Two numbers before the ranking
Our Website Privacy Index scanned 47,505 public websites and scored 47,419 of them on what happens to a visitor before they agree to anything. The crawl ran January to September 2026, across restaurant, hospitality and independent ecommerce sites. It is not a sample of the web as a whole and should not be read as one.
Of those 47,419 sites, a consent platform was detected on 1,475. That is 3.1%. Within that group a vendor could be identified on 1,109. The remaining 366 ran something the scanner could not attribute.
Both bases matter, because everything below is a share of the 1,109 the scan could name, not a share of the web and not a measure of anyone's commercial position.
The ranking
| Vendor | Sites detected | Share of identifiable installs |
|---|---|---|
| OneTrust | 589 | 53.1% |
| CookieYes | 206 | 18.6% |
| Cookiebot | 149 | 13.4% |
| Termly | 96 | 8.7% |
| iubenda | 40 | 3.6% |
| Usercentrics | 22 | 2.0% |
| Quantcast | 7 | 0.6% |
Rawsoft Website Privacy Index. n = 1,109 identifiable installs of 1,475 sites with a consent platform detected, scanned January to September 2026.
The seven named vendors account for all 1,109. The 366 unattributable installs are not a rounding error and we are not going to quietly drop them: they are a quarter of every platform the scan saw, and they include self-hosted banners, white-labelled builds and anything the detection rules did not recognise.
The list splits into two different stories
One enterprise suite sits at the top with more than half of everything the scan could name. Underneath it is a long tail that is almost entirely self-serve: tools bought with a card, installed by pasting a snippet, and configured by whoever was nearest the website that week.
It is tempting to read the top of that list as a sign of maturity and the tail as a sign of corner-cutting. The index does not support either reading. A self-serve platform installed carefully beats an enterprise suite installed badly, every time. What the distribution actually tells you is who was in the room, and that is a different question from whether the thing works.
Which is why the vendor name predicts so little
Set the ranking next to the other figure the index publishes about this same group. Of the 1,475 sites where a platform was detected, 620 still fired tracking before the visitor touched the banner or carried on after a refusal. That is 42.0%. A further breakdown is on the banner results page.
We can measure how often sites running each platform still leaked. We are deliberately not publishing it, and the reason is on the index page: the largest vendor group here has 589 sites in it and the smallest has seven, which is nowhere near enough to characterise a product used on millions of sites. Leak rates also track configuration far more than they track the tool.
So the honest version of this piece is not a league table of vendors. It is this: a banner somebody installed and a consent architecture somebody built are two different artifacts, and they fail differently. A missing banner is visible to anyone who loads the page. Tags firing behind a working banner is not.
Four checks to run before you scope consent work
None of these need a tool. A browser is enough, and they take about ten minutes on any site.
- Open the site in a fresh private window with the network tab already open, and touch nothing. Watch what goes out before you have made any choice. Analytics and ad requests here mean the banner is not holding anything back.
- Click reject, reload, then browse two or three pages. Look again. This is the second failure and it is the more common one: the banner appeared on time, recorded the answer, and the tags behind it ignored it.
- Open one Google request and read the whole query string. If there is no consent state in it at all, Consent Mode is not running, whatever the banner says. There is more on what that signal looks like on the Consent Mode v2 page.
- Follow the preferences link in the footer. Check it lands on something that can actually change a setting, rather than a policy page describing choices that are made somewhere else.
Run those four and you will know more about a site's consent posture than the vendor name will ever tell you. We wrote up what the second check usually turns up in more than a third of cookie banners do not block anything, and the mechanism behind it in the piece on banner blocking.
What this says about the enterprise suites: nothing
The near-absence of several well-known enterprise platforms from the tail of this list is not a comment on their quality. They sell to organizations with a privacy function, and this index is mostly sampling organizations without one. A vendor that barely appears here may be everywhere in a sample of large retailers or banks.
The same caution runs the other way. A vendor's count in this crawl moves with which domains happened to be scanned, and a ranking built on one sample of one set of verticals is exactly the kind of number that should not be repeated as market share.
The principle
The vendor name on a consent banner tells you which product was purchased. It does not tell you whether any tag on the page waits for the answer that banner collects. Only the browser tells you that, and it will tell anyone who asks.
Our free privacy scan runs the same method on any domain in about a minute, with no account. Run it on your own site, or book a data and tracking audit if you want the whole tag layer reviewed rather than the front page.
Not legal advice. Rawsoft determines what a system technically does: which tags fire, when, under what consent state, and what data is transmitted. We do not determine which laws apply to your organization, how a regulator would read them, or whether your organization is in compliance. Those are determinations for your counsel. Everything above describes behavior an automated scan observed on public pages at the time of the scan, and nothing in it is a legal conclusion about any site.