whats-best.ai
Search Sign in

Lead Generation

Cognism

UK / wider Europe Report an error

Panel rating · 6 judges · How to read the stars

Category median

Sovereignty: 2 of 4 dimensions proven

0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.

by Cognism Limited · www.cognism.com

Compare with Lusha → Report an error on this page Is this your product? →

Read this page as one judge. Each weighs the same scores by what they care about.

The panel's verdict

Cognism is a B2B contact database with a European focus and phone-verified mobile numbers. It is strongest on CRM sync and export and data provenance, both scored 4 at minimum and maximum: direct export to Salesforce, HubSpot and Pipedrive, an automatic CRM-enrichment add-on, API and bulk access via Data-as-a-Service, and a privacy notice that names its source categories with a self-service opt-out. Sovereignty scored 5-6 — the higher scores credit Amazon Web Services hosting in Ireland, a stated practice of storing personal data inside the EU, SCCs and named recipients, while the lower scores point to the contracting entity under England and Wales law and a third-party vendor list available only on request. Weakest is visitor identification, scored 2 at minimum and maximum; we found no public information on how intent data is sourced or whether website visitors are identified. Data coverage ranged 2 to 4: higher scores credit phone-verified mobiles and firmographic depth; lower ones demand record counts, per-country DACH figures and refresh cadence. Both plans route to an individual quote, though the billing unit is public.

Report an error

Speaks for it

  • Direct export to Salesforce, HubSpot and Pipedrive, a CRM-enrichment add-on, and API and bulk access via Data-as-a-Service are documented on the captured pages.
  • The privacy notice names its source categories — licensed third-party data vendors, customers under data-sharing agreements, direct correspondence — with a self-service Privacy Centre opt-out.
  • Hosting is named as Amazon Web Services in Ireland, with a stated practice of storing personal data inside the EU and Standard Contractual Clauses for third-country recipients.
  • Verified-mobile filters and verification of mobile numbers on demand are offered alongside firmographic fields for revenue, headcount and technologies.
  • The credit unit is published — one credit per unlocked contact, pooled account-wide, with browsing and reuse free.

Report an error

Held against it

  • We found no public record counts, per-country or DACH coverage figures, or re-verification cadence; data coverage ranged from 2 to 4.
  • We found no public information on identifying companies behind website visits or on where intent data is sourced; visitor identification scored 2 at minimum and maximum.
  • We found no public information on a suppression or do-not-contact list, do-not-call register checks, or per-country outreach guidance; prospecting compliance scored 3 to 4.
  • The captured pages state no legal basis for the records, and the homepage GDPR question appears with no answer text on the page.
  • We found no public information on field mapping, deduplication, or which exported data a customer may keep after the subscription ends.

Report an error

Best for

  • You build targeted lists with firmographic, technographic and signal filters and push them straight into Salesforce, HubSpot or Pipedrive — CRM sync and export scored 4 at minimum and maximum.
  • You buy contact data and want the sources named by category with a self-service opt-out for the people listed — data provenance scored 4 at minimum and maximum.
  • You require stated EU hosting before signing — the privacy policy names Amazon Web Services in Ireland and states that personal data is stored inside the European Union; sovereignty scored 5 to 6, the highest-scoring criterion for this product.

Report an error

Avoid if

  • You need documented coverage — record counts, per-country DACH figures, re-verification cadence — before committing; we found no public information on any of these.
  • You expect website-visitor identification or a named source for intent data; we found no public information on either, and visitor identification scored 2 at minimum and maximum.
  • You want vendor tooling to carry outreach compliance — suppression lists, do-not-call register checks, country-aware flags; we found no public information on these, so the legal checks stay with your team.
  • You must compute an annual cost before committing — the Standard and Pro plans each list 5 licenses, and the captured pricing page routes every tier to an individual quote.

Report an error

The scores

Coverage, accuracy & freshness

Show reasoning
How this is scored

How much of the target market the database actually covers — judged on DACH and EU coverage as much as North American — and what the vendor documents about verification and refresh, because accuracy claims cannot be checked from outside.

0 — No stated coverage, no refresh cadence, no verification method; accuracy asserted as a percentage with nothing behind it.

3 — Headline record counts for the whole database, thin or unstated European coverage, and no description of how often records are re-verified.

5 — Coverage stated per country or region including DACH, email verification described, a stated refresh cadence, and firmographics beyond name and domain.

8 — Coverage broken down by country, industry and data type (email, direct dial, mobile), verification method and refresh cadence documented, company data drawn from official registers where available, and a bounce or credit-back guarantee with stated terms.

10 — The vendor is accountable for its data: per-country coverage and accuracy methodology published, every field carrying a last-verified date visible to the user, register-sourced company data, and credit-back terms that make inaccuracy the vendor's cost rather than the buyer's.

Report an error

The SDR Team Lead

Verified-mobile filters and on-demand mobile verification are the only accuracy mechanics named, alongside firmographics reaching revenue, headcount and technology — respectable for connect-rate work. But we found no public information on record counts, DACH or country-level coverage, refresh cadence or verification method, so I cannot judge whether a German filter feeds my reps five usable contacts or five thousand. 1 2

Report an error

The RevOps Manager

European focus is the pitch — "aktuelle und rechtskonforme Daten" for Europe, phone-verified mobiles, verified-mobile filters and on-demand mobile verification — but the captured pages give no record counts, no per-country or DACH breakdown, and no re-verification cadence beyond on-demand mobile checks. I found no public information on bounce guarantees or last-verified dates visible to the user. 1 2

Report an error

The Data Protection Officer

The vendor positions itself on quality over volume with a stated European focus, phone-verified mobiles, filters for verified mobile numbers and on-demand verification, plus firmographics well beyond name and domain. But we found no record counts, no per-country coverage breakdown for DACH or anywhere else, no refresh cadence and no bounce or credit-back terms on the captured pages. 1 2

Report an error

The ABM Marketer

The vendor positions itself on data quality over volume and shows what a record carries — revenue, headcount, roles, technologies, verified-mobile filters and on-demand mobile verification — but we found no public information on database size, per-country coverage including DACH, or any re-verification cadence. No accuracy methodology or credit-back guarantee is published either. 1 2

Report an error

The DACH Sales Director

Coverage is stated only at the level of 'Europe' — we found no public information on Germany, Austria or Switzerland individually, on record counts, or on how often records are re-verified. Mobile verification is described (filters for verified mobile numbers and verification on demand) and firmographics reach revenue, headcount, headquarters and technologies, which is more than a bare claim but well short of a country-by-country, DACH-accountable dataset. 1 2

Report an error

The Skeptic

The positioning line "Nicht die Datenmenge entscheidet, sondern ihre Qualität und Nutzbarkeit" is the only coverage statement on the captured pages — I found no record counts, no per-country or DACH figures, and no refresh cadence for anything. Firmographic filters, verified-mobile filters and verification-on-demand are described as features, but we found no public information on the verification method, last-verified dates, or credit-back and bounce terms. 1 2

Report an error

Data sources & lawful basis

Show reasoning
How this is scored

Where the personal data in the database comes from and on what legal basis it is processed — as evidenced on the vendor's own pages. Covers Art. 6(1)(f) legitimate interest, the Art. 14 notice to the people in the database, and whether they can find, object to and remove their record.

0 — No statement of where contact data comes from or on what legal basis; "GDPR-compliant" asserted without explanation, and no way for a listed person to object.

3 — Sources described in general terms ("public sources", "partners"), legitimate interest named without any balancing, and an opt-out request form as the only route for data subjects.

5 — Source categories named (registers, company websites, contributory networks, licensed partners), legitimate interest stated as the basis for EU records, a dedicated privacy notice for the people in the database, and a self-service opt-out or removal process.

8 — The above plus an Art. 14 notification practice described (people informed when added), contributory or browser-extension collection disclosed as such, a legitimate-interest assessment summarised publicly, and EU records handled differently from US records where the law differs.

10 — Provenance is traceable per record: the source and collection date available for each contact, Art. 14 notices sent and documented, the balancing test published, objections honoured across the whole dataset and suppressed permanently, and no data sourced by scraping behind logins or from contributors' address books without their contacts' knowledge.

