Quick answer: IAB Europe published TCF 2.4 on 23 July 2026. Web implementations must migrate by 23 October 2026; the deadline for mobile apps and CTV is 23 February 2027. The TC string format version remains 2 and the TCF policy version remains 5. TCF 2.4 therefore does not introduce a blanket new string format. The key work is applying the updated policies, especially the stricter vendor legitimate-interest rule.
Key takeaways
- TCF 2.4 is the current specification, with separate migration deadlines by environment.
- Web: 23 October 2026. Mobile app and CTV: 23 February 2027.
- The binary TC string version stays at 2;
tcfPolicyVersionstays at 5. - Existing valid choices do not require blanket reconsent merely because the framework label changed. Other material changes can still require a new prompt.
- The
DisclosedVendorssegment became mandatory in TCF 2.3 and continues under 2.4; it is not a new 2.4 feature. - Vendors may not signal legitimate interest based only on Special Purposes. This 2.4 rule has applied since April 2026.
- Registration and certification are different claims, and a CMP registration must be checked per environment.
What changes with IAB TCF 2.4?
TCF 2.4 updates the policies and technical specifications of the Transparency and Consent Framework. Implementers must not confuse the framework label with fields encoded in the TC string. The Core segment still uses format version 2, and the policy version remains 5. Integrations must neither encode an invented string version “2.4” nor discard every existing signal solely because the framework version changed.
The most important implementation change concerns vendor legitimate interest. A vendor may set an LI bit only where at least one permitted processing purpose supports it. Special Purposes alone are insufficient. CMPs must enforce this invariant while generating, restoring and withdrawing signals.
Disclosed Vendors: introduced in 2.3, still required in 2.4
The DisclosedVendors segment records which vendors were actually presented to the person. It became mandatory with TCF 2.3 and remains part of a correct 2.4 implementation. A migration should validate it against the visible vendor list:
- Every vendor in the segment must have been disclosed in the consent UI.
- Vendors that were not shown, are deleted or are inactive must not be signalled as disclosed.
- Vendor sets in configuration, UI,
DisclosedVendorsandTCDatamust be traceably consistent.
Deadlines by environment
| Environment | TCF 2.4 migration deadline |
|---|---|
| Web | 23 October 2026 |
| Mobile app | 23 February 2027 |
| CTV | 23 February 2027 |
A Web registration does not automatically cover mobile apps or CTV. Check the CMP's entry in the official CMP list and its registered environments. Biscotti CMP is operated by Campcruisers GmbH and is registered for Web under CMP ID 497. This does not claim a mobile-app or CTV registration.
Step-by-step migration to TCF 2.4
1. Verify registration and environment
Compare the CMP ID, legal entity and registered environments with the official CMP list. Do not rely on a logo or a broad “IAB compliant” statement.
2. Bind the current GVL and vendor selection
Load a current Global Vendor List and determine which vendors are actually used for the specific site or app. The interface and consent state must derive from the same vendor set.
3. Enforce vendor LI fail-closed
Do not produce a vendor-LI signal when the vendor declares only Special Purposes or no permitted LI purpose remains. Re-check this after rejection, withdrawal, GVL changes and restoring stored state.
4. Preserve TC string semantics
Continue to encode TC string format version 2 and policy version 5. Keep the mandatory DisclosedVendors segment. Do not change API version fields merely because the framework specification is named 2.4.
5. Make a targeted reconsent decision
A version change alone is not a blanket reason for reconsent. Instead, assess material changes to purposes, vendors, legal bases, publisher restrictions and the information shown to the person. Record the decision.
6. Test complete state transitions
At minimum, test Accept All, Reject All, granular choices, legitimate interest, withdrawal, reopening, browser restart and a GVL update. Decode generated strings independently and compare vendor and purpose sets.
Technical checklist
__tcfapi('ping', 2, ...)reports consistent CMP and policy data.- TC string format version is 2 and
tcfPolicyVersionis 5. DisclosedVendorsmatches the vendors actually shown.- Vendor LI is never set without a permitted LI purpose.
- Reject and withdrawal remove impermissible consent and LI signals.
- Stored state is restored only when compatible with the current configuration.
- CMP ID and registered environment match the public CMP list.
- Web, mobile-app and CTV releases are approved separately.
Must existing users be asked again?
Not automatically. The TCF 2.4 label alone changes neither the TC string format nor the policy-version number. A new choice is required when the previous decision no longer describes current processing or the person must receive material new information. Base the decision on actual configuration changes and obtain legal advice where appropriate.
Common mistakes
- Encoding TCF 2.4 as a new TC string format version.
- Increasing
tcfPolicyVersionwithout a normative basis. - Describing Disclosed Vendors as a new TCF 2.4 change.
- Treating Special Purposes as sufficient for vendor LI.
- Presenting a Web registration as a mobile-app or CTV registration.
- Using “registered”, “validated” and “certified” as synonyms.
- Testing only Accept All while omitting reject, withdrawal or restart.
Conclusion
Migrating to TCF 2.4 is not a text-only update. It requires an environment-specific release plan, correct vendor-LI signals and evidence that the visible vendor set, stored state and TC string agree. Keeping format version 2, policy version 5 and the history of Disclosed Vendors distinct avoids the most common migration errors.
FAQ
Is TCF 2.4 a new TC string format version?
No. The TC string version field remains 2; the framework label 2.4 must not be written into it.
Does the TCF policy version change?
No. tcfPolicyVersion remains 5 for TCF 2.4.
Are Disclosed Vendors new in TCF 2.4?
No. The segment became mandatory in TCF 2.3 and continues in 2.4.
Does TCF 2.4 always require reconsent?
No. The actual changes to processing and user information matter, not the version number alone.
Is Biscotti CMP registered for mobile apps or CTV?
The current entry for Campcruisers GmbH, CMP ID 497, covers Web. It does not establish registration for mobile apps or CTV.
Sources
- IAB Europe, TCF Policies v5.0.b and Specifications v2.4: https://iabeurope.eu/transparency-consent-framework/
- IAB Europe CMP list: https://cmplist.consensu.org/v2/cmp-list.json
- IAB Tech Lab, Consent String and Vendor List Formats: https://github.com/InteractiveAdvertisingBureau/GDPR-Transparency-and-Consent-Framework
This article explains technical and operational considerations and is not legal advice.