CMP
How to Show Your Privacy Posture Improved: Building a Before-and-After Benchmark
Jul 28, 2026
Tyler Zey
"Can you give us a privacy score?"
I hear this constantly, and for a long time I answered it badly. The instinct is to say no, because we don't stamp your website with a single number out of 100. But that answer is wrong, because what people are actually asking for is something we do have: a way to prove that the work they did moved the needle. They need to walk into a meeting and show a before and an after.
That's the Progress Report. This guide is about how to use it that way.
Why a single number is the wrong ask
Let me argue against the thing people request, because it matters for how you use the tool.
Imagine we gave you a composite score of 72. What would you do with it? You can't act on 72. You don't know if it's driven by one terrible tracker or forty mediocre ones. And when your score moves to 68, you can't tell whether you got worse or whether the scanner simply crawled more pages this week and found more of what was always there.
That last point is the real trap. Raw counts move with crawl scope. A wider crawl surfaces more hosts without anything having actually degraded. Any single number built on top of counts inherits that noise, and a number you can't trust in a board meeting is worse than no number at all.
So instead of one composite figure, the Progress Report gives you four measures that each mean something specific, and shows the change in each across whatever window you choose.
The four numbers, and which one to lead with
Open Compliance → Progress Report, pick your site, and choose a date range. You get four headline deltas, each comparing the oldest scan in your window to the most recent, with a label telling you whether the move was healthy.
Consent coverage percentage. The share of detected third-party hosts your consent configuration actually governs. This is your headline number. It's a ratio, so it stays honest when crawl scope changes: crawl twice as many pages and find twice as many hosts, and coverage still reads correctly if you're governing them. When someone demands a privacy score, quote this.
High-risk hosts. The count of hosts classified as high risk, typically advertising and tracking vendors that won't sign a BAA. You want this going down. It's your best supporting number because it's concrete and a non-technical audience immediately understands "we had 39 of these, now we have 11."
Third-party hosts. Your total footprint. Useful context, but the noisiest of the four, so don't lead with it.
Uncovered hosts. What's been detected and still has no decision attached. This is your remaining work, which makes it the natural "what's next" slide.
Coverage percentage plus high-risk hosts is the pairing I'd build any presentation around. One says your footprint is governed, the other says it's less dangerous. Together they're the claim an auditor or an executive is looking for.
Building the before-and-after
The mechanics are simple once you know what you're reaching for.
Set the window to span the change. The date range is the entire trick. Your range must start before the work you're claiming credit for. If you replaced your embedded maps in March, a 30-day window in June shows you nothing. Pick 6 months or 1 year so the "before" state is actually inside the window.
Read the deltas, then sanity-check them. Each headline metric shows its move with a better-or-worse label. Before you present them, check the page count on the trend points. If host counts jumped because the crawl expanded, say so rather than being caught out on it. Coverage percentage is unaffected, which is exactly why it's your lead.
Export the workbook. Download Excel gives you three sheets. The Summary sheet is your scorecard: four headline metrics, the change since the first scan in range, and a one-line verdict. That's the page you screenshot or paste into a deck. Scan history has one dated row per scan, so any change traces to a specific date, which is what makes it audit evidence rather than a marketing chart. Consent banner history tracks vendors you've categorized by publish date.
Know which clock each chart runs on. The scanner charts move on your scan schedule, meaning what actually loads in a browser. The categorized-vendors chart moves on your consent banner's publish history, meaning how you've configured things. They're separate charts on purpose. Configuring a vendor in your banner and that vendor's behavior changing on your site are two different events, and conflating them is how people end up confused about why a number didn't move.
What a good story looks like
The narrative that works, in the order that works:
Start with where you were. Coverage at 61%, 39 high-risk hosts, from the oldest scan in the window. Don't editorialize; it's a measurement.
Say what you did. Self-hosted the fonts. Put click-to-load placeholders in front of the embedded maps. Routed ad conversions server-side so the browser stopped talking to platforms that won't sign a BAA. Categorized the remaining vendors into consent categories.
Show where you landed. Coverage at 94%, high-risk hosts down to 11. Each with its date, from the export.
Then name what's left. The uncovered-hosts number is your next quarter's work, and including it is what makes the whole thing credible rather than a victory lap.
The reason this lands better than a score out of 100 is that every step is traceable. Someone can ask "which hosts?" and you click View hosts and show them. A composite number can't survive that question.
Being careful about the claim
One caution, because I'd rather you hear it from me than from your compliance officer.
These are measurements of what the scanner observed, not a certification. Coverage at 94% means 94% of the hosts this crawl detected are governed by your configuration. It does not mean you're HIPAA compliant, and it doesn't cover pages the crawl never reached. Present it as evidence that your posture improved, which is genuinely valuable and defensible, rather than as a compliance guarantee, which it isn't.
Used that way, it's the most useful artifact we produce. It turns privacy work, which is usually invisible when it goes well, into something you can actually show people.
Further reading:
Progress over time: the report card, the four metrics, and the Excel export.
Web Scanners overview: what the scanner detects and how coverage is decided.
Recommended fixes: the changes that move these numbers.
Real-time script blocking: keeping new unknown scripts from undoing the work.
This guide describes how to configure and interpret Ours Privacy and is provided for example purposes. It is not legal advice, and the metrics described are not a certification of compliance. Regulatory requirements vary by jurisdiction and change over time. Consult your own counsel and privacy officers when determining your compliance strategy.