Just over half of the consent management platforms checked in IAB Europe’s most recent compliance audit failed a basic test: letting a user withdraw consent as easily as they gave it. The 2025 TCF Compliance Report, published in March 2026, found 53% of audited CMPs lacked a working withdrawal mechanism, and 80% of audits failed the underlying TC string storage disclosure check. The platform market built to solve consent compliance is, by its own governing body’s numbers, still failing the test it exists to pass.
That gap between what a CMP promises and what an audit finds is the story behind every number below: market size, vendor registrations, enforcement activity, and the consolidation reshaping who sells this software.
How many CMPs actually pass a compliance audit?
Most fail at least one check. IAB Europe’s 2025 TCF Compliance Report, covering audits run between January and December 2025, found that 53% of registered CMPs did not provide a functioning consent withdrawal option, a requirement under both the TCF policy and GDPR’s principle that withdrawal must be as easy as giving consent. TC string storage disclosure, the technical record of what a user actually agreed to, failed in 80% of audits. About 14% of CMPs were still serving an outdated Global Vendor List, meaning the list of ad tech vendors a user is asked to consent to was already stale.
| Audit check | Failure rate | Pass rate |
|---|---|---|
| TC string storage disclosed correctly | 80% | 20% |
| Working consent withdrawal option | 53% | 47% |
| Current Global Vendor List version | ~14% | ~86% |
Source: IAB Europe 2025 TCF Compliance Report, as reported by PPC Land, March 2026.
Figure 1: Share of audited CMPs that failed each compliance check in 2025. Source: IAB Europe 2025 TCF Compliance Report.
A cookie policy tells a visitor what a site collects, but it cannot fix a CMP that buries the withdraw option or never renders it at all. Pairing a compliant CMP with a current cookie policy generator closes half of that gap; fixing the underlying withdrawal flow is on the CMP vendor.
The audit numbers say the same thing the market has been slow to admit: registering under the TCF is not the same as passing an audit against it.
How big is the consent management platform market in 2026?
Analyst estimates cluster in the low single-digit billions, though the exact figure depends on which segments a firm counts as “consent management.” Mordor Intelligence, updated January 2026, values the market at USD 0.91 billion in 2025, growing to USD 1.07 billion in 2026 and USD 2.34 billion by 2031, a 17.05% CAGR. Grand View Research puts 2025 at a similar USD 1.0 billion, reaching USD 1.2 billion in 2026 and USD 2.8 billion by 2033.
| Research firm | 2026 estimate | Longer-term forecast | CAGR |
|---|---|---|---|
| Mordor Intelligence | USD 1.07 billion | USD 2.34 billion by 2031 | 17.05% |
| Grand View Research | USD 1.2 billion | USD 2.8 billion by 2033 | 13.1% |
Warning
Market-size figures for “consent management platforms” vary by publisher because there is no standard industry definition. Some reports fold in broader privacy management software (data subject rights, vendor risk, consent alongside cookie banners); others count cookie banner tooling alone. Treat any single figure as directional, and check which segments a report actually covers before citing it as the market size.
Figure 2: Consent management market size trend. Source: Mordor Intelligence, updated January 2026.
Both firms agree on the direction even where they disagree on the number: the market roughly doubles in size over the next five to seven years, driven by state privacy law expansion in the US and continued GDPR enforcement in the EU.
How many vendors and CMPs are registered with IAB Europe’s TCF?
Registration keeps growing faster than compliance does. 953 vendors and 181 CMPs were registered under the Transparency and Consent Framework as of December 31, 2025, according to IAB Europe’s own compliance report. That is up 7.7% from 885 vendors and up 2.3% from 177 CMPs a year earlier, with 154 new vendors and 19 new CMPs joining the framework during 2025 alone.
Registration is a floor, not a ceiling. A CMP has to actively maintain its listing, keep its vendor list current, and pass the checks described above to stay in good standing.
Figure 3: The compliance path a registered CMP has to clear, built from IAB Europe’s 2025 audit categories.
Enforcement moved with registration growth. CMP enforcement procedures rose from 40 in 2024 to 51 in 2025, a 27.5% increase, and the framework recorded its first temporary CMP suspension since IAB Europe started publishing this report. Vendor-side enforcement grew far faster, from 269 procedures in 2024 to 587 in 2025, a 118.2% jump, with vendor suspensions up 78.3% over the same period.
Who are the leading CMP vendors, and is the market consolidating?
The vendor landscape is fragmenting and consolidating at the same time. OneTrust, the largest single vendor by enterprise reach, states it is used by over half of the Fortune 500 and runs an AI-focused governance platform out of Atlanta with offices in 13 countries. Usercentrics (which owns Cookiebot), TrustArc, Didomi, and Osano compete for the mid-market and privacy-first segment, while a long tail of WordPress and Shopify-native plugins covers small business sites that never touch an enterprise CMP at all.
