Your SOC 2 Type 2 covers 1 January to 31 December. It is now March, a prospect is in a security review, and their vendor risk team wants to know what happened in the eleven weeks since the period ended. The usual answer is a bridge letter, and it will probably satisfy them.
What it will not do is extend your auditor’s opinion. A bridge letter — also called a gap letter — is a statement written and signed by your management, not by your service auditor. Nobody tested the assertions in it. That single fact determines everything about how far a bridge letter can reasonably be stretched, and it is the point most people miss when they treat the letter as a mini-report.
What a bridge letter actually says
The content is short and fairly standard across firms. A typical bridge letter identifies the SOC report it relates to, the period that report covered, and the gap period being addressed — say 1 January to 15 March. It then states, on management’s behalf, roughly three things:
- There have been no material changes to the system, the control environment or the controls described in the report during the gap period.
- Management is not aware of any control failures, security incidents or other matters during the gap period that would materially affect the description or the controls.
- Where changes have occurred — a new subservice organization, a significant infrastructure migration, a reorganization — those are disclosed.
It is signed by someone who can credibly make that statement: commonly the CFO, CISO, head of compliance or another officer with visibility across the environment. It normally names the next examination period so the reader can see when audited coverage resumes.
That third element matters more than people give it credit for. A bridge letter that says “no changes” when you moved your production workload to a different cloud region in February is a false statement made by an officer of your company. Disclose the change and describe how the controls carried across.
The distinction that makes it a bridge and not a report
Your Type 2 report contains an independent service auditor’s opinion, formed after testing samples of control operation across the period, supported by working papers. It is an attestation engagement performed under professional standards.
A bridge letter contains none of that. No sampling, no testing, no independent opinion, no professional standards behind the conclusion. It is a representation by the people who run the system that the system kept running the way the report described.
That is not worthless — a signed statement from an officer carries real weight, and misrepresenting it has consequences. But it is a different category of assurance, and a vendor risk reviewer who understands the difference will treat it accordingly. If someone asks you whether the bridge letter is audited, the honest answer is no.
Practice on who drafts the letter varies. Some service organizations write it entirely themselves. Some ask their service auditor to review the wording so it does not accidentally imply audit coverage. Firms differ on how involved they are willing to be, and a CPA firm that has issued your opinion has good reason to keep clear of anything that reads as extending it. Ask your auditor what they will and will not do before you promise a customer a turnaround time.
How long a gap a bridge letter can reasonably cover
There is no universal rule here, which is exactly why the question comes up so often.
The common convention is that a bridge letter covers around three months, and many user auditors and vendor risk teams treat roughly that as the outer limit of what they will accept without additional work. The reasoning is straightforward rather than regulatory: the longer the unaudited stretch, the less an untested “nothing changed” statement tells you. Six months of unexamined operation is a meaningful blind spot in a control environment that is supposed to be continuously effective.
Some reviewers are stricter, some are more relaxed, and financial statement auditors relying on a SOC 1 will make their own judgement about whether the gap requires alternative procedures at the user entity. If you are being asked to bridge a gap approaching half a year, the underlying problem is usually your reporting calendar rather than the letter.
What a bridge letter does not cover
Worth being explicit, because these show up in real reviews:
It does not cover changes it discloses. If you disclose that you onboarded a new subservice organization in February, the letter tells the reader that happened. It does not give them any assurance about controls at that provider. They will have to go and look.
It does not extend the trust services categories. A letter cannot bridge you into Availability if your report only covered Security.
It does not cure exceptions in the report itself. If your Type 2 has a noted exception in access reviews, a bridge letter saying you are not aware of failures does not resolve it. Remediation and the next examination do.
It does not work as a substitute for a report. A company that has never completed a Type 2 cannot bridge from nothing. There has to be an examined period behind it.
It does not roll forward indefinitely. Issuing a fresh bridge letter every quarter for eighteen months because the next audit keeps slipping is a pattern reviewers notice.
Getting your calendar to reduce the need for one
Bridge letters exist because report periods end and reports take time to issue. You can shrink the problem structurally.
Pick a period end that suits your buyers. If most of your enterprise customers run security reviews around their fiscal year end, ending your period a couple of months before that means the report lands when they are looking. Some service organizations with heavy financial services exposure choose period ends specifically to serve user auditors.
Keep periods contiguous. Each new examination period should begin the day after the last one ended, so there is no uncovered stretch inside your history. Buyers reading your second and third reports check this.
Then close the reporting lag. The gap a bridge letter covers is period end to today, and a big share of that is often fieldwork and report production. Having populations, tickets and review records ready when the period closes moves issuance earlier and makes the letter cover weeks rather than months.
Handling the request when it comes in
When a customer asks for a bridge letter, three questions save time. What date do they need it through? Are they asking because their own audit needs it, or because a vendor questionnaire has a box? And will they also want the next report when it issues, so you can tell them when that is?
Keep a template your management is comfortable signing, keep a running note of material changes so you are not reconstructing the quarter from memory, and refuse to sign anything you cannot support. A letter that overstates is worse than a gap honestly described.
What to do next
Look at your last report’s period end date and count forward to today. If you are past about three months and your next examination has not started, the fix is scheduling, not paperwork — get the next period underway before the letters start stacking up.
If you are drafting one now, read it once more as a sceptical reviewer would and check that nothing in it implies your auditor examined the gap period. Assurion issues SOC 1 and SOC 2 opinions as a licensed CPA firm, and we will tell you plainly where a bridge letter helps and where it is being asked to do a report’s job.