GetSOC2

SOC 2 bridge letter: what it is

A bridge letter is a short statement from your management saying nothing material changed since the report period ended. It is free, it is not an audit product, and a customer either accepts it or does not.

Last reviewed 2026-08-31Written by Jacob Masse, TrazTech Inc.

A SOC 2 bridge letter, sometimes called a gap letter, is a one page statement you write and sign covering the period between the end of your report period and today. It says the controls described in the report still operate, names anything that changed, and confirms you know of no incident that would alter the opinion. Your auditor does not write it, does not sign it, and cannot provide assurance over it.

It costs nothing, it takes an hour, and most enterprise reviewers accept one for a gap of up to three months. Past six months they stop accepting it and ask when the next report is coming.

3 months The gap most reviewers will bridge before they ask for a report

Why the gap exists at all

A Type 2 report covers a stated period, say 1 January to 31 December. It is issued four to ten weeks after that period ends, and then it sits still while the calendar does not. By March a prospect reading it is looking at evidence about a period that finished three months ago, and a reviewer doing their job will ask what happened since.

That is not a defect in your program. Every company with an annual report has the same gap, and it widens until the next report is issued.

What a bridge letter contains

There is no AICPA form for this and no standard wording. A letter a reviewer will accept covers six things.

  1. Identify the report: the service auditor's name, the report type, and the exact period covered.
  2. State the bridge period: from the day after the report period ended, to the date you are signing.
  3. Assert that the controls described in the report continued to operate over that bridge period.
  4. Disclose changes. New systems, a cloud migration, a change of subservice organisation, a material change in key personnel, or a security incident. Silence here is the part that gets a letter rejected later.
  5. State when the next report period ends and when the report is expected. A date does more for a reviewer's confidence than the rest of the letter.
  6. Sign it. An officer of the company, usually the CEO, CTO or whoever signed the management assertion in the report itself.

Do not ask your auditor to sign it

A bridge letter is a management representation, not an assurance product. A CPA firm cannot opine on a period it did not examine. A firm asked to sign one will decline, and a firm that agrees is doing something it should not. Some firms will review your draft for wording, which is worth asking for and is not the same as signing.

How long a bridge letter stretches

How reviewers typically treat a bridge letter by gap length
Gap since period endUsual receptionWhat to send with it
Under 3 monthsAccepted routinelyThe letter and the report
3 to 6 monthsAccepted with questionsAdd the next period end date and a current penetration test summary
6 to 9 monthsOften refusedAdd the audit engagement letter for the period in progress
Over 9 monthsTreated as no reportNothing bridges this. The next report is the answer

A reviewer is deciding how much of your evidence is still evidence. At three months most of it is. At nine months the report describes a company that has hired, shipped and changed vendors since, and no letter from you can substitute for testing.

The Canadian wrinkle

Nothing in PIPEDA, Law 25 or PHIPA mentions bridge letters, and none of them is satisfied by one. Canadian companies sometimes hand a bridge letter to a customer asking a privacy question rather than a security one. If the request came from a Quebec customer citing Law 25, or from a health custodian under PHIPA, the answer they need is about your privacy obligations and not about your SOC 2 report period. What SOC 2 does and does not cover under Canadian privacy law sets out which is which.

The shape of one, in plain words

Write it on your own letterhead, keep it to a page, and avoid the phrase "certifies". A workable structure runs: we engaged [firm] to examine our controls for the period [dates] and received a SOC 2 Type 2 report dated [date]. From [day after period end] to [today], the controls described in that report have continued to operate. During this period the following changes occurred: [list them, or state that there were none]. We are aware of no security incident that would affect the conclusions in the report. Our next examination covers [period] and we expect the report by [date].

Then sign it, date it, and reissue it every quarter rather than editing the date on the old one. A letter dated four months ago tells a reviewer you have not looked at this since.

When a bridge letter is not the right answer

If you have never held a report, there is nothing to bridge from, and a letter asserting controls nobody has examined is worth nothing to a reviewer. The thing to send instead is a signed audit engagement letter with the period dates in it, plus a current penetration test summary. The deadline back-calculator tells you what can realistically exist by the date the customer named, and what to offer instead of a report ranks the substitutes buyers actually accept.

If the gap is long because the last audit slipped rather than because the calendar moved, say so plainly. Reviewers deal with slipped audits constantly, and they deal with a company that hid one exactly once.

Get the next report scheduled

The only permanent fix for a widening gap is the next examination. Tell us your scope and we will put it in front of Canadian firms.

Get matched

A bridge letter is also how coverage stays continuous when you move to a new audit firm and its first period cannot start the day after the last one ended. Changing SOC 2 auditors covers the timing.

Common questions

What is a SOC 2 bridge letter?

A short statement signed by your own management covering the period between the end of your SOC 2 report period and the date a customer is reviewing you. It asserts that the controls in the report continued to operate and discloses anything that changed. It carries no auditor opinion and costs nothing to produce.

Who signs a SOC 2 bridge letter?

An officer of your company, usually whoever signed the management assertion inside the report. The audit firm does not sign it and should decline if asked, because it cannot give assurance over a period it did not examine.

How long is a bridge letter valid?

There is no formal validity period. In practice reviewers accept one for a gap of up to three months without argument, ask questions between three and six, and stop accepting it beyond about six. Reissue it quarterly with a current date rather than sending an old one.

Can a bridge letter replace an annual SOC 2 report?

No. It bridges a gap between reports and cannot substitute for one. A company relying on bridge letters instead of commissioning the next examination will lose deals to reviewers who notice, and most of them notice.

Does a bridge letter help with a PIPEDA or Law 25 question?

No. Canadian privacy statutes impose obligations that a SOC 2 report does not discharge and a bridge letter does not touch. If the question came from a privacy reviewer rather than a security one, answer it with your privacy program rather than with an audit document.