an accountability expectation under the GDPR in the EU and UK. A CMP typically stores information about the choices a user made and when, though the precise records that are adequate can depend on the applicable regime and any guidance from the relevant authority. IAB approval concerns technical conformance with the TCF and does not by itself determine whether your logging practices satisfy your legal obligations. What records are sufficient in a given case may involve facts and requirements beyond the scope of this definition, so this should be assessed with appropriate advice.

Common misconceptions

Using an IAB-approved CMP means your cookie consent is legally compliant.
Approval indicates conformance with the TCF's technical and policy specifications, not compliance with law. In most EU jurisdictions, lawfulness still depends on how the CMP is configured, whether consent is freely given, specific, informed, and unambiguous under the GDPR, and how the ePrivacy rules on storing or accessing information on a device are met. The framework itself has been the subject of regulatory scrutiny, so approval should not be treated as a definitive legal safeguard.
The TCF is an official legal standard imposed by regulators.
The TCF is a voluntary framework developed and maintained by IAB Europe for the advertising industry. It is not legislation, and adopting it neither replaces the applicable EU, UK, or US-state legal requirements nor automatically satisfies them.
A TCF CMP handles consent for every jurisdiction and every technology the same way.
The framework is oriented toward EU-style consent for online advertising and does not automatically address obligations under the UK regime or US state laws such as the CCPA and CPRA, which often rely on opt-out mechanisms and signals like Global Privacy Control. It also does not, on its own, resolve consent requirements for all technologies (pixels, local storage, SDKs, fingerprinting) unless those are properly declared and configured.

Best practices

Treat an IAB-approved CMP as a tool that supports compliance, and pair it with independent legal review of your consent notices, purposes, and vendor list rather than relying on approval status alone.
Confirm the CMP is registered against the current TCF version and keep the integration and Global Vendor List references up to date as the framework evolves.
Configure the CMP so consent is obtained through a clear affirmative action before non-essential cookies or similar technologies are set, avoiding pre-ticked boxes, implied consent from continued browsing, and cookie walls in EU contexts.
Verify that the CMP captures and retains records of consent choices (including the relevant TC String) to support consent-logging and record-keeping obligations, and confirm retention meets your accountability needs.
Assess whether a TCF-based setup adequately covers non-EU obligations, such as UK requirements and US state opt-out signals like Global Privacy Control, and supplement it where the framework does not address them.
Review how legal bases such as legitimate interest are presented and used within the framework, and document the reasoning, since the appropriateness of a legal basis is a legal judgment the CMP does not make for you.
Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide