SOC 2 Bridge LetterWhat It Is, When You Need One, and a Template Your Customers Will Accept
A SOC 2 bridge letter, also called a gap letter, is a short signed statement from a service organization's management that covers the period between the end of its most recent SOC 2 report and the date a customer needs assurance. It confirms whether the controls described in the last report have continued to operate and whether anything material changed. Petronella Technology Group has helped regulated businesses in the Research Triangle and nationwide prepare for SOC 2 examinations since 2002, and this page explains exactly what a bridge letter can and cannot do, what one must contain, and how to write one that a vendor risk team or a user auditor will accept.
- A bridge letter is written by you, not by your auditor. It is a management representation. The CPA firm that issued your SOC 2 report does not sign it, does not test anything for it, and its opinion does not extend to it. A customer who treats a bridge letter as audited assurance is misreading it, and a vendor who implies otherwise is misrepresenting it.
- It covers a gap, not a year. Most user entities and their auditors accept a bridge letter for a gap of up to three months after the report period ends. Some will stretch to six. Past that, the honest answer is a new report, not a longer letter.
- It has a fixed set of contents. The report it bridges, the period it covers, a statement about material changes to the system and controls, a statement that controls continued to operate, any exceptions or incidents, a signature from an officer, and a date. Leave one out and the letter will bounce back.
- A letter without evidence behind it is a liability. When you state that controls continued to operate, you should be able to show the access reviews, vulnerability scans, change tickets, and monitoring records that prove it. That is where continuous compliance tooling earns its keep.
- It cannot cover a period before your first report. If you have never completed a SOC 2 examination, there is nothing to bridge. The right tools for that situation are a readiness assessment, a SOC 2 Type 1 report, or a completed security questionnaire.
What Is a SOC 2 Bridge Letter?
A SOC 2 bridge letter is a dated, signed document in which the management of a service organization states that, since the end of the review period covered by its most recent SOC 2 report, there have been no material changes to the system description or the controls the report examined, or discloses what changed, and that the controls have continued to operate. The term "gap letter" describes the same document. It exists because SOC 2 Type 2 reports cover a defined review period in the past, typically six or twelve months, while customers need assurance about today.
The mechanics are simple. Suppose your SOC 2 Type 2 report covers January 1 through December 31. The auditor completes fieldwork in January and issues the report in February. A customer performing annual vendor due diligence in April now holds a report whose coverage ended four months ago. They ask a fair question: what has happened since? The bridge letter is your answer. It bridges the end of the report period to the date of the letter, which is why the period it covers is often called the gap period or the stub period.
Two things distinguish a bridge letter from the report it extends. First, authorship: the report is issued by an independent CPA firm under AICPA attestation standards, while the bridge letter is issued by the service organization's own management. Second, assurance: the auditor tested controls and expressed an opinion in the report, while the bridge letter contains management's representation only, with no testing behind it other than what management chooses to describe. That difference is not a weakness to hide. It is the reason the letter is short, the reason customers limit how long a gap they will accept, and the reason the letter should point back to a real report instead of trying to stand on its own.
- A management representation covering the period after a completed SOC 2 report
- Signed and dated by an officer of the service organization, usually the CEO, CFO, CISO, or compliance lead
- Specific about which report it bridges: the report type, the review period, and the issuing CPA firm
- Explicit about material changes to people, processes, systems, subservice organizations, or controls, or the absence of them
- A short document, usually one page, provided on request to customers, prospects, and their auditors
- Not an extension of the auditor's opinion; the CPA firm does not sign, review, or take responsibility for it
- Not a substitute for a SOC 2 report, and not accepted for indefinite gaps
- Not a place to describe controls that were never in the original report's scope
- Not a certification, a "SOC 2 certificate," or a badge; SOC 2 produces reports, not certificates
- Not available for a service organization that has never completed an examination, because there is no report to bridge
The SOC 2 Report Cycle and Where the Bridge Letter Fits
Every SOC 2 Type 2 engagement has three dates that matter to a bridge letter: the first day of the review period, the last day of the review period, and the report issuance date. The review period is the window during which the auditor tests whether controls operated effectively. Fieldwork, evidence review, and report drafting happen after the period closes, so the report is usually issued several weeks to a few months after the last day it covers. From the customer's point of view, coverage ends on the period end date, not on the issuance date, and not on the day they download the report from your trust portal.
Organizations that examine annually therefore have a predictable rhythm. For part of the year the current report is fresh. As the months pass, the gap between the period end and today grows, and customers begin asking for a bridge letter. Once the next examination's review period closes and its report is issued, the cycle resets. Organizations that keep a continuous, back-to-back review period, where the next period starts the day after the previous one ended, keep the gap as short as possible and rarely need a letter that covers more than the fieldwork and issuance lag. Organizations that let periods lapse, skip a year, or change auditors mid-stream generate longer gaps and more letter requests. Our SOC 1 vs SOC 2 guide explains the report types in detail, and our SOC 2 Type II page covers how a review period is chosen.
Five Situations That Call for a SOC 2 Bridge Letter
Bridge letters are reactive documents. Most are written because someone asked. Knowing the situations that generate the request lets you prepare the letter and, more importantly, the evidence behind it before the request lands in a deal-blocking email.
A customer's annual vendor review lands mid-gap
Enterprise vendor risk programs review critical vendors on their own calendar, not yours. If their review falls three months after your period end, they will ask for the report plus a letter covering the months since. This is the most common trigger and the easiest to anticipate.
Your customer's own auditor needs coverage through their year-end
When your service affects a customer's financial reporting or their own SOC examination, their auditor wants control coverage through the customer's fiscal year-end. If your period ends September 30 and their year ends December 31, a bridge letter closes the three-month difference.
A sales cycle or RFP falls between reports
Procurement teams ask for "your current SOC 2." If the current report's period ended several months ago, a bridge letter dated this week shows the prospect that the control environment has been maintained and that you take the question seriously.
The next report is delayed
Auditor scheduling, a scope change, an acquisition, or an unexpected exception can push report issuance out. A bridge letter keeps existing customers covered while the examination finishes, provided the gap stays within what they will accept.
You changed the review period or the auditor
Moving from a June 30 period end to a December 31 period end, or changing CPA firms, can create a one-time gap of several months. A bridge letter that explains the transition and the interim controls is far better received than silence.
When a bridge letter will not work
If you have never completed a SOC 2 examination, if the gap is longer than a customer will accept, or if the controls a customer cares about were never in your report's scope, a bridge letter cannot help. The honest alternatives are a readiness assessment, a Type 1 report, or a scoped examination.
What a SOC 2 Bridge Letter Must Contain
There is no single mandated format. There is, however, a consistent set of elements that vendor risk teams and user auditors look for, and a letter missing any of them is likely to be returned with questions. Write the letter in this order and each reviewer will find what they need without a follow-up call.
Identification of the report being bridged: the report type (SOC 2 Type 2), the Trust Services Criteria categories in scope (for example Security and Availability), the review period start and end dates, the report issuance date, and the name of the CPA firm that issued it.
The gap period the letter covers, stated as explicit dates: from the day after the review period ended through the date of the letter. Do not write "through the present" or "until the next report"; a reviewer needs a fixed end date.
A statement about material changes to the system description, the control environment, key personnel, infrastructure, subservice organizations, or the services provided. Either state that there were none, or describe each change and its effect on the controls in the report.
A statement that the controls described in the report have continued to operate as described during the gap period, to the best of management's knowledge, and a short description of how management knows this: monitoring, internal reviews, evidence collected.
Disclosure of any security incidents, control failures, or exceptions during the gap period that a user entity would reasonably want to know about, along with the remediation status. Omitting a known incident from a bridge letter is the fastest way to lose a customer's trust permanently.
A clear statement that the letter is a representation of management, that it was not prepared or reviewed by the service auditor, and that the auditor's opinion in the referenced report does not extend to the gap period.
The expected date of the next report, or the review period currently in progress, so the reader knows when audited coverage will resume.
A signature, printed name, title, and date from an officer with authority to make the representation, on company letterhead, with a distribution statement if you restrict who may receive it.
