The short answer
Yes — if anything non-essential fires before consent, and on a SaaS marketing site something almost always does.
The obligation does not attach to “being a SaaS company.” It attaches to storage and access on a visitor’s device, and to whether personal information is being sold or shared. A product-analytics SDK, a session-replay tool, a support widget and an ad pixel all put something on the device, and most SaaS marketing sites run at least three of those.
The useful move is to stop guessing. UserGuard loads your site in a real browser with no consent given, captures every cookie set by header, by HTTP-only record, or by document.cookie, and files scripts, pixels and storage keys separately as what they are. You then decide with a list in front of you instead of a hunch.