What this service does
Canadian Programme for Cyber Security Certification (CPCSC) Level 1 mandatory in defence contracts summer 2026 , CMMC analog. Protected B clearance setup, ITSG-33 program, PSPC standing offers. Five Eyes reciprocity favours US-side delivery. CAD 175-220K (~$130-160K) for the readiness package.
Senior practitioner on every engagement. Quinnlan Varcoe (Founder and CEO) oversees every engagement and reviews every case before findings leave the practice; Jose Santana, Lead Technical Consultant, oversees the practitioner team executing the technical work under her methodology. NDA-protected. No black-box delivery, no off-shoring, no junior staff bait-and-switch.
What we deliver
- CPCSC Level 1 Readiness. Canadian Programme for Cyber Security Certification , Level 1 mandatory in defence contracts summer 2026. CMMC L2 analog with NIST 800-171 control alignment. Our existing CMMC playbook converts with light translation.
- ITSG-33 Implementation. Information Technology Security Guidance 33 , IT security risk management framework for Government of Canada. Security categorization, control selection, assessment, authorization.
- Protected B Environment Setup. Protected B classification handling. Cloud architecture (Microsoft Cloud for Sovereignty Canada, AWS GovCloud Canada paths), endpoint hardening, network segregation, personnel security baseline.
- PSPC Standing Offers + Supply Arrangements. Public Services and Procurement Canada standing offers. SBIPS, SBIPS-2, Cyber Protection Supply Arrangement bidding. CanadaBuys posting, CISD pre-qualifications.
- Cyber Security Establishment (CSE) Coordination. Coordinated assessment and authorization for federal sponsorship. Top Secret Cyber Threat Sharing partnership readiness for primes.
- PIPEDA + Provincial Privacy. PIPEDA (Personal Information Protection and Electronic Documents Act), Quebec Law 25, Alberta PIPA, BC PIPA cybersecurity-specific obligations.
How an engagement begins
- Confidential consultation. NDA-protected. 30 to 60 minutes. Direct conversation with Quinn, not a sales rep.
- Scoped engagement. Written proposal with defined deliverables and pricing. Hourly with milestone caps for open scopes; fixed fee where the work is well-defined.
- Delivery and reporting. Court-admissible methodology where evidence matters. Written deliverables you can hand to counsel, the board, or your auditor.
Why this work runs through Witness
Witness is the parent brand for the practice. The same firm operates a B2B sister brand at varcoe.ai for buyers whose procurement workflow expects a B2B website and a B2B sales motion. Same legal entity (Blueberry Security Global, Inc., Delaware C-corp). Same Quinn. Same delivery team. The split is by audience, not by capability.
















