Guides

How to choose a consent management platform

Every option here can show a cookie banner — what actually differs is IAB TCF support, pricing basis, and how deep the legal-document bundle goes.

A consent management platform (CMP) scans a site's cookies and tracking scripts, shows visitors a banner asking for their consent, and blocks non-essential scripts until they answer. Every tool in this category does that. The differences that actually matter when you're paying for one are narrower and more specific: whether the tier you can afford includes IAB TCF certification, whether pricing is based on domains, pageviews or sessions, and whether the vendor bundles generated legal documents alongside the banner or sells just the consent mechanism.

You need one of these if you run any site that sets non-essential cookies or scripts and has visitors in a jurisdiction covered by GDPR, CCPA or a similar regime — which, for a site with any meaningful traffic, is effectively every site. You don't need the more advanced (and more expensive) tiers if you don't sell programmatic advertising inventory through the IAB ecosystem; TCF support is specifically an ad-tech requirement, not a general compliance one.

IAB TCF is the feature that sorts the cheap tiers from the real ones

If you run programmatic display advertising or work with ad-tech partners who require it, IAB TCF (Transparency & Consent Framework) support is not optional, and it is consistently the feature vendors hold back from free and entry tiers. Cookiebot includes TCF 2.3 only on Premium plans; CookieYes requires its Pro or Ultimate tier; Termly requires Pro+ or above; iubenda includes TCF 2.2 on all paid tiers, which is unusual generosity for the category. Complianz and Didomi both state TCF support more broadly across their plans. If ad-tech compliance is the reason you're buying a CMP at all, check this one line item before comparing anything else — a plan that looks cheaper on the surface may not include the feature you actually need.

Platform-native versus universal

Complianz is built specifically for WordPress, self-hosted as a plugin rather than a universal script embed, and priced per number of sites covered per year rather than by traffic. Every other tool here — Cookiebot, CookieYes, Didomi, iubenda, Termly, Usercentrics — is a cloud script embed that works on any platform, with plugins for common CMS systems as a convenience rather than the whole architecture. If your whole footprint is WordPress, a native plugin like Complianz integrates more tightly and avoids a third-party script call; if you run multiple platforms or a custom stack, a universal embed is the only realistic option.

iubenda and Termly both pair the consent mechanism with generated privacy policies, terms and conditions, and cookie policies from the same vendor, useful if you'd otherwise need a separate legal-document generator or outside counsel for boilerplate documents. Complianz does the same, generating a privacy statement, disclaimer and processing agreement as part of every tier including the free plugin. Cookiebot, CookieYes, Didomi and Usercentrics focus on the consent mechanism itself without a document-generation bundle. Neither approach is more "compliant" — a generated privacy policy is not a substitute for legal review on anything beyond the basics, and the bundle mainly saves a separate subscription for smaller sites.

Who owns whom, and what that means for the product line

Usercentrics owns Cookiebot: Usercentrics is positioned for larger sites needing granular geolocation rules, multi-domain management and brand customization, while Cookiebot stays the lighter-weight product for smaller sites, under the same parent company. This matters if you're choosing between what looks like two competitors — you may be choosing between two tiers of the same company's roadmap rather than genuinely different technology. Didomi also owns Addingwell, a server-side tagging product built so consent state travels through server-side pipelines, worth knowing if you're already moving toward cookieless server-side tracking.

How pricing scales

There is no single basis across this category. Complianz and Termly price per website per year, independent of traffic. Cookiebot and iubenda price by pageview or subpage volume scanned. CookieYes combines a pageview allowance with a per-1,000-pageview overage fee once you exceed it. Usercentrics bills by monthly visitor sessions rather than pageviews. Didomi does not publish self-serve figures at all. Match the pricing basis to your actual traffic pattern — a high-pageview, low-session site (heavy single-visit browsing) costs very differently under a pageview model than a session model.

A shortlist by situation

  • You run WordPress and want a native plugin, not a third-party script. Complianz.
  • You want automatic cookie scanning with the least manual setup. Cookiebot or CookieYes.
  • You need consent plus generated legal documents from one vendor. iubenda or Termly.
  • You operate across web, app and connected TV and want one vendor for all three. Usercentrics.
  • You need consent mapped explicitly to multiple regulations across regions, plus server-side tagging. Didomi.
  • Budget is tight and you just need a working banner with Google Consent Mode. Start with the free tiers of Cookiebot, CookieYes or Termly, and upgrade only when TCF or higher pageview volume forces it.

Questions to ask vendors or in a trial

  1. Does our required tier actually include IAB TCF, or is that a higher-tier feature?
  2. Is pricing based on domains, pageviews, or sessions, and how is overage billed?
  3. Does the tool support Google Consent Mode v2 (basic and advanced), and at which tier?
  4. How is the cookie/script scan kept current as our site adds new tracking tags?
  5. If we're already on a related product from the same parent company, what does upgrading actually change?

Common mistakes

Buying an entry tier and discovering TCF isn't included is the single most common and most expensive mistake in this category — verify it explicitly rather than assuming any "consent management platform" includes ad-tech-grade compliance by default. A second mistake is treating a generated privacy policy as legal sign-off; it covers the common cases, not your specific data flows. A third is picking a pricing basis mismatched to your traffic shape — a pageview-billed tool can cost far more than a session-billed one for a site with many pageviews per visit, or the reverse for a site with many short single-page visits.

Two comparisons cover specific pairs: Cookiebot vs Usercentrics and Complianz vs Termly. See every tool in this category for the full list.

Related tools

Terms used in this guide

Latest on this topic