CookieHub is ready for IAB TCF v2.4

CookieHub is ready for IAB TCF v2.4 - here's what changed

Table of contents

CookieHub shipped support for the IAB TCF v2.4 requirements in widget release 2.9.3, ahead of the 23 October 2026 deadline for web environments. Feature disclosures with the IAB's standard texts and illustrations, a new TCF settings section in the Dashboard, and stricter, more defensible consent strings - delivered automatically to every domain with automatic updates enabled.

On 23 July 2026, IAB Europe published the TCF Technical Specifications v2.4 and the corresponding Global Vendor List update, following the release of TCF Policies v5.0.b in May. Web CMPs have until 23 October 2026 to comply. CookieHub shipped support for the IAB TCF v2.4 requirements in widget release 2.9.3 - almost a month ahead of that deadline - and for most customers it arrived the way compliance should: automatically, with nothing to configure and nothing to migrate.

What TCF v2.4 asks of CMPs

The Transparency and Consent Framework is IAB Europe's standard for collecting and signalling consent to advertising vendors. Version 2.4 tightens how CMPs disclose and encode that consent. The changes that matter to a consent dialog:

The framework's three Features must be disclosed with the IAB's standard explanation and real-world illustrations from the Global Vendor List.

Publishers gain flexibility to persist privacy choices across devices, for example for logged-in users - with a duty to inform users when choices apply across devices, and to resolve conflicts between device and account-level choices.

The vendor list gains new standard texts, and Special Feature 2 was renamed to "Identify devices based on information actively requested".

TCF CMPs operating in web environments must implement the v2.4 requirements by 23 October 2026; mobile app and connected TV environments have until 23 February 2027.

What your visitors will notice

Very little, which is deliberate. Existing dialogs keep the same purposes, the same toggles and the same order. Two things are new in the second layer:

A Features section with the IAB standard explanation and all three Features, each expandable to show its description and illustration. Features carry no consent choice under the framework, so they are presented as information, not toggles.

CookieHub now also discloses Special Purpose 3 alongside the other special purposes.

New: TCF settings in your Dashboard

Alongside the compliance work, we shipped something we have wanted to give you for a while: control over what your dialog presents. The new TCF settings section in the Dashboard lets you choose the purposes, special features and stacks your dialog offers - individually or bundled as IAB stacks. Your vendor-list selection and legitimate-interest settings moved there from Customize, values unchanged.

Existing domains keep exactly the set they present today. New domains additionally include Stack 10, which makes personalised advertising grantable out of the box - and any existing customer can opt in by selecting purposes 3 and 4, or Stack 10, in the new section. Purpose 1 stays required, because several Google Consent Mode signals depend on it.

A stricter TCF implementation under the hood

The widget now runs on the current IAB reference library and encodes a stricter, more defensible TC string:

Accept all means accept what was shown. If your configuration leaves a purpose out of the dialog, it is never signalled as consented - even on Accept all. That is what TCF Policy requires, and it is what your visitors would expect.

Disclosed vendors are recorded. The TC string now carries the disclosed-vendors segment, so downstream vendors can see which vendors your dialog actually presented.

Nothing collected before the update is lost. Consent strings written under 2.3 still decode correctly, and a configuration change never rewrites stored consent - newly added purposes read as denied until the visitor is asked again.

Before release, we decoded real TC strings produced by real configurations against the live Global Vendor List and checked every segment.

Also new: the Consent Mode mapping, documented

How CookieHub derives each Google Consent Mode signal - from cookie categories and from TCF purposes - is now published in our documentation: Google Consent Mode v2 mapping. The tables show what each signal requires and which mappings are defined by Google versus applied by CookieHub. They describe the widget from version 2.9.1 onward.

Do you need to do anything?

If your domain runs the latest widget generation with automatic updates enabled: no. TCF v2.4 is already live on your site.

If you have disabled automatic updates, or your domain runs an earlier widget generation: update to the 2.4 release before the 23 October 2026 web deadline. CookieHub no longer supports TCF 2.3, so this update is not optional - but it is one click, and everything above comes with it.

Frameworks move; that should be our problem, not yours. TCF v2.4 reached every automatically updating CookieHub domain almost a month before the IAB's web deadline, with no migration and no configuration required. If you have questions about what changed on your site, the updated TCF documentation walks through it - or ask us at support@cookiehub.com.

Share this post

It's easy to be compliant with CookieHub

Sign up today and create a custom cookie banner for your website

14 day free trial

No credit card required