Consent

Cookiebot, Usercentrics or custom: does your CMP choice matter?

Cookiebot, Usercentrics or custom: does your CMP choice matter?

Rhobin

July 30, 2026

7 min read

Your CMP choice settles a short list: whether it is on Google's certified list, which only binds sites serving Google publisher ads, whether it can load tags before the dialog appears, and whether it covers your domains and regions. It does not decide how much data you keep, because the cookie categorisation, the reject option and the consent state reaching your platforms stay your configuration on any vendor.

The symptom

Three tabs open. Cookiebot's pricing, Usercentrics' pricing, and a document costing out a banner built in house. The client wants a decision this week, and nobody can say what changes depending on which wins.

The material you read while deciding makes it worse. Both brands publish their own comparison pages, and the roundups score on language counts and detected cookies. None of them opens with the detail that matters most: Cookiebot's parent company Cybot and Usercentrics merged operations in September 2021, Usercentrics aimed at enterprise and Cookiebot at plug-and-play compliance for smaller businesses. Two of your three options come from one company.

Meanwhile the client account keeps losing whatever it was losing. The decision you are stuck on takes an afternoon. The decision that determines what the client sees in reporting has not been put in front of you yet.

Why the comparison never settles it

Because a feature table cannot separate the two halves of this decision. One is what a vendor decides for you. The other stays yours whoever's script sits on the page, and that is the half your numbers come from.

Where the vendor does matter

  • Does the client's site serve Google publisher ads? The one place a vendor list binds you. Google states that partners using its publisher products, AdSense, Ad Manager or AdMob, must use a CMP that has been certified by Google and integrated with the IAB Europe Transparency and Consent Framework to serve personalised ads, since 16 January 2024 in the EEA and the UK and 31 July 2024 in Switzerland.

  • On the advertiser side, nothing binds you. For measurement, ad personalisation and remarketing, Google requires that you collect consent from users based in the EEA and share those signals through the ad_user_data and ad_personalization parameters. The same page treats three routes as acceptable: a certified platform, your own banner with consent mode implemented, or a custom banner with the signals implemented yourself. Most agency clients sit here.

  • Can the platform express what you need? All four consent signals, loading tags before the dialog rather than only after acceptance, per-region rule sets, and the domains and languages the client has. Products differ here, and you can check it in an hour.

What that list does not include is any assurance about your setup. On the same page where Google sets that requirement, it also says plainly: "Google does not check CMPs for full compliance with the TCF or applicable privacy laws." The separate CMP Partner Program badge, which both Cookiebot and Usercentrics carry, is awarded for integrating with consent mode and Google Tag Manager. Both describe the tool. Neither describes your implementation.

The part that stays yours

The EDPB's Cookie Banner Taskforce report, adopted in January 2023, lists the practices European authorities examined after a wave of complaints. Read it as an agency and one thing stands out: every item is a choice someone made in a dashboard, and those dashboards belong to platforms on Google's certified list.

  • No reject option on any layer carrying a consent button. A vast majority of authorities treated that as an infringement, since consent requires a positive action.

  • Pre-ticked boxes behind the settings button, which the taskforce confirmed do not produce valid consent.

  • A reject option offered only as a link buried in a paragraph, without enough visual support to draw an average user's attention.

  • Contrast on the alternative button so low the text is unreadable. On colour generally the taskforce was careful: no general standard can be imposed, and each banner needs a case-by-case assessment.

Then the item no product takes off your hands. Discussing the tools that scan a site and list its cookies, the taskforce recorded that "the only available tools do not allow to check the nature of the cookies but only to list the cookies placed". The scanner enumerates. Deciding which cookies are strictly necessary, and proving it to an authority, is the website owner's job. The report is equally direct that the legal basis for placing or reading cookies cannot be legitimate interest, and that withdrawal must be possible at any time and as easy as giving consent, with no specific mechanism imposed.

One more thing no vendor sells as a feature. For the placement of cookies, the taskforce confirmed the applicable framework is the national law transposing the ePrivacy Directive, and that the GDPR one-stop-shop does not apply to it. So "compliant in Europe" is not one condition a product can satisfy. It depends on which national implementations your client's traffic touches. A CMP gives you the mechanism, never the conclusion.

And the data side works the same way

The measurement outcome turns on how the platform is wired, not which one it is. Google's own documentation is the proof: in basic consent mode "no data is sent before a user consents, not even the default consent status", and GA4's behavioural modelling prerequisites require tags to load before the dialog and in all cases, plus published volume thresholds, and even then say meeting them "doesn't guarantee eligibility". Those are settings, not products. Across the accounts we audit, 15 to 30% of conversions go consistently uncaptured, and how much of that pool a consent setup argues over is decided here rather than by the logo on the banner. We put numbers on it in how much data your cookie banner is throwing away.

What good looks like

Treat the vendor question as procurement and time-box it. Does the client serve Google publisher ads, which decides the shortlist outright. Does the platform support all four consent signals and loading before the dialog. Does it cover the domains, languages and regional rules the client has. What does it cost at real traffic. Building your own is legitimate on the advertiser side, and means owning the signals, the categorisation and the regional logic permanently. Answer those, sign, move on.

Then spend the time you saved on the work that carries the result: a cookie categorisation justified line by line and written down so it survives the client's lawyer, a reject option at the same level as accept with nothing pre-ticked, withdrawal reachable at any time, and the consent state actually arriving at your server container and your ad platforms, checked against what those platforms report receiving rather than what the dashboard claims it sent.

That is the work Archon Consent does, on the platform the client already has. We do not ask agencies to migrate, because the migration was never what held the numbers back. Done properly, the consent layer stops undercutting the 15 to 40% recovery a server-side setup should deliver. For one performance agency: 38% of client traffic affected by tracking prevention back into measurement, measured conversions up 26% on average, 14 hours per project returned to the campaign team.

Frequently asked

So is Cookiebot or Usercentrics the better choice?

One owner since 2021, two segments: Usercentrics at enterprise, Cookiebot at plug-and-play for smaller businesses. Start with which one the client is, then run the procurement list above. Neither decides your consent rate or your recovered conversions, the configuration does.

Should we just build our own banner?

On the advertiser side Google treats a self-built banner with the consent signals implemented as an acceptable route, so it is a real option. The trade is permanent ownership: the signals, the categorisation, the regional rule sets and every future change to them. If the client's site serves Google publisher ads in the EEA, the UK or Switzerland, the option is closed, because a certified platform integrated with the TCF is required there.

Our CMP is Google-certified. Does that make the client compliant?

No, and Google says so on the page that sets the requirement: it does not check platforms for full compliance with the TCF or applicable privacy laws. Certification is about the tool integrating correctly. Whether the banner obtains valid consent, and whether the cookies behind it are categorised honestly, is assessed against your configuration.

Is one platform more compliant across the whole EU than another?

This is the honest "it depends", and it does not depend on the vendor. The taskforce confirmed the placement of cookies falls under national law transposing the ePrivacy Directive and that the one-stop-shop does not apply, so requirements shift with the countries your client's traffic comes from. What you can compare is whether a platform lets you express per-region rules cleanly. The judgment underneath stays yours, the same way the server-side vendor question turned out to be a procurement detail in Stape versus Taggrs.

If you would rather have an answer for one client account than another feature matrix, request a free tracking audit and we will check what the current consent setup is really sending, whichever platform is behind it.

© 2026 Archon LabsPrivacyTermsBuilt on unsampled data.