SOC 2 Bridge Letter Template
The template below contains every element from the list above in the order reviewers expect. Replace the bracketed placeholders, delete the alternative sentences you do not need, and put the result on letterhead. Have counsel review it the first time you use it; after that, the same structure can be reused each cycle with updated dates and facts. Keep the letter to one page. Length signals nothing, and a long letter invites more questions than it answers.
[Company Letterhead]
[Date of Letter]
To: User entities of [Company Name] and their auditors
Re: Bridge letter for the SOC 2 Type 2 report of [Company Name] covering the [System or Service Name] system for the period [Review Period Start Date] through [Review Period End Date]
[Company Name] engaged [CPA Firm Name] to perform a SOC 2 Type 2 examination of the [System or Service Name] system relevant to the Trust Services Criteria for [Security, Availability, Confidentiality, Processing Integrity, and/or Privacy] for the period [Review Period Start Date] through [Review Period End Date]. [CPA Firm Name] issued its report dated [Report Issuance Date]. This letter covers the period from [Day After Review Period End Date] through the date of this letter (the "gap period").
Management of [Company Name] represents that, to the best of its knowledge and belief, during the gap period:
1. There have been no material changes to the system description, the control environment, the controls described in the report, key personnel responsible for those controls, the infrastructure supporting the system, or the subservice organizations used by [Company Name]. [Alternative: The following changes occurred during the gap period: [describe each change and its effect on the controls described in the report].]
2. The controls described in the report have continued to operate as described. Management bases this representation on its ongoing monitoring activities, including [access reviews, vulnerability management, change management review, security monitoring, and internal control testing] performed during the gap period.
3. [Company Name] is not aware of any security incidents, control failures, or other events during the gap period that would materially affect the conclusions a user entity would draw from the report. [Alternative: The following incident occurred on [date]: [brief description, affected controls, and remediation status].]
The next SOC 2 Type 2 examination covers the period [Next Review Period Start Date] through [Next Review Period End Date], and the resulting report is expected to be issued in [Month and Year].
This letter is a representation of the management of [Company Name]. It was not prepared, reviewed, or examined by [CPA Firm Name], and the opinion expressed in the report referenced above does not extend to the gap period or to this letter. This letter is provided solely for the use of user entities of [Company Name] and their auditors and may not be relied upon by any other party.
Sincerely,
[Signature]
[Printed Name]
[Title, for example Chief Executive Officer or Chief Information Security Officer]
[Company Name]
Two drafting notes. First, the phrase "to the best of its knowledge and belief" is standard and appropriate, but it is not a shield: if management knew of an incident and left it out, the qualifier does not help. Second, resist the temptation to add descriptions of controls that were not in the original report. A bridge letter cannot expand scope. If a customer needs coverage of a control you did not examine, that is a scoping conversation for the next audit, and a good SOC 2 compliance checklist will show where the scope should grow.
Need a Bridge Letter This Week and the Evidence to Stand Behind It?
Petronella Technology Group prepares SOC 2 bridge letters with the supporting evidence pack that vendor risk teams ask for next: the access review records, vulnerability scan history, change tickets, and monitoring logs from the gap period, organized in ComplianceArmor® so the letter's representations are backed by something a reviewer can see. If you have a customer deadline, tell us the date.
How Long Can a Bridge Letter Cover?
No standard sets a maximum gap. Acceptance is decided by the reader: the customer's vendor risk policy, or the professional judgment of the user auditor relying on your report. In practice the expectations are consistent enough to plan around. A gap of up to three months is routinely accepted. A gap of three to six months is accepted by some organizations, often with additional questions or a request for interim evidence. Beyond six months, most reviewers will decline the letter and ask for a new report, and some vendor risk policies flag any vendor whose most recent report period ended more than a year ago regardless of what letters were provided.
The practical rule that follows: schedule examinations so that the review periods run back to back, and start fieldwork planning before the current period closes. A service organization on a continuous annual cycle almost never needs a letter that covers more than the two or three months of fieldwork and issuance lag, and its letters are accepted without argument. Organizations we help with ongoing SOC 2 compliance plan the next review period as part of closing the current one for exactly this reason.
