Here is what I would say. Get 2 Cisco 5508 WLC that has enough AP license for the amount if APs you need at all locations. Look at the 3602i access points for the HQ and branch office. This can provide you with more than you want. You have the redundancy on the WLCs and you have AP's that is modular that can allow for 802.11ac in the future. If all your users are in Active Directory, then you should also look at using a radius server. Microsoft NPS, Cisco's ACS or even Cisco's ISE.