Report an error

The SDR Team Lead

Sources are named in categories — third-party data vendors with the list available on request, customers who opted to share, direct correspondence — with a Privacy Centre form for removal and Standard Contractual Clauses for transfers, which is more than a bare GDPR badge (the FAQ poses the GDPR question with the answer not shown on page). We found no public information on the lawful basis for the contacts in the database, on a legitimate-interest balancing, or on notifying the people listed, so my reps cannot answer a prospect who asks how they were found. 3 1

Report an error

The RevOps Manager

Sources are named by category — third-party data vendors, customers under data-sharing agreements, direct correspondence — with a self-service Privacy Centre opt-out and a disclosed practice of generating approximate business emails from employer patterns. I found no public information stating the lawful basis for EU records, no balancing test, and no Art. 14 notification practice; the GDPR FAQ on the captured page shows only the question. 1 3

Report an error

The Data Protection Officer

The privacy notice names its source categories — licensed third-party data vendors, customer data-sharing agreements and direct correspondence — and offers a self-service Privacy Centre opt-out with a stated five-year removal aim for platform contact data. What I cannot find is the legal basis: the GDPR question appears in the FAQ with no answer text captured, no legitimate-interest statement, and no public information on an Art. 14 notification practice or a balancing test. 1 3

Report an error

The ABM Marketer

The privacy policy names its source categories — licensed third-party data vendors with the list available on request, customers sharing data under agreement, and direct correspondence — and offers a self-service Privacy Centre opt-out plus a five-year retention aim for business contact data. We found no public information on the legal basis for EU records such as legitimate interest, on any balancing test, or on notifying the people listed under Article 14. 3

Report an error

The DACH Sales Director

The privacy policy names its source categories — licensed third-party data vendors (the list itself only on request), customers under data-sharing agreements, and direct correspondence — and gives the people in the database a notice plus a self-service opt-out form at the Privacy Centre. We found no public statement of the legal basis for EU records, no balancing summary, and no description of how individuals are informed when they are added; the homepage GDPR topic appears as a question with the answer text not on the captured page. 1 3

Report an error

The Skeptic

The privacy notice names its source categories — licensed third-party data vendors (list only on request), customers under data sharing agreements, direct correspondence — and honestly discloses that business emails may be generated approximately from the employer's email pattern, with a self-service Privacy Centre opt-out and platform data removed after 5 years from collection. But the GDPR FAQ survives on the homepage as a question with no captured answer, no legal basis is stated for the records, and we found no public information on an Art. 14 notification practice or a published balancing test. 1 3

Report an error

Visitor identification & intent signals

Show reasoning
How this is scored

Identifying companies behind website visits and surfacing buying intent — scored on what is identified (company or person), how the tracking works, and whether the vendor states that its script needs consent under §25 TDDDG and how it behaves without it.

0 — No visitor identification or intent data, or person-level identification of EU visitors with no statement of legal basis.

3 — Reverse-IP company identification with a cookie-setting script, no statement about consent, and match rates claimed without method.

5 — Company-level identification with filters, visit history per company, a stated position that the script requires consent where it sets cookies, and a consent-mode or cookieless option.

8 — Company-level only for EU traffic by design, cookieless operation documented, integration with common consent management platforms, intent topics or page-level signals with the source of third-party intent data named, and alerts routed to owners.

10 — Identification that survives a DPO review: no personal data of visitors stored, the TDDDG and GDPR position published and specific, third-party intent data sourced from a named co-op or panel with its consent basis stated, and scoring on intent that the user can trace back to the underlying visits.

Report an error

The SDR Team Lead

Intent data, hires, job changes and funding rounds are offered as filters and account-prioritisation signals — exactly the triggers my team calls on. We found no public information on identifying companies behind website visits, on how intent is scored or where it comes from, or on any consent position for a tracking script. 1 2

Report an error

The RevOps Manager

Intent is sold as a filter and prioritisation signal ("Kaufabsichten", "Intent-Daten"), but I found no public information on identifying companies behind website visits, on how intent data is captured or sourced, or on any consent position for a tracking script. With no identification mechanism evidenced, this sits at the bottom of the scale. 1 2

