Skip to main contentChat with us

Learn · SOC Reports

SOC 2 Bridge Letters,
Explained

A bridge letter — also called a gap letter — covers the months between the end of your SOC 2 observation period and the date a customer is asking about. It states whether anything material has changed. It is not a second audit, and it is not signed by your auditor.

The point everyone gets wrong: a bridge letter is issued and signed by your management. The CPA firm that performed the examination carries out no procedures on the gap period and gives no assurance over it. A letter that implies otherwise misrepresents the auditor.

~3 mogap a bridge letter credibly covers
0audit procedures behind it
250+SOC 2 engagements supported by TCSA

Plain-English explainer · Management representation · Last reviewed August 2026

A SOC 2 bridge letter is a short, signed statement from service-organisation management saying whether its system and controls have materially changed since the end of the period covered by its most recent SOC 2 report. It exists because report periods end and sales cycles do not. A customer reviewing you in November, holding a report that closed in July, wants to know what happened in between. Rather than commissioning a second examination for four months, you write a letter. The letter is useful, widely accepted, and routinely oversold.

Anatomy

What a bridge letter must contain

Identification of the underlying report

The service auditor, whether it was a Type 1 or Type 2, and the exact period covered. A reader must be able to tie the letter to a specific report.

The gap period

From the day after the report period ended to a stated date — usually the date of the letter. Never leave the end date open.

A material-change statement

Whether the system, control environment, or controls have materially changed since the period end — and a description of any changes that did occur. Silence is not the same as "no changes".

Known control failures and incidents

A statement that management is not aware of control failures or security incidents in the gap period that would affect the report’s conclusions — or disclosure of those that occurred.

Explicit no-assurance caveats

That the letter is a representation of management, that the service auditor performed no procedures over the gap period, and that the letter provides no assurance. This paragraph is the one most often left out, and it is the one that protects you.

Language discipline

Sentences that overstate assurance

A bridge letter goes wrong when it borrows the vocabulary of an audit opinion. These are the phrasings we ask clients to remove.

“Our controls continue to operate effectively.”

Operating effectiveness is an auditor’s conclusion reached through testing. Management can say it is not aware of failures; it cannot assert tested effectiveness for an untested period.

“This letter extends our SOC 2 report through 31 December.”

Nothing extends a report. The report covers what it covers. The letter addresses the gap; it does not lengthen the examination.

“Our auditor confirms no material changes.”

The auditor confirms nothing here. If a reader relies on this and it is untrue, the misrepresentation is yours and it names your CPA firm.

“We remain SOC 2 certified.”

There is no SOC 2 certification. It is an attestation performed under AT-C 205. This phrasing invites a knowledgeable reviewer to discount everything else in the letter.

Frequently Asked Questions

Who signs a SOC 2 bridge letter — the CPA or us?

Your management signs it. A bridge letter is a management representation, not a second CPA opinion. The service auditor performs no procedures over the gap period and normally is not a party to the letter. Some firms will review the wording so it does not misrepresent their work, but reviewing wording is not providing assurance.

A customer is asking for a bridge letter four months after our report. Is that normal?

Yes, entirely. Vendor-risk policies vary, and a customer whose policy requires assurance no older than a quarter will ask even when other customers are satisfied with the report alone. Treat it as a routine request rather than a signal that something is wrong.

How long a gap can a bridge letter cover?

There is no defined limit — this is market practice, not a standard. Roughly three months is the range most reviewers accept without further questions. Past that, the letter is carrying more weight than a management representation reasonably can, and customers increasingly ask when the next observation period closes instead.

Do we have to disclose changes in the bridge letter?

Yes, and this is where letters most often fail. If you changed cloud providers, replaced your identity provider, onboarded a new subservice organisation, or had a security incident, the letter must say so. A letter asserting no material changes that is later contradicted by your own next Type 2 report is a serious credibility problem — and the next report is exactly where a reviewer will look.

What should we check before signing one?

Verify rather than assume: review the change-management log for material system or control changes, review incident and exception records for the gap period, confirm no key subservice organisation changed, and check the remediation status of any exceptions noted in the report. The signature is a representation by a named officer — it should rest on records, not recollection.

Related reading: how long a SOC 2 report stays usable, bridge letters in the SOC 1 context, opinions and exceptions, and the SOC 2 hub.

Written By Expert Auditors

Surendra Pal Singh
Surendra Pal Singh
Chief Information Security Officer & Data Protection Officer
CISODPOCISAMCSEITILISO 27001 Lead AuditorISO 27701 Lead AuditorISO 42001 Lead Auditor
Saundhi Chauhan
Saundhi Chauhan
Lead Auditor
ISO 27001 Lead AuditorISO 27701 Lead Auditor
Last reviewed: August 2026Content verified by certified lead auditors

Get in touch

Book a free consultation or send us your requirements. We respond within 24 hours.

Quick Call

Pick a time slot

Send Requirements

Get a custom quote in 24 hours

We're Online

⚠️ Business inquiries only. Personal email addresses will be rejected.

24hr Response
Free Consultation
No Obligations