What this service does
UK MoD CSM v4 + DefStan 05-138 Issue 4 readiness. G-Cloud 15 framework supplier (£14B / 4-yr launching 2026). Cyber Essentials Plus certification, NCSC Assured Service Provider scheme. CMMC L2 playbook converts to UK MoD with light translation. £135-165K (~$170-210K) for the readiness package.
Senior practitioner on every engagement. Quinnlan Varcoe (Founder and CEO) oversees every engagement and reviews every case before findings leave the practice; Jose Santana, Lead Technical Consultant, oversees the practitioner team executing the technical work under her methodology. NDA-protected. No black-box delivery, no off-shoring, no junior staff bait-and-switch.
What we deliver
- MoD CSM v4 Readiness. Cyber Risk Profiles 0-3 mapped, DefStan 05-138 Issue 4 evidence package, supply-chain pre-cert workflow. Structurally identical to CMMC L2 , our existing playbook converts with translation overhead, not rebuild.
- Cyber Essentials Plus Certification. Five-control verification (firewalls, secure config, access control, malware protection, security update management). On-site or remote audit. Annual renewal. Mandatory for many UK government contracts.
- G-Cloud 15 Listing. G-Cloud framework supplier listing for the £14B / 4-year cycle launching 2026. Service description writeup, pricing structure, no UK domicile requirement to list. Direct-sell channel into central + local government, NHS, devolved administrations.
- NCSC Assured Service Provider. NCSC-assured cyber incident response, certified CIR scheme membership for IR retainers serving government, regulated industries, CNI.
- ISO 27001 + UK Public Sector Variants. ISO 27001 certification with public-sector-specific Annex A control selection. NHS DSPT, OFFICIAL-SENSITIVE handling, supplier security questionnaires.
- GDPR + UK GDPR Cybersecurity. Article 32 technical and organisational measures, ICO breach notification 72-hour clock, Data Protection Impact Assessments tied to security controls.
How an engagement begins
- Confidential consultation. NDA-protected. 30 to 60 minutes. Direct conversation with Quinn, not a sales rep.
- Scoped engagement. Written proposal with defined deliverables and pricing. Hourly with milestone caps for open scopes; fixed fee where the work is well-defined.
- Delivery and reporting. Court-admissible methodology where evidence matters. Written deliverables you can hand to counsel, the board, or your auditor.
Why this work runs through Witness
Witness is the parent brand for the practice. The same firm operates a B2B sister brand at varcoe.ai for buyers whose procurement workflow expects a B2B website and a B2B sales motion. Same legal entity (Blueberry Security Global, Inc., Delaware C-corp). Same Quinn. Same delivery team. The split is by audience, not by capability.
















