Checklist

Does a CMP attestation replace a cookie audit?

Start a free audit

CMP attestation and SOC-style badges are vendor claims. Fresh and Reject still record cookies and hosts on your URL. Not a second hub. Not legal advice.

In brief

A CMP attestation does not replace a cookie audit on the live storefront. An attestation, a certification badge, or a SOC-style badge is a vendor or program claim. A cookie audit records cookies, storage, and hosts on labeled Fresh and Reject visits to your URL. Keep both artifacts. A free US-baseline scan is not an EU or California legal conclusion. This FAQ is not a second cookie-audit hub, not a privacy-policy rewrite, and not legal advice.

Not legal advice

This FAQ explains how to observe whether a CMP vendor attestation, a certification badge, or a SOC-style badge replaces a Fresh and Reject cookie audit. It is not legal advice, not a SOC, ISO, or attestation drafting guide, not counsel on whether any attestation meets a legal duty, and not a GDPR, ePrivacy, CPRA, or other compliance certificate. ConsentProbe reports are technical observations of what fired under labeled visits. They do not say what counsel would allow. Observation is not counsel permission.

Last updated September 29, 2026. The CMP claims page owns banner UI versus runtime. The audit-versus-banner page owns the banner comparison. The before-Accept audit owns the protocol. The evidence pack owns the file you hand over. The testing hub owns which test is next. The privacy-policy page owns written policy sentences. This FAQ only compares attestation claims with a runtime audit. It does not open a second hub, and it does not rewrite a privacy policy.

Short answer

A CMP attestation does not replace a cookie audit as a storefront test. An attestation, a certification badge, or a SOC-style badge is what a vendor or program asserts about controls or posture. A cookie audit records cookies, storage, and hosts on labeled Fresh and Reject visits to your URL.

Treat the badge or PDF as a claim. Falsify storefront behavior with Fresh versus Reject. CMP UI claims and privacy-policy sentences use the same pattern on their own pages. Open the hub for which test is next, and the evidence pack when you hand findings to engineering or counsel. This FAQ is not a second cookie-audit hub, not a privacy-policy rewrite, and not legal advice. Observation is not counsel permission.

Attestation, audit, policy, and banner

Prefer a sentence such as Fresh still shows host X despite the attestation claim. Leave the legal reading with counsel. This page does not redefine SOC and does not invent a certificate scope.

Vendor claims and the storefront check that still uses Fresh and Reject.
ArtifactWhat it usually assertsWhat you still check on the storefrontWhere the longer page lives
CMP attestation, certification badge, or SOC-style badgeA vendor or program claim about controls or postureCookies and hosts on Fresh and Reject for your URLCMP claims versus runtime, and audit versus banner
Cookie auditRuntime cookies, storage, and Network on labeled visitsThe same labeled visits, kept as the auditBefore-Accept audit and the evidence pack
Privacy policy cookie sentencesWritten business claimsThe same Fresh and Reject pack read against the policy textCookie audit versus privacy policy claims
CMP banner UI that says saved or analytics offA UI claimMatching Network on RejectCMP claims versus runtime, and Reject leftovers

Which artifact when

Keep the PDF if a vendor sent one. Still run Fresh and Reject. A badge on a sales deck does not capture Network rows on your URL.

  1. When a vendor sends an attestation PDF or a certification badge, keep it as vendor-claim evidence and still run Fresh and Reject on the live URL.
  2. When a banner or a sales deck says CMP certification means tags are blocked, falsify that with Fresh and Reject. Open the Reject leftovers guide when Reject still shows a host.
  3. When the privacy policy also says marketing waits for Accept, compare the same pack with the policy text.
  4. Write one finding sentence per unexpected match, such as the same ad host on Fresh as after Accept, or an analytics host still present on Reject.
  5. Open the evidence pack when you hand the rows to engineering or counsel. Open the hub for which test is next.

When an attestation PDF is not a Network row

Reading an attestation PDF does not capture your storefront Network rows. ConsentProbe runs Fresh and Reject on the storefront URL. Each finding stays tied to a request, a cookie, or a screenshot.

Use the free US-baseline visit when you want the report format. Use paid EU or California scenarios when those regions are the claims. The free versus paid guide draws that line. ConsentProbe does not issue or replace CMP attestations, does not install a CMP, and does not issue a certificate. A free US-baseline scan is not an EU or California legal conclusion.

FAQ

Does a CMP attestation replace a cookie audit?

No, as a storefront test. An attestation is a vendor or program claim. A cookie audit is labeled runtime evidence on your URL.

If the CMP sent a certification badge, can I skip Fresh and Reject?

Not when you need to see what fired on your storefront. Run the before-Accept audit, and the Reject leftovers guide when Reject still shows a host.

Is a SOC-style report the same artifact as a cookie audit?

This page does not equate them. They are different artifacts. Still verify cookies and hosts on Fresh and Reject.

How is this different from CMP UI claims versus runtime?

The CMP claims page covers banner and UI claims. This FAQ covers attestation, certification-badge, and SOC-style marketing claims.

Is this a second cookie-audit hub?

No. The hub stays the testing hub. This FAQ only answers attestation versus audit, and it is not a privacy-policy rewrite.

Is this legal advice?

No. These are technical observations. It is not legal advice. Observation is not counsel permission. ConsentProbe does not replace counsel, and it does not install a CMP.

Limits of this page

This FAQ says a CMP attestation, a certification badge, and a SOC-style badge are claims, and a cookie audit is labeled runtime evidence. It is not legal advice, not a second cookie-audit hub, and not a privacy-policy rewrite. Observation is not counsel permission. ConsentProbe does not issue or replace attestations, and it does not install a CMP. A free US-baseline scan is not an EU or California legal conclusion.

Related guides

Open the CMP claims page for banner text, the audit-versus-banner page for the banner comparison, the before-Accept audit for the protocol, the evidence pack for the handoff file, the hub for which test is next, and the privacy-policy page for written cookie sentences.

Sources

These links cover the platform and regulatory context used in this guide. Applicability still depends on the organization and jurisdiction.

Save a US-baseline technical record

After a DIY check, run a free US-baseline audit: one browser visit outside California, with cookies, requests, and screenshots stored as evidence. That visit does not run EU reject/accept or California GPC. EU, California, and Global 2 audits can be purchased from Billing after sign-in.

Does CMP attestation replace a cookie audit? | ConsentProbe