This feature is currently in BETA and is not yet available to all Cookiebot Admin Users. We intend to roll out the feature broadly once it is ready for general availability.
What is the Configuration Health Checker?
The Configuration Health Checker is a built-in tool in your Cookiebot Admin that analyses your CMP configuration and identifies gaps against best practices for your chosen privacy legislation. It gives you an instant risk assessment score and highlights specific areas of your setup that may need another review.
Disclaimer: The Configuration Health Checker is a helper tool designed to benchmark your CMP configuration against recognised best practices. It does not constitute legal advice and should not be relied upon as a definitive assessment of your legal compliance obligations. Cookiebot™ makes no warranties regarding the completeness or accuracy of the results. Always consult a qualified legal professional for guidance specific to your situation.
Where to find it?
The Configuration Health Checker is available in your Cookiebot Admin under:
Cookies & Reports → Configuration Health Checker.
How it works
When you open the Configuration Health Checker tab, it automatically runs a check against your current CMP configuration. It evaluates a set of rules based on the selected legislation (currently GDPR) and returns one of three statuses for each rule:
| Status | Meaning |
| ✅ PASS | Your configuration meets this requirement. No immediate risk based on selected legislation check. |
| ⚠️ WARN | Your CMP configuration may require your attention. Please assess whether this setting has an immediate impact on your context. |
| ❌ FAIL | We've identified high-risk settings in your CMP configuration that are generally not permitted under the selected legislation. Please ensure this configuration aligns with what is allowed under the legislation you operate under. |
Each failed or warned rule can be expanded to show:
A description of why the rule matters
A suggested fix to resolve the issue
Risk Assessment score
At the top of the page you will see your overall Risk Assessment score. This is calculated from the number and severity of rules your configuration fails. The score maps to one of three risk levels:
🟢 Low Risk — Your configuration is well set up. Please still address any outstanding warnings.
🟠 Medium Risk — Some areas need attention
🔴 High Risk — Significant issues detected that should be addressed
Rules checked
The Configuration Checker currently evaluates 11 rules:
Rule | What it checks |
|---|---|
Implicit consent must be disabled | The general method chosen typically correlates with the sub-settings below. Consent should not be collected implicitly. Where to find: Go to Configuration > Compliance section > Method |
Implied consent by scrolling must be disabled | Scrolling should not be treated as consent Where to find: Go to Configuration > Compliance section > Page scroll |
Implied consent by page refresh must be disabled | Page refresh should not be treated as consent Where to find: Go to Configuration > Compliance section > Page refresh |
Reject all button must be visible | Users must be able to easily reject all non-essential cookies Where to find: Go to Configuration > Compliance section > Type |
Button colors must not nudge users toward accepting | Accept and decline buttons should be equally prominent Where to find: Go to Configuration > Design section > Button styles |
Consent banner should resurface periodically | Users should be able to revisit their choices over time Where to find: Go to Domain Groups > Select DomainGroup > User Consent Expiration Generally enabled by default for Cookiebot users. |
Marketing category must not be pre-checked | Marketing consent must require affirmative opt-in Where to find: Go to Configuration > Compliance section > Default mode for checkboxes |
Preferences category must not be pre-checked | Preference consent must require affirmative opt-in Where to find: Go to Configuration > Compliance section > Default mode for checkboxes |
Statistics category must not be pre-checked | Statistics consent must require affirmative opt-in Where to find: Go to Configuration > Compliance section > Default mode for checkboxes |
Consent widget should be visible | Users must be able to reopen the consent dialogue at any time Where to find: Go to Configuration > Privacy trigger section > Show privacy button |
Re-running the check
Your configuration may change over time. To get the latest results at any time, click the Re-run check button at the top of the Configuration Health Checker tab. You can run the check as many times as you wish.
Supported legislation
The Configuration Health Checker currently supports GDPR in BETA version.
Support for additional frameworks is currently in development. The full list of legislative rules to be added is subject to change.
Frequently asked questions
Does passing all rules mean I am fully GDPR compliant?
The Configuration Health Checker benchmarks your CMP setup against common best practices. It is not a legal compliance audit. A complete compliance review of your website may involve many other factors, including the declarations and tracking behavior deployed on your site.
Please consult a qualified legal professional for a definitive compliance assessment.
Why is my score different from what I expected?
The score is based on your live CMP configuration at the time the check runs. If you have recently made changes, click Re-run check to refresh the result
Can I fix issues directly from the Configuration Health Checker?
Not directly — but each failed rule includes a suggested fix with guidance on where to make the change in your CMP settings.
Can I ignore warnings and fails?
Ultimately, it is up to you and your organization to determine whether an identified issue represents a relevant compliance risk in your specific scenario.
Please note that, from a UI perspective, warnings and fails cannot be ignored or hidden.
Comments
0 comments
Please sign in to leave a comment.