Who Writes, Signs, and Reviews a Bridge Letter
The bridge letter belongs to management. It is typically drafted by the compliance or security lead who owns the SOC 2 program, reviewed by counsel the first time and whenever material changes must be described, and signed by an officer: the CEO, CFO, COO, or CISO, depending on who is accountable for the control environment in your organization. The signer should be someone who can be held to the representation, which is why a sales engineer or an account manager should never sign one, however urgent the deal.
The service auditor's role is deliberately limited. The AICPA's SOC 2 guidance treats the bridge letter as a communication from the service organization to its user entities. The auditor does not perform procedures on the gap period, does not review the letter as part of the engagement, and does not extend the report's opinion to it. Some CPA firms will share a template or comment informally on wording, but the letter still goes out under management's signature and management's responsibility. If a customer asks whether your auditor "approved" the bridge letter, the correct answer is no, and the letter itself should already say so.
On the receiving side, the reader is usually a vendor risk analyst applying a third-party risk policy, or a user auditor deciding how much reliance to place on your report for a client's financial statement or SOC examination. Both are trained to look for the elements listed above and to reject letters that are vague about dates, silent on incidents, or missing the auditor disclaimer. Writing the letter with those readers in mind is the whole craft.
How to Evaluate a Vendor's Bridge Letter
Most of our clients are on both sides of this document. They issue bridge letters to their customers, and they receive them from their own vendors: cloud hosts, payroll processors, managed service providers, and software platforms that touch regulated data. A bridge letter from a vendor deserves the same scrutiny your customers apply to yours. Use this checklist when one arrives as part of your IT vendor management review.
- It names a specific SOC 2 report you have also received, with matching dates and CPA firm
- The gap period has explicit start and end dates and the end date is recent
- The gap is within your policy, typically three months, or six with interim evidence
- It addresses material changes, continued operation, and incidents as three separate statements
- It is signed by a named officer, dated, on letterhead, and carries the auditor disclaimer
- The vendor can name the next review period and expected issuance month
- The letter covers "the present" or "until further notice" with no end date
- It describes controls or Trust Services Criteria categories that are not in the referenced report
- It is unsigned, signed by a sales contact, or dated months before you received it
- It is silent on incidents when you know from the news or from your own logs that something happened
- The gap exceeds six months, or the vendor cannot say when the next report is due
- The vendor offers a bridge letter in place of any report at all; there is nothing to bridge
When a vendor's letter is weak, the follow-up is a short list of targeted questions, not a rejection of the vendor. Ask for the interim evidence behind the representations, and record the answers with the letter in your vendor file. For vendors whose service includes AI features or model access, our AI vendor security questionnaire covers the questions a standard SOC 2 report usually leaves open.
SOC 1 Bridge Letters and SOC 2 Bridge Letters
The bridge letter concept applies to every SOC report type, and the structure is the same. What differs is who relies on it and how strictly. A SOC 1 report covers controls relevant to a user entity's internal control over financial reporting, so a SOC 1 bridge letter is read primarily by the user entity's financial statement auditor, who needs control coverage through the client's fiscal year-end. That reader tends to be the strictest about gap length and about the incident disclosure, because a control failure at a payroll or transaction processor can change an audit conclusion. A SOC 2 bridge letter is read primarily by security, procurement, and vendor risk teams evaluating the vendor's protection of data, and by user auditors in the SOC 2 context. Both letters should follow the same eight-element structure, and a service organization that issues both reports typically issues both letters on the same cycle.
Two edge cases come up often. A vendor with only a SOC 1 report cannot use a SOC 1 bridge letter to answer a SOC 2 request; the reports examine different criteria. And a vendor whose SOC 2 covers only the Security category cannot bridge a customer's questions about Availability or Confidentiality, because the report never addressed them. In both cases the honest response is a scoping conversation, which is usually where our SOC 2 consulting engagements begin.
Six Bridge Letter Mistakes That Get Vendors Flagged
Treating it as a marketing document
Letters that open with paragraphs about the company's commitment to security, then bury the actual representations, get skimmed and returned. The reader wants dates, changes, incidents, and a signature. Everything else is noise.
