What Is a SOC 2 Bridge Letter, and Who Writes It?
A SOC 2 bridge letter, also called a gap letter, is a short statement that your own leadership writes and signs, saying that the controls described in your most recent SOC 2 report have continued to operate since that report's period ended. Your auditor does not write it, does not sign it, and does not opine on it. It is a management representation, not an attestation deliverable, which is why no standard prescribes its form, its content, or how long a gap it may cover. It does not extend your report, it is not evidence, and a customer is entitled to decline it.
That last point is the one people find surprising, so the rest of this explains why the letter has the properties it has, what to put in one, and the disclosure that separates a routine letter from a self-inflicted problem.
Key takeaways
- A bridge letter is management's own representation. Your auditor does not write it, sign it, or opine on it, because nobody examined the gap period.
- It does not extend your report and it is not evidence. Its credibility is exactly your credibility.
- Five things belong in it: identification of the report, the gap period as dates, a statement about continued operation, disclosure of anything that did change, and a signature from someone who can be held to it.
- No standard limits the gap. The operative constraint is the customer's own vendor risk policy, so ask them what gap they accept and when they need the next report.
- Three cases where a letter is the wrong answer: the customer's policy requires a current report, something material actually changed, or your last report carried exceptions you have not closed.
Why your auditor will not sign it
A SOC 2 report is the output of an examination. A licensed CPA firm defines a scope, obtains evidence about the period, tests it, and issues an opinion on what they found. Every word of it is backed by procedures the firm performed and can defend to its peer reviewers.
The gap period, by definition, is the stretch after your report's period ended and before your next one begins. Nobody examined it. There is no evidence file, no sampling, no fieldwork. If your auditor were to attest to anything about that period, they would first have to perform an examination of it, and at that point you would not have a bridge letter, you would have a second report.
So the letter necessarily comes from the only party with direct knowledge and no independence to protect: you. That is not a loophole. It is the same logic behind management representations everywhere in assurance work, and it sets the letter's real weight. It is your word, on your letterhead, with a signature attached. Its credibility is exactly your credibility, which is why a vendor with a clean track record gets a bridge letter accepted and a vendor whose last report carried unresolved exceptions does not.
What belongs in one
A bridge letter that does its job is short, specific, and boring. Five elements:
- Identification of the report. The service organisation, the auditing firm, the report type (Type I or Type II), and the exact period covered. A customer's vendor risk team needs to match your letter to the report already in their file.
- The gap period, stated as dates. From the day after the report period ended to the date of the letter, and if you are willing, to the date you expect the next report to cover.
- A statement about continued operation. That the controls described in the report have continued to operate, and that management is not aware of any changes that would materially affect them.
- Disclosure of anything that did change. Acquisitions, a new production environment, a change of subservice organisation (a new cloud provider or payment processor), a security incident, a material change in the control environment or in key personnel who operate controls. This is the element people leave out, and it is the element that matters.
- A signature from someone who can be held to it. An executive with authority over the control environment, with title and date.
Two things do not belong. Do not imply your auditor reviewed the letter, endorsed it, or agrees with it; some firms will supply a template, which is not the same thing as an opinion. And do not use the phrase "no material changes" as boilerplate. If something did change, say so and describe how the control environment absorbed it. A letter that claims nothing changed, sent by a company that migrated its production database that quarter, is a written misstatement to a customer, and it will be read again if anything ever goes wrong.
How long a gap can a letter cover?
There is no rule, and anyone quoting you one is quoting a convention rather than a standard. What there is instead is a logic you can apply, and a customer who decides.
The letter's usefulness decays with the length of the gap, because the proportion of your recent history covered by actual evidence shrinks with every month. A one-month gap asks a customer to accept an unaudited month against twelve audited ones. A seven-month gap asks them to accept more unaudited history than audited, and at that point the letter is doing more work than a signature can carry.
The customer's own policy is the operative constraint. Vendor risk teams routinely write a maximum gap into their standards, and it varies. So the useful move is not to memorise a number, it is to ask: send the letter with a direct question about what gap their policy allows and when they will need the next report. That question costs you nothing and turns a possible rejection into a calendar item.
