Pricing that reflects your size, risk and goals

Most businesses do not need more security spend. They need more clarity, more confidence and better proof from the spend they already have. Loopli’s pricing is built around that reality: fixed-fee where possible, tailored where needed, and always focused on outcomes, so you know what you are buying, what it costs and how it strengthens your position with boards, customers, insurers and regulators. For smaller organisations, that often starts with CE/CE+ and practical visibility support. For more complex environments, it usually starts with a Baseline. Either way, the goal is the same: reduce waste, improve resilience and get more value from what you already spend, without hidden upsells or big-consultancy overhead.

Pricing Principles

  • Fixed-fee where possible
  • No hidden upsell traps
  • Aligned to your size and complexity
  • More value from existing spend
  • Built around outcomes, not hours
  • Clear scope, clear cost, clear impact
Ways to work with Loopli

Packaged services

  • Packaged services
  • AI-accelerated pen-test (from £279)

Tailored programmes

  • OSbD Launch
  • OSbD Operate
  • SecureROI modules
  • MNVEM & other services
Enterprise-grade outcomes, accessible beyond enterprise budgets.

Three ways to work with Loopli

Different organisations need different levels of support, but almost every journey fits into one of three routes:

Most common

SME visibility & assurance

(typically 1–100 people) For SMEs and smaller organisations that need professional-grade visibility, Cyber Essentials / CE+ and practical assurance – without an in-house security team.
Includes CE/CE+ with published pricing for up to 50 people
At launch, our managed Cyber Essentials / CE+ service is available with published monthly pricing, including assessment and certification costs for organisations up to 50 people.
Other SME services, such as Managed Network Visibility & Exposure Monitoring (MNVEM), are scoped and priced based on your environment.

OSbD Launch programmes

(growing & regulated organisations) For organisations that need to step back and reset how security, resilience and compliance work. Fixed-price, time-boxed programmes to:
  • Design or refresh your OSbD operating model
  • Align frameworks (ISO, CE/CE+, NIS2, DORA, CAF, customer controls)
  • Produce a realistic roadmap and evidence set for boards, auditors and regulators.
For teams needing help raising their baseline and demonstrating assurance.

OSbD Operate & SecureROI

(growing & regulated through to mid-market & enterprise) For organisations that want ongoing support to run their operating model and continuously tune security and compliance spend – whether you’re a growing regulated business or a large enterprise. This route typically includes:
  • A Managed Compliance & Trust Office (OSbD Operate) that scales up or down with your organisation, and
  • One or more SecureROI modules that identify avoidable spend and reinvest it into stronger controls and evidence – without increasing run-rate.
For teams needing proactive support and continual assurance.
Packaged services with online pricing:
Managed CE/CE+ service, AI-accelerated infrastructure pen-test.
Tailored programmes:
OSbD Launch, OSbD Operate (scalable), SecureROI , MNVEM and other services.

Packaged services – online pricing

Packaged services – online pricing These are the services you can buy directly from the site at launch. Pricing is fixed or banded, with a clear scope and no hidden extras. All prices are from and exclusive of VAT. Final fees may vary slightly depending on your environment and any agreed add-ons.
Managed Cyber Essentials / CE+ service
Available to buy online
from, per month, ex VAT
A managed Cyber Essentials / CE+ service that plans, implements and maintains your baseline – including certification costs – so you stay in good standing year-round rather than scrambling once a year.
Example monthly pricing
Company size Foundation/Implementation/Certification (One Off) Continuous Improvement/Ongoing Management (Per Month)
Up to 9 £1,595.00 £155
10-19 £1,875.00 £180
20-29 £2,125.00 £210
30-39 £2,395.00 £235
40-49 £2,645.00 £265
What's included (example):
Initial scoping and baseline review
Remediation plan aligned to CE / CE+ requirements
Support to implement required controls using what you already have
Preparation and submission of the assessment
Ongoing guidance and checks to keep you close to CE/CE+ readiness for renewal
Assessment/certification fees included within the monthly service

If you're not sure which band you fall into, we'll confirm it with you before you commit.

