What Is a SOC 2 Bridge Letter? Contents, Signers, and Limits

A SOC 2 bridge letter is a signed statement from a service organization’s management confirming that the internal controls described in its most recent SOC 2 report have continued to operate as designed during the period after that report ended. It is sometimes called a gap letter because it fills the assurance gap between the SOC 2 examination’s end date and the user entity’s own fiscal year-end or next audit cycle. It is a management representation, not an audit, and no external auditor attests to its contents.

Why the Gap Exists

SOC 2 reports cover a fixed historical window, usually six to twelve months. A service organization might hold a report covering January 1 through September 30, but a customer’s fiscal year runs through December 31. That leaves three months during which the customer has no auditor-tested evidence about the service organization’s controls. The customer’s own auditors still need some basis for concluding that those controls did not fall apart during the uncovered stretch.

The bridge letter closes that specific gap. It gives the user entity a formal, signed statement covering the period between the SOC 2 report’s end date and the date the letter is issued. Management is vouching for the window the auditor has not examined. The letter is only as reliable as the people signing it.

What a Bridge Letter Should Contain

A useful bridge letter addresses four specific areas. Missing any of them weakens the document and should prompt questions from anyone reviewing it.

  • Coverage period. Exact start and end dates. The start date should be the day immediately after the prior SOC 2 report’s period ended, with no unexplained gap between the report and the letter.
  • Control continuity. Management affirms that the controls described in the most recent SOC 2 report have continued operating as designed throughout the coverage period.
  • Material changes. The letter identifies significant changes to the control environment, such as system migrations, organizational restructuring, changes in key personnel, or overhauls to access control policies. If nothing changed, it says so explicitly.
  • Incidents and exceptions. Management discloses any control failures, exceptions, or security incidents that occurred during the gap period. This is the section that separates a meaningful bridge letter from a rubber stamp.

A strong letter also confirms that management has continued its monitoring activities and internal assessments throughout the gap period. A letter that simply says “everything is fine” without referencing ongoing monitoring lacks the specificity that user entity auditors look for.

Who Signs It

The service organization’s management prepares the letter, typically through the compliance, risk, or information security function. A senior officer with authority to bind the organization signs the final document, usually a CEO, CTO, or chief compliance officer. The letter goes out on the service organization’s letterhead, reinforcing that it is a management representation rather than an extension of the auditor’s opinion.

The Auditor Does Not Sign It

The external auditor who performed the SOC 2 examination does not sign, audit, or attest to anything in the bridge letter. Once the SOC report has been issued, the auditor has performed no additional testing and does not know definitively whether the control environment has materially changed. The auditor may review a draft for consistency with prior findings, but that courtesy review provides no assurance. If someone hands you a bridge letter that implies auditor endorsement, treat it as a red flag.

How Long a Bridge Letter Stays Useful

Bridge letters are designed for short durations, typically no more than three months. A letter stretching past that window raises legitimate questions about why the next SOC 2 examination has not been completed. Many user entity auditors push back on letters covering four or more months, and some organizations set internal policies refusing anything beyond a 90-day gap.

Past that point, a bridge letter loses its value as a stopgap. User entities may need to request an accelerated SOC 2 examination, perform their own assessment, or lean on other evidence such as penetration test results or ISO 27001 certification. A bridge letter is not a substitute for a delayed audit. It is a short-term measure for a predictable, manageable gap.

Type 1 Versus Type 2

The bridge letter matters most after a SOC 2 Type 2 report, which tests whether controls operated effectively over a period. When that period ends and the next examination has not yet started or been issued, the bridge letter covers the interim.

After a SOC 2 Type 1 report, the letter carries less weight. A Type 1 examines control design at a single point in time, not operating effectiveness over a period. Because the Type 1 never tested whether controls actually worked over time, a management assertion that they continued working means less. Organizations issuing their first SOC 2 report often start with a Type 1, and the bridge letter in that context functions as a placeholder until the first Type 2 is completed.

What a Bridge Letter Cannot Do

The letter is not an audit. It is not independently verified. It carries none of the professional standards, testing procedures, or accountability that come with a SOC 2 examination performed under SSAE 18. Anyone relying on it is relying entirely on management’s honesty and the thoroughness of their internal monitoring.

That does not make bridge letters useless. It makes them a specific tool for a specific situation: a brief, predictable gap where the control environment is expected to be stable. When there have been major changes to systems, infrastructure, personnel, or processes, a management assertion may not provide sufficient assurance, and an expedited SOC 2 examination or additional audit procedures fit the situation better.

Evaluating a Bridge Letter You Receive

If you are on the user entity side, look past the boilerplate. A few things should stand out if they are missing or vague.

  • No specific dates. The letter should state the exact period it covers. Without clear start and end dates, it is not useful.
  • Generic language with no detail. “No material changes” without any indication that management actually reviewed monitoring data suggests the letter was produced as a formality.
  • Missing incident disclosure. Every bridge letter should address whether any control failures or security incidents occurred. Silence on this point is not the same as confirming nothing happened.
  • Unsigned or signed by someone without authority. The signatory should be a senior executive. A letter signed by a mid-level analyst does not carry the same organizational commitment.
  • Gap period longer than three months. A letter covering six or nine months suggests the audit cycle has slipped. Ask when the next full SOC 2 report will be available.

When a bridge letter does disclose material changes or incidents, that is not automatically disqualifying. Honest disclosure is a better sign than a suspiciously clean letter from an organization you know went through major changes. The question is whether the disclosed issues affect the controls relevant to your reliance on that vendor, and whether the organization took corrective action.