Report an error

The Data Protection Officer

Intent signals such as buying intent, job changes, hiring and funding rounds are marketed as filters and for account prioritisation, but that is the whole of it. We found no public information on identifying companies behind website visits, on any tracking script and its behaviour before consent, or on who supplies the third-party intent data — as DPO I can only treat that as unevidenced. 1 2

Report an error

The ABM Marketer

Intent data appears as a filter and as a promise to prioritise target companies with real purchase interest, but we found no public information on where that intent is sourced, no website-visitor identification, and no statement on whether any tracking script needs consent under §25 TDDDG. For working a named account list, nothing on the pages shows how a signal would be scored, traced back to underlying activity, or pushed to the account owner while it is still warm. 1 2

Report an error

The DACH Sales Director

Intent signals are sold as filters and account prioritisation — buying intent, hires, job changes, funding — but we found no public information on website visitor identification, on any tracking script and its consent position under the TDDDG, or on where the third-party intent data is sourced. Signal marketing without method or legal position is not something I could defend to a German data protection officer. 1 2

Report an error

The Skeptic

Intent signals — buying intent, hires, funding and M&A, job changes — are marketed as account-prioritisation features, but we found no public information on how companies or visitors are identified, whether a tracking script sets cookies, or any statement on consent under §25 TDDDG. The source of the intent data is not named on the captured pages. 1 2

Report an error

Prospecting workflow & outreach rules

Show reasoning
How this is scored

Search, list building and outreach — and whether the product helps the buyer stay within UWG §7 and the GDPR once the list exists, rather than leaving the legal risk entirely with the customer.

0 — A search box and an export button; nothing on the pages about what the buyer may lawfully do with the contacts.

3 — Filters on firmographics and job title, saved lists, and a terms clause making the customer solely responsible for compliance.

5 — Advanced filters including technographics and triggers, company-level lists and alerts, a global suppression or do-not-contact list, and guidance on cold outreach rules in the main EU markets.

8 — The above plus country-aware handling (for example flagging German contacts where cold calls and emails require consent), phone numbers checked against national do-not-call registers where they exist, and opt-outs from outreach synced back to the database.

10 — Compliance is part of the workflow: outreach channels restricted or flagged per country and contact type by default, suppression shared across the whole account and every export, the Art. 14 notice supported at first contact, and a documented record of how each contact entered the buyer's pipeline.

Report an error

The SDR Team Lead

Firmographic, technographic and signal-based filters, targeted list building and export to the CRMs are clearly evidenced, and the pitch is compliant data for the right approach at the right time. We found no public information on a do-not-contact or suppression list, country-specific outreach flags, do-not-call register checks, or guidance on cold-email and cold-call rules — every legal check stays manual on my side. 1 2

Report an error

The RevOps Manager

Filters run deep — firmographics, technographics, signals, verified-mobile filters — and compliance is the marketing headline, but I found no public information on a suppression or do-not-contact list, per-country flagging of German contacts, or guidance on consent rules for cold calls and emails in the main EU markets. The published terms govern website use, not what a buyer may lawfully do with exported contacts. 1 2 4

Report an error

The Data Protection Officer

Targeted list building with firmographic, technographic and signal filters, AI search and export are documented, and the homepage promises current, legally compliant data for outreach in Europe — but nothing operational backs that promise. We found no guidance on cold-outreach rules in the main EU markets, no suppression or do-not-contact list, and no country-aware flagging of German or other contacts. 1 2

Report an error

The ABM Marketer

Search is well built for account-based work — firmographic, technographic and signal filters, verified-mobile filters, targeted lists and direct export into CRMs — and the vendor sells itself on compliant prospecting, but we found no public information on a suppression or do-not-contact list, on country-aware flags for German cold-outreach rules, or on checks against do-not-call registers. The homepage GDPR question is captured with no answer text on the page. 1 2

Report an error

The DACH Sales Director

The filter set is genuinely deep — firmographics, technographics, hiring, funding and job-change signals — and 'compliant prospecting' is the vendor's own positioning, but we found no public information on a suppression or do-not-contact list, on checks against national do-not-call registers, or on country-aware flags for German contacts where a cold call requires consent under UWG §7. For a Mittelstand buyer the legal risk in the outreach step would sit squarely with us. 1 2

Report an error

The Skeptic

The filter set is real — firmographic, technographic and signal-based filters, verified-mobile filters, CSV enrichment and export — though "rechtskonforme Daten" is sold as a property of the data rather than a workflow. We found no public information on a suppression or do-not-contact list, on checking numbers against do-not-call registers, or on guidance for cold outreach rules in the main EU markets; the website terms limit liability without allocating compliance duties. 1 2 4

Report an error

CRM sync, enrichment & export

Show reasoning
How this is scored

Getting the data into the systems where sales works — CRM sync, enrichment of existing records, API — and what happens to exported data, and to the buyer's access to it, when the subscription ends.