Vague or missing dates
"Since our last audit" and "through the present" are not periods. Reviewers need a start date, an end date, and the review period of the referenced report so they can compute the gap themselves.
Omitting a known incident
A phishing compromise, an availability event, or a failed backup restore during the gap period belongs in the letter with its remediation status. A customer who learns of it another way will not accept another letter from you.
Implying auditor involvement
Wording that suggests the CPA firm reviewed, approved, or stands behind the letter misstates the auditor's role and can create problems for both parties. State plainly that the auditor was not involved.
Making representations without evidence
"Controls continued to operate" is a strong claim. If nobody ran the quarterly access review or the monthly vulnerability scan during the gap, the letter is wrong, and the next audit will show it. Collect evidence continuously so the letter is simply a summary of what already exists.
Letting the gap grow
The letter is a bridge, not a permanent structure. Organizations that use it to postpone the next examination find that customers stop accepting it, and that the eventual audit is harder because a year of drift has accumulated.
How Petronella Technology Group Supports the Bridge Letter Process
Petronella Technology Group does not issue SOC 2 reports; only a licensed CPA firm can perform the examination under AICPA standards, and we say so at the start of every engagement. What we do is everything around the examination that makes a bridge letter truthful and easy to produce: readiness assessment before the first audit, remediation of gaps, continuous evidence collection during and between review periods, and the drafting and evidence packaging of the letter itself. Craig Petronella, founder of Petronella Technology Group, is a CMMC Registered Practitioner, holds CCNA and CWNE certifications, is a North Carolina Licensed Digital Forensics Examiner (license 604180-DFE), completed MIT Sloan Executive Education in cybersecurity, and is the author of How Hackers Can Crush Your Business, which covers the vendor and third-party risks that SOC 2 programs exist to control.
Gap period evidence review: we inventory what evidence exists for the gap period, control by control, against the controls listed in your report, and identify anything that was not performed so it can be caught up or disclosed.
Change assessment: we compare the current system description, personnel, infrastructure, and subservice organizations to what the report described, and document each change and whether it is material to the controls.
Incident review: we review security monitoring, help desk, and change records for the gap period to confirm what, if anything, must be disclosed, and we word the disclosure and remediation status accurately.
Letter drafting: we prepare the letter on your letterhead using the structure on this page, tailored to the report's scope and to the specific customer or auditor request, ready for counsel review and officer signature.
Evidence pack: we assemble the gap period evidence in ComplianceArmor®, our compliance documentation platform, so that when the reviewer asks "how do you know the controls continued to operate," the answer is a folder, not a promise.
Cycle planning: we schedule the next review period to run back to back with the last one and set the evidence calendar for it, so future bridge letters cover only the fieldwork lag and the question never becomes urgent again.
- In business since April 2002, BBB A+ rated since 2003, and a CyberAB Registered Provider Organization (RPO #1449)
- Rated 4.7 across 92 verified TrustIndex reviews and 5.0 across 15 Google reviews
- SOC 2, HIPAA, CMMC, and PCI DSS programs run in one platform, so a control tested once serves every framework
- Engineers who operate environments, not only assess them, so evidence collection is built into daily operations
- Headquartered in Raleigh, North Carolina, serving the Research Triangle and clients nationwide
"Petronella's work has been a major factor in our business success, helping it to become one of the most secured networks of its kind on the Internet."
Financial Services Firm, Raleigh, NC
Read more verified reviews on TrustIndex or learn more about Petronella Technology Group.
No Letter vs. a Do-It-Yourself Letter vs. an Evidence-Backed Letter
Get a Bridge Letter Drafted, Evidenced, and Ready for Signature
Send us your most recent SOC 2 report and the customer or auditor request that prompted the question. We will review the gap period, identify anything that needs to be disclosed or caught up, and return a letter and evidence pack for your counsel and signing officer. If you have not completed a first examination yet, we will tell you that a bridge letter is the wrong tool and recommend the right one.
