Check explainer
Cookie banner / CMP
A cookie banner is the visible half of the consent flow, no CMP means no documented opt-in.
- critical
- note
- ok
What we check
Detects 11 common cookie banners: OneTrust, Usercentrics, Cookiebot, Didomi, and more.
Why it matters
A cookie banner is the visible half of the consent flow, no CMP means no documented opt-in.
Common causes
- There simply is no CMP, and the tracking has run without a consent layer for years.
- The CMP only loads on the homepage; campaign landing pages or a separate shop run without a banner.
- A self-built banner without a CMP backend: visible yes, but with no audit trail and no tag-blocking behind it.
- After a relaunch the CMP script no longer loads from an old template, and nobody notices because the banner cookie still sits in their own browser.
- The CMP is loaded through the tag manager and thereby loses exactly the window in which it should block tags.
How to fix it
Integrate a CMP (Usercentrics, Cookiebot, consentmanager) and enable tag-blocking. The CMP script belongs directly in the HTML before all tracking snippets, not in the tag manager. For Usercentrics setups: how the chain continues into the server container is covered in Usercentrics + Server-Side GTM; we run the platform as a certified partner.
What does a failing Cookie banner / CMP finding mean?
A cookie banner is the visible half of the consent flow, no CMP means no documented opt-in. Integrate a CMP (Usercentrics, Cookiebot, consentmanager) and enable tag-blocking.
How do you fix Cookie banner / CMP?
Integrate a CMP (Usercentrics, Cookiebot, consentmanager) and enable tag-blocking.