The structural fix is to shorten the gap rather than to write better letters. If your report period ends in December and issuance takes eight weeks, your gap begins in January and the letter is bridging your own reporting lag. Talk to your auditor about issuance timing before you set the next period end, particularly if a large customer's renewal falls in a predictable month.
When a bridge letter is the wrong answer
Three cases, and in all three the honest move is to say so rather than to send a letter that will not survive review.
The customer's policy says "current report", full stop. Some vendor risk programs, particularly in financial services and healthcare, do not accept management representations for critical vendors at all. Sending one anyway costs you a cycle and signals that you did not read their standard.
Something material actually changed. A new production region, an acquired product now handling customer data, a change of hosting provider, or a security incident during the gap. A letter disclosing a material change is honest but it is also an admission that the report in the customer's file no longer describes your environment. In that situation the useful conversation is about the scope of your next report, not about the letter.
Your last report carried exceptions you have not closed. A bridge letter asserting that controls continue to operate, attached to a report showing that some of them did not, invites the obvious question. Answer the exception first. Our piece on what exceptions actually mean covers how to have that conversation, including the management response that should already be in the report.
If you are on the receiving end
The mirror case is worth stating, because most companies are both vendor and customer.
When a vendor hands you a bridge letter, read it as what it is: an unaudited assertion by the vendor's own management. Check three things. Does it identify the report you actually hold, including the same auditor and period? Does it disclose changes, or does it assert that nothing changed in a period when you know something did, such as a publicly announced acquisition? And is the person who signed it senior enough to be accountable?
Then apply your own tiering. For a low-tier vendor, a bridge letter with a short gap is a reasonable thing to accept. For a critical vendor holding regulated data, it is a stopgap that should come with a date for the real report, recorded in your vendor register. How to build that register and its tiering rules is the subject of our vendor risk management guide.
Where Top Floor fits
Bridge letters are a symptom, not a project. When they start arriving as a quarterly fire drill, the underlying issue is almost always reporting cadence: a period end that does not line up with the renewals that matter, or an issuance lag nobody planned around. That is a scheduling conversation with your auditor, and it is the sort of thing an audit readiness partner should be raising a year ahead rather than the week a customer asks.
If you need one this quarter, write it yourself. It is a one-page document and paying a consultancy to draft it is not a good use of your money. What is worth outside help is the thing behind it, which is keeping the controls actually running between audits so the assertion in the letter is true.
Frequently asked questions
Who writes and signs a SOC 2 bridge letter?
You do. It is written on the service organisation's letterhead and signed by an executive with authority over the control environment. The auditing firm does not write it, does not sign it, and expresses no opinion on it, because the gap period was never examined. Some firms supply a template as a courtesy, which is helpful but confers no assurance. Treat the letter as exactly what it is: your management's own representation, carrying your credibility and nothing else.
How long a gap can a bridge letter cover?
No standard sets a limit, so the answer is whatever your customer's vendor risk policy allows, and policies differ. The useful principle is that the letter's weight decays as the unaudited stretch grows relative to the audited one; a letter bridging more months than the report covers is asking a signature to do the work of an examination. Ask the customer directly what gap they accept and when they need the next report, and treat the answer as a calendar commitment.
Can a customer refuse a bridge letter?
Yes, and some routinely do. Many vendor risk programs will not accept management representations in place of a current report for critical vendors, particularly in regulated industries. That is a legitimate policy position rather than an unreasonable one, because the letter carries no independent assurance. If a customer refuses, the productive response is a date for your next report, not a longer letter.
Do we need a bridge letter if we have no gap?
No. If your observation windows run continuously and each report issues before the previous one goes stale in your customers' eyes, there is nothing to bridge. That continuity is the real goal, and it is why the next window normally opens the day after the last one closes, a point we make in SOC 2 year two. Bridge letters exist to cover reporting lag, so the best long-term answer is to shrink the lag.
Related Services
Need help with your compliance program?
Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.
Schedule a Free ConsultationGet insights like this in your inbox
Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.
Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.