Published September 23, 2026
Switching CMP vendors: a migration checklist for publishers
Switching consent vendors is the riskiest week in a publisher's ad-tech calendar. Get the migration wrong and consent strings break, TCF signals go missing from bid requests, and programmatic revenue dips for reasons nobody can immediately explain. Work through this checklist before the cutover.
Export your consent records first
Before touching anything, export the existing consent records: who consented, to what, and when. Some jurisdictions expect continuity of proof, and if the new vendor's import has a gap, you want the old data available rather than discovering the gap during an audit.
Map the vendor list to TCF v2.2
The new CMP must carry the same purposes, special features, and vendor list, and it must be registered with the IAB Transparency and Consent Framework. Confirm the new CMP ID propagates correctly in the consent string and that the string decodes to the purposes your ad stack expects. A string that looks valid but carries the wrong purposes will silently suppress demand.
Audit every ad-tech integration
Prebid, Google Ad Manager, and each SSP adapter read the consent signal differently. Test every bidder under three states: full accept, full reject, and partial consent with legitimate interest only. Pay special attention to bidders that were added as custom adapters, since those are the ones most likely to parse the string with their own assumptions.
Run old and new in parallel
Do not cut over in one step. Run the new CMP in shadow mode: it collects and stores consent while the old vendor still serves the string to the ad stack. Compare consent rates and string validity between the two for several days of real traffic, then cut over on a quiet traffic day with engineering on standby.
Watch revenue for two weeks after
Track consent rate, TCF string validation errors, and bid density per pageview daily for two weeks. A slow decline in bid density often means a subset of traffic is sending malformed or missing signals. If the numbers move the wrong way, roll back to the old vendor the same day: a prolonged dip costs more than the migration saves.
How to compare consent rates fairly
Do not compare the new vendor's consent rate to the old vendor's lifetime average. Compare the same traffic slice over the same weekdays, because consent rates vary with traffic mix: weekend mobile traffic opts in differently than weekday desktop traffic.
Watch the reject rate as closely as the accept rate. A new banner that is easier to dismiss can look like it has a healthy accept rate while quietly increasing rejects, which is what actually moves ad revenue. Segment by device and geography before concluding anything.
What to do with the old vendor's data
Keep read access to the old vendor's dashboard for at least six months. Discrepancies surface late: a quarterly business review, an advertiser asking about a campaign from two months ago, or a privacy request that references the old consent records.
When you finally close the old account, export everything first and confirm the export is complete. Consent records are the kind of data you only miss when you need them, and by then the vendor has no obligation to help you retrieve them.
Tell your demand partners in advance
Give your top SSPs and direct advertisers a heads-up with the migration date and the new CMP ID. Partners who see an unfamiliar CMP ID in bid requests sometimes throttle demand defensively, and a short email beforehand prevents a week of confused troubleshooting on both sides.
Keep a single migration log with timestamps for each step: export, shadow mode start, cutover, old vendor shutdown. When revenue questions come up later, that log is the difference between a confident answer and a guessing session.