0 — Manual CSV export only; no CRM integration and no API.

3 — A one-way push to one CRM, CSV export, and no statement on whether exported data may be kept after cancellation.

5 — Native sync with the major CRMs including field mapping and deduplication, enrichment of existing CRM records, and a documented API with stated limits.

8 — Bidirectional sync with scheduled re-enrichment, update and deletion propagated when a record changes or a person objects, webhook or API access with credit costs per call published, and data retention rights after cancellation stated plainly.

10 — The vendor treats the buyer's CRM as the system of record: objections and corrections propagated into synced records automatically, full change history per field, a versioned API with a deprecation policy, and exit terms that say exactly which data the customer may keep and for how long.

Report an error

The SDR Team Lead

Direct export to Salesforce, HubSpot and Pipedrive, an add-on that automatically enriches CRM records and keeps them current, and API or bulk access via Data-as-a-Service — with one credit covering prospecting, enrichment and API reuse — cover the working week. We found no public information on field mapping, deduplication, API limits, or what happens to exported data when the subscription ends. 1 2

Report an error

The RevOps Manager

Export to Salesforce, HubSpot, Pipedrive and more, an automatic CRM-enrichment add-on that "halten Sie sie aktuell", and API access via the Data-as-a-Service add-on — that clears the enrichment bar I care about. But I found no public information on field mapping, deduplication, scheduled re-enrichment, or what a customer may keep — records and credits — when the subscription ends. 1 2

Report an error

The Data Protection Officer

Direct export to Salesforce, HubSpot, Pipedrive and further systems, an automatic CRM-enrichment add-on, CSV enrichment and API or bulk access via Data-as-a-Service are all documented. We found no public information on field mapping, deduplication, propagation of objections or deletions into synced records, or — the question that matters most to me — which exported data the buyer may keep once the subscription ends. 1 2

Report an error

The ABM Marketer

Salesforce, HubSpot and Pipedrive are named alongside further systems, CRM enrichment is an add-on that automatically refreshes CRM records, and one unlocked contact can be reused for prospecting, enrichment and the API without extra credits. We found no public information on field mapping or deduplication during sync, on API limits, or on whether exported records may be kept after cancellation. 1 2

Report an error

The DACH Sales Director

Export goes directly into Salesforce, HubSpot and Pipedrive, a CRM-enrichment add-on keeps records current, CSV enrichment and SSO are on the plan comparison, and API access arrives via the Data-as-a-Service add-on. We found no public information on field mapping or deduplication, on stated API limits, or on what happens to exported data and access to it after cancellation. 1 2 3

Report an error

The Skeptic

Direct export to Salesforce, HubSpot and Pipedrive (with further systems named), a CRM enrichment add-on that keeps records current, and Data-as-a-Service access via API and bulk delivery are all evidenced. We found no public information on field mapping, deduplication, API rate limits or credit costs per call, and nothing on whether exported data may be kept after the subscription ends. 1 2 3

Report an error

European sovereignty panel opinion

Show reasoning
How this is scored

Where a database of EU residents' personal data is held, who the contracting entity and controller are, and which subprocessors see it. Independently sourced by the sovereignty pipeline; weighted heavily here, because the product itself is personal data about people who never chose the vendor.

0 — Non-EU vendor and contracting entity, hosting unstated, subprocessors unnamed, and EU residents' contact data processed outside the EU with no stated transfer basis.

3 — Non-EU contracting entity with an EU representative under Art. 27, or EU hosting offered while enrichment, support or AI processing stay non-EU.