SOC 2 Bridge Letter: Frequently Asked Questions
What is a SOC 2 bridge letter?
A SOC 2 bridge letter, also called a gap letter, is a signed statement from a service organization's management covering the period between the end of its most recent SOC 2 report's review period and the date of the letter. It states whether there have been material changes to the system or controls described in the report, whether the controls have continued to operate, and whether any incidents occurred. It is a management representation and is not part of the auditor's report.
Who issues a bridge letter, the auditor or the company?
The company. A bridge letter is written and signed by an officer of the service organization, such as the CEO, CFO, or CISO. The CPA firm that performed the SOC 2 examination does not prepare, review, or sign it, and the opinion in the SOC 2 report does not extend to the period the letter covers. The letter should say this explicitly.
How long can a SOC 2 bridge letter cover?
There is no fixed maximum in any standard, but most customers and user auditors routinely accept a gap of up to three months after the report period ends, some accept up to six months with additional questions or interim evidence, and most decline a letter for a gap longer than six months. A gap beyond twelve months usually means the report itself is treated as expired and a new examination is required.
What should a SOC 2 bridge letter include?
Identification of the report being bridged (type, Trust Services Criteria in scope, review period, issuance date, and CPA firm), the exact gap period dates, a statement about material changes or their absence, a statement that controls continued to operate and how management knows, disclosure of any incidents or control failures with remediation status, a statement that the auditor was not involved, the expected date of the next report, and an officer's signature, title, and date.
Is a bridge letter the same as a gap letter?
Yes. "Bridge letter" and "gap letter" describe the same document. Some organizations also call it a comfort letter, although that term has a different and specific meaning in securities offerings and is best avoided for SOC purposes. Whatever the name, the contents and the limits are the same.
Can we provide a bridge letter if we have never had a SOC 2 audit?
No. A bridge letter extends a completed report, so without a report there is nothing to bridge. Organizations that have not yet completed an examination can offer a completed security questionnaire, a readiness assessment summary, or a SOC 2 Type 1 report, which can be obtained faster than a Type 2 because it examines control design as of a single date rather than operation over a period.
What is the difference between a SOC 1 bridge letter and a SOC 2 bridge letter?
The structure is the same; the report and the reader differ. A SOC 1 bridge letter extends a SOC 1 report on controls relevant to a customer's financial reporting and is read mainly by the customer's financial statement auditor, who needs coverage through the customer's fiscal year-end. A SOC 2 bridge letter extends a SOC 2 report on the Trust Services Criteria and is read mainly by security, procurement, and vendor risk teams. One cannot substitute for the other.
Does Petronella Technology Group write bridge letters?
Yes. Petronella Technology Group drafts the letter, reviews the gap period for changes and incidents that must be disclosed, and assembles the evidence pack in ComplianceArmor® that shows the controls continued to operate. We do not issue SOC 2 reports, which only a licensed CPA firm can do; we prepare organizations for the examination and support them between examinations. Call 919-348-4912 or schedule a free consultation to discuss a current request.
Related SOC 2 and Compliance Pages
SOC 2 Compliance Services
→SOC 1 vs SOC 2
→SOC 2 Type II Reports
→SOC 2 Readiness Assessment
→SOC 2 for Startups
→IT Vendor Management
→IT Audit Services
→ComplianceArmor® Platform
→Last Updated: September 13, 2026 (first published September 13, 2026). This page describes SOC 2 reports issued under the AICPA attestation standards and the Trust Services Criteria, and the management bridge letter practice that accompanies them. Gap acceptance ranges reflect common vendor risk and user auditor practice rather than a published standard; confirm the specific requirement with the customer or auditor who requested the letter. Written by Craig Petronella, CMMC Registered Practitioner, North Carolina Licensed Digital Forensics Examiner, and author of How Hackers Can Crush Your Business.
Answer the Gap Question Before It Stalls a Deal
Petronella Technology Group has prepared regulated businesses for compliance examinations since 2002, holds a BBB A+ rating dating to 2003, and is a CyberAB Registered Provider Organization. Send us the request you received, and we will return a bridge letter and the evidence to stand behind it.