All Blog Posts

Introducing the Cookiebot Configuration Health Checker: Find Setup Gaps Before They Become Problems

Close
Read time
3 mins
Published
Oct 7, 2026
Share

  • The Configuration Health Checker is a self-service tool in the Cookiebot Admin that checks your live CMP setup for common configuration issues.
  • It checks your setup against core rules and returns a Pass, Warn, or Fail status for each, plus an overall risk score.
  • The tool is currently in Beta and currently covers the GDPR ruleset, with other frameworks planned, like the CCPA/CPRA.
  • You can re-run the check at any time, so the score always reflects your current setup.
  • It's a helper tool for spotting configuration gaps, not a substitute for legal advice.

Most Cookiebot™ customers set up their CMP once and may only rarely revisit it. That's understandable. Configuration options span consent methods, cookie category defaults, button design, and more. But small settings changes can happen without anyone noticing, whether from a plugin update, a new team member’s access, or a setting flipped during testing and never flipped back.

The trouble is that these small gaps carry real weight. A pre-checked marketing category, an implicit-consent setting left on, or a reject button that's harder to find than the accept button are the kinds of details regulators and site visitors all notice. If you don't have a dedicated legal or compliance team checking your setup regularly, it's easy for a gap like this to sit unnoticed for months.

That's the problem that Cookiebot’s new Configuration Health Checker is built to help with.

What the Configuration Health Checker Does

The Configuration Health Checker analyzes your live CMP configuration and flags setup issues automatically, with no manual trigger needed. You'll find it in the Cookiebot Admin Interface, under Cookies & Reports → Configuration Health Checker.

It checks your setup against 11 rules covering four areas:

How consent is collected

For example, whether the setup incorrectly treats implicit consent, scrolling, or page refresh as valid consent.

Cookie category defaults

Whether marketing, preferences, and statistics categories are pre-checked instead of requiring an opt-in.

Banner and button design

Whether the reject option is visible and whether button colors give equal weight to accepting and declining.

Ongoing consent management

Whether the consent banner resurfaces over time and whether visitors can reopen their preferences later.

Each rule comes back as Pass, Warn, or Fail. Expand a Warn or Fail and you'll see a plain-language explanation of why the rule matters and a suggested fix, along with where in your settings to make the change.

At the top of the page, an overall risk score rolls all results into a single Low, Medium, or High reading, based on the number and severity of issues found. If you make a change, click Re-run check and the score updates immediately, so you always know where your current setup stands, not where it stood last time someone looked.

Who It's For, and What It Isn't

The Configuration Health Checker is built for the way many Cookiebot customers actually work: managing your own CMP setup, likely without a dedicated legal or compliance function checking it for you. If that's your situation, the tool gives you a fast, second-pair-of-eyes read on your configuration, in your own dashboard, without waiting for anyone else.

It is not a privacy compliance audit or legal sign-off. It benchmarks your setup against common best practices for the selected legislation. It doesn't evaluate your cookie declarations, your tracking behavior, or the broader legal context your site operates in, and a clean Pass across all rules doesn't mean your site is fully compliant with data protection law. 

Treat it as a helper that flags where to look more closely, not as the final word. For a definitive read on your obligations, talk to qualified legal counsel or a data privacy professional.

What to Expect Right Now

A few things worth knowing while the Configuration Health Checker is in Beta:

  • The current rule set is built around the GDPR. Other legislation isn't part of the check just yet.
  • Warnings and fails can't be dismissed or hidden from the interface. Whether a flagged item is genuinely relevant to your situation is your call to make, and the tool is designed to surface the question rather than answer it for you.

More Frameworks Are on the Roadmap

This first version intentionally covers one regulation (GDPR) and core rules so the team can validate the approach before expanding it. Additional frameworks and rule sets are on the roadmap. 

Feedback from customers trying it during Beta is one of the main things shaping what comes next. If you try it and something's confusing, missing, or just plain wrong, that feedback goes somewhere useful.

Want a walkthrough of all 11 rules and the reasoning behind each one? Read the full Configuration Health Checker help article.