5 — EU contracting entity and EU hosting as standard, but parts of the chain — data partners, enrichment sources, tracking infrastructure — are non-EU without an explained safeguard.

8 — EU contracting entity and controller, EU hosting on named infrastructure, subprocessor and data-partner list published, and any non-EU transfer named with its legal basis.

10 — Sovereign end to end and evidenced: vendor, controller, hosting, data partners and every subprocessor European, certification published, and a DPA covering both the customer's data and the database records the customer exports.

Report an error

The SDR Team Lead

Hosting is AWS in Ireland with a stated EU-storage position, a Croatian joint-controller entity stands alongside the UK company under the Croatian data-protection authority, and non-EU recipients in North Macedonia and the UK are named with Standard Contractual Clauses as the transfer basis. The contracting terms run under England and Wales law, the data-vendor list is available only on request, and the named sales-engagement processors are mostly US, which keeps this short of full European sovereignty. 3 4

Report an error

The RevOps Manager

Hosting is AWS in Ireland with EU storage stated, recipients are named (including a Macedonia affiliate and UK and French entities), SCCs are described for third-country transfers, and both a DPA and a joint-controller arrangement exist. Rights requests route to the UK entity with the ICO as its lead supervisor, and I found no public information on a certification or on a DPA covering the database records a customer exports. 3

Report an error

The Data Protection Officer

The privacy policy names joint controllers Cognism Limited in England and Wales and Cognism d.o.o. in Croatia, hosting on Amazon Web Services in Ireland with a statement that personal data is stored inside the EU, SCCs for third-country transfers, and named affiliate recipients including a North Macedonian entity. The chain is only partly evidenced, however: the third-party data-vendor list is available on request rather than published, governing law is England and Wales, and ownership and certification are unconfirmed on the captured pages. 3 4

Report an error

The ABM Marketer

Hosting is named as AWS in Ireland with a stated practice of storing personal data inside the EU, the UK and Croatian entities are identified as joint controllers under the ICO and AZOP, and SCCs are described for third-country transfers with named affiliate and sales-engagement recipients. The contracting entity and governing law sit in the UK, the third-party data vendor list is only available on request, and a Macedonia-based affiliate is among the recipients, leaving parts of the chain outside the EU. 3 4

Report an error

The DACH Sales Director

The privacy policy puts hosting on Amazon Web Services in Ireland, names a Croatian sister company as joint controller with the Croatian data protection authority for the EU, and discloses affiliate recipients — among them one in North Macedonia — and US engagement platforms, with standard contractual clauses stated for third-country transfers. The contracting entity is still the UK company under English law and the licensed data vendors are a list available only on request, so the chain is half-disclosed rather than sovereign end to end. 3 4

Report an error

The Skeptic

The privacy policy names Cognism Limited (England and Wales) and Cognism d.o.o. (Croatia) as joint controllers, storage inside the EU on Amazon Web Services in Ireland, and SCCs for third-country recipients, with a Macedonian affiliate and UK and French affiliates named as data recipients. The contracting picture stays non-EU — the website terms are governed by England and Wales, the third-party data vendor list is only available on request — and independent sourcing could not confirm jurisdiction, ownership, residency or subprocessor exposure beyond the privacy policy's own statements. 3 4

Report an error

Pricing transparency not rated — the vendor publishes no price

Show reasoning
How this is scored

Whether a buyer can compute the real annual cost from public pages alone — including credits per email, phone number and mobile, credit expiry, seat pricing, visitor-identification tiers and the API — in a category where the unit of billing is often invented by the vendor.

0 — No public prices at all; every tier is a sales conversation.

3 — A monthly headline exists, but what a credit buys, whether credits expire, or the cost of an additional seat is unstated — the invoice is unknowable.

5 — Tier prices public with credit allowances given, but at least one commonly needed piece (mobile numbers, extra seats, API access, CRM sync) is unpriced or behind a sales call.

8 — Every tier priced publicly with credits per data type, credit expiry and rollover, per-seat costs, overage rates, minimum term and VAT treatment stated.

10 — Complete price computability: the annual invoice derivable for a given number of seats, exported contacts by data type, identified companies and API calls, with every credit cost and the refund rule for inaccurate data published.