2025 brought the clearest consolidation move in the sector: Didomi acquired rival CMP Sourcepoint in July 2025, backed by investment partner Marlin Equity Partners, three months after Didomi bought Addingwell, a server-side tracking infrastructure company, in April 2025. Financial terms of neither deal were disclosed. The stated goal, per the companies’ joint announcement, was combining Didomi’s consent management with Sourcepoint’s infrastructure to serve a single privacy and compliance stack.
Figure 4: Software still dominates the component split, though the services share (implementation, audits, managed compliance) is growing faster. Source: Mordor Intelligence.
North America holds the largest regional revenue share at 36.20% in 2025, while Asia-Pacific is the fastest-growing region at a projected 17.4% CAGR through 2031, tracking the spread of new state and national privacy laws outside the EU.
How did Google’s Consent Mode v2 enforcement change the CMP landscape in 2025?
Google began fully enforcing Consent Mode v2 for European Economic Area traffic on July 21, 2025, per its own support documentation. Sites that had not implemented the required consent parameters through a CMP lost access to certain Google Ads and Analytics measurement features for EEA visitors on that date. Third-party analysts reported steep drops in EEA conversion and remarketing data for non-compliant sites in the days that followed; Google itself has not published an official figure for the scale of that impact, so treat any specific percentage circulating online as an outside estimate, not a Google-confirmed number.
The practical effect on the CMP market was direct: a site’s Consent Mode implementation runs through whichever CMP it uses, so enforcement turned CMP configuration from a compliance nice-to-have into a measurement dependency. That shift shows up in the timeline of the sector’s biggest moves this year.
Figure 5: Key framework, enforcement, and consolidation milestones. Sources: IAB Europe, Google, PR Newswire.
The Bottom Line
The consent management platform market is growing at a double-digit CAGR by every analyst estimate, and the number of registered vendors and CMPs keeps climbing year over year. None of that growth has closed the compliance gap: 53% of audited CMPs still lack a working consent withdrawal mechanism, and 80% fail the underlying disclosure check that is supposed to prove what a user actually agreed to. Buying or registering a CMP is not the same as running one that passes an audit. Site owners should treat CMP selection as an ongoing compliance decision, not a one-time setup task, and pair it with a cookie policy that is kept current as vendors, laws, and enforcement all keep moving.
Frequently Asked Questions
What percentage of consent management platforms pass a compliance audit? In IAB Europe’s 2025 TCF Compliance Report, 53% of audited CMPs lacked a working consent withdrawal mechanism and 80% of audits failed the TC string storage disclosure check. About 14% were still running an outdated Global Vendor List.
How big is the consent management platform market in 2026? Mordor Intelligence values the consent management market at USD 1.07 billion in 2026, growing to USD 2.34 billion by 2031 at a 17.05% CAGR. Grand View Research puts 2026 at a similar USD 1.2 billion, reaching USD 2.8 billion by 2033.
How many vendors and CMPs are registered under IAB Europe’s TCF? 953 vendors and 181 CMPs were registered under the Transparency and Consent Framework as of December 31, 2025, up 7.7% and 2.3% respectively from 885 vendors and 177 CMPs a year earlier, per IAB Europe’s own compliance report.
Is the CMP market consolidating? Yes. Didomi acquired rival CMP Sourcepoint in July 2025, months after acquiring server-side tracking company Addingwell in April 2025. OneTrust says it is used by over half of the Fortune 500, making it the largest single vendor by enterprise reach.
Sources and References
- PPC Land. (2026). “TCF Enforcement More Than Doubled in 2025, IAB Europe Report Shows.” Reporting on IAB Europe’s 2025 TCF Compliance Report, published March 2026.
- IAB Europe. Transparency and Consent Framework, official framework page and version history.
- Mordor Intelligence. “Consent Management Market Size and Share Analysis.” Updated January 13, 2026.
- Grand View Research. “Consent Management Market Size, Share Report, 2026-2033.”
- PR Newswire. (2025). “Didomi and Sourcepoint Join Forces to Build the Future of Privacy Technology.” July 8, 2025.
- Google. “Updates to Consent Mode for Traffic in the European Economic Area (EEA).” Official support documentation.
- OneTrust. Company overview and self-reported customer statistics.
Note: All figures verified as of August 2026. CMP market size and vendor registration figures are refreshed at least twice a year. The Google Consent Mode impact figures in this article are third-party estimates and should be re-checked against Google’s own published data before each refresh.