AI-accelerated infrastructure penetration test – IP-based
Available to buy online

IP-based (internal & external), from, ex VAT

An AI-powered, human-led infrastructure penetration test designed to give SMEs and growing organisations near human-depth insight at a fraction of traditional pen-test cost.

We use an advanced AI testing platform to drive deep, repeatable technical coverage (often producing hundreds of pages of raw findings), then Loopli consultants turn that into a clear, prioritised report your teams can act on. For higher-risk or regulated contexts, we can extend this with a CREST-certified manual layer focused on the remaining delta.

Entry-level pricing (up to 5 IPs total)
Base package:

1 IP in scope – £279 (AI-accelerated test, expert human review and report)

Additional IPs (up to 5 total): £98 per additional IP for the next 4 IPs

To illustrate:
Total IPs in scope Example price (ex VAT)
1 IP £279
2 IPs £377
3 IPs £475
4 IPs £573
5 IPs £671
6 IPs Contact Us

For 6 or more IPs, or more complex internal/external mixes, we’ll confirm a fixed price with you, with pricing breaks for larger ranges.

What you get:
Pre-engagement scoping call and documented scope
AI-driven infrastructure testing across your chosen IPs (external and/or internal/VPN)
Expert human triage and translation of findings into a concise, prioritised report
Optional debrief session to walk stakeholders through findings and next steps
Optional CREST-certified uplift where you need formal, human-led testing for regulatory or high-stakes scenarios
This is an ideal step up from basic vulnerability scanning for smaller estates – giving you a strong, affordable perimeter check and a clear path into broader OSbD and resilience work.
OSbD Launch, Operate & SecureROI – contact for pricing

Our OSbD Launch, OSbD Operate and SecureROI services are designed for organisations with more complex environments, regulatory obligations or board expectations. These engagements are scoped and priced with you.

We generally structure pricing as:

OSbD Launch programmes

Fixed-price, time-boxed engagements (typically 12–16 weeks).
  • Deliver an OSbD Baseline, target operating model, roadmap and initial evidence set.

OSbD Operate – Managed Compliance & Trust Office

Scalable annual managed service retainers for running your OSbD operating model day to day – from growing regulated organisations through to large enterprises.
  • Pricing reflects frameworks in scope, governance cadence, evidence complexity and the level of hands-on support you need.

SecureROI optimisation modules

Short, focused modules targeting domains such as cloud storage, backups, monitoring, SD-WAN and connectivity or SaaS.
  • We work with your current suppliers and tools to identify avoidable spend and reinvest savings into upgraded controls, better evidence and improved resilience – without increasing run-rate.
We don't ask you for more budget. We help you take waste out of your current run-rate, then turn that into a stronger operating model and a better story for boards, regulators and insurers.

Reassurance:

Before any OSbD Launch, Operate or SecureROI engagement, you'll see a documented scope of work, KPIs and a reporting cadence – and we'll be clear about where we are advisory, where we are accountable, and where your other suppliers fit.

How our pricing works

Fixed-fee where possible Wherever we can, we agree a fixed fee and scope upfront for each packaged service or programme, so you know the cost before we start.
Aligned to your size and complexity For packaged services like CE/CE+ and AI-accelerated pen-tests, we use simple bands or formulas (e.g. headcount, IP count). For OSbD Launch & Operate and SecureROI , we factor in entities, locations, regulations, frameworks and evidence complexity.
No hidden upsell traps If we believe you need extra technology or major remediation beyond scope, we'll be explicit and quantify options. We're vendor-agnostic – our incentive is to rationalise spend, not sell tools.
Built around outcomes Every engagement has a defined set of outputs and intended business outcomes – reduced exposure, stronger evidence, smoother audits, optimised spend – not just hours or reports.
Risk-reduced entry Where sensible, we start with a constrained pilot or baseline (for example, a CE/CE+ managed service, an AI-accelerated pen-test or an OSbD Baseline) so you can see value before you commit to a longer journey.
You should always know what you're paying, what you're paying it for, and what will be different when we're done.

Still not sure which route makes sense?

Share a bit about your organisation – size, sector, key obligations and current pain points – and we’ll come back with a simple, written proposal showing where we think you’ll get the best return and whether you’re better starting with CE/CE+, an AI-accelerated pen-test, or a more strategic OSbD Baseline.