Report an error

The SDR Team Lead

Standard and Pro tiers appear with five licences each but no figures, the only path to a price is an individual quote, and Data-as-a-Service plus CRM-enrichment pricing sit behind collapsed FAQ entries. The credit mechanics are unusually clear — one credit per unlocked contact, pooled across users, free browsing and free reuse for enrichment and API — but we found no public information on the price per credit, credit expiry, or additional seats, so no annual cost can be computed from the public pages. 2

Report an error

The RevOps Manager

The credit mechanics are documented unusually well — "1 Credit = 1 freigeschalteter Kontakt", pooled account-wide, browsing and reuse across products at no extra cost — but both published plans name five licenses without prices and route to "Individuelles Angebot anfordern". Credit expiry, per-seat costs and the DaaS and CRM-enrichment add-on prices sit behind collapsed FAQ answers, so the annual invoice can only be arrived at through an individual quote. 2

Report an error

The Data Protection Officer

The credit mechanics are unusually clear — one credit per unlocked contact, pooled account-wide, free reuse across prospecting, CRM enrichment and API, with browsing free — so a buyer knows the unit of billing. But neither the Standard nor the Pro plan shows a price, add-on pricing details sit collapsed in the FAQ, and every path leads to requesting an individual quote; we found no credit price, expiry terms or per-seat cost, so the invoice is not computable. 2

Report an error

The ABM Marketer

Both tiers point to requesting an individual quote with no price shown on the page, and the CRM enrichment and Data-as-a-Service add-ons address pricing only in collapsed FAQ text. The credit unit is at least public — one credit equals one unlocked contact, browsing is free, and reuse across prospecting, enrichment and the API costs nothing extra — but we found no public information on credit prices, expiry, extra seats or API costs. 2

Report an error

The DACH Sales Director

The pricing page routes every plan to an individual quote — no price is shown for Standard or Pro — though the credit unit is at least defined: one credit buys one unlocked contact, reusable across users and products at no extra cost, with browsing free. We found no public information on credit allowances, expiry, per-seat costs or VAT treatment, so the annual invoice is not computable from public pages. 2

Report an error

The Skeptic

The pricing page ends every tier in "Individuelles Angebot anfordern" — Standard and Pro each show five licenses with no price, and the Data-as-a-Service and CRM-enrichment pricing questions sit collapsed with no figures. Credit them this much: the billing unit is unusually public — "1 Credit = 1 freigeschalteter Kontakt", browsing and reuse free, credits pooled account-wide — but without tier prices, credit allowances, expiry or per-seat costs, the annual invoice cannot be computed from public pages. 2

Report an error

European sovereignty — proven facts

2 of 4 dimensions proven

Built only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.

Ownership Not determined — uncited Report an error
Data residency Not determined ⚠ unverified — uncited Report an error
Subprocessors US CLOUD Act reach ⚠ unverified 0/2 pts 3 Report an error

Where this could be wrong

What we left out

A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.

Sources (11)

The pages every claim on this page was read from — each one checked, dated, and kept verifiable.

  1. 1 Vendor homepage www.cognism.com Checked 22 Sep 2026 Details →
  2. 2 Pricing page www.cognism.com Checked 22 Sep 2026 Details →
  3. 3 Privacy policy www.cognism.com Checked 22 Sep 2026 Details →
  4. 4 Terms of service www.cognism.com Checked 22 Sep 2026 Details →
  5. 5 Imprint — found from the homepage www.cognism.com Checked 30 Sep 2026 Details →
  6. 6 Coverage, accuracy & freshness — found from sitemap www.cognism.com Checked 1 Oct 2026 Details →
  7. 7 Coverage, accuracy & freshness — found from sitemap www.cognism.com Checked 1 Oct 2026 Details →
  8. 8 Prospecting workflow & outreach rules — found from sitemap www.cognism.com Checked 1 Oct 2026 Details →
  9. 9 Prospecting workflow & outreach rules — found from sitemap www.cognism.com Checked 1 Oct 2026 Details →
  10. 10 CRM sync, enrichment & export — found from sitemap www.cognism.com Checked 1 Oct 2026 Details →
  11. 11 CRM sync, enrichment & export — found from sitemap www.cognism.com Checked 1 Oct 2026 Details →