SOC2Prep

SOC 2 bridge letters: what to write

You write it, not your auditor. It is one page, it costs nothing, and it is the single most common request a Canadian vendor gets between report cycles.

Last reviewed 2026-09-01Written by Jacob Masse, TrazTech Inc.

A bridge letter, sometimes called a gap letter, is a one-page statement on your letterhead saying that between the end of your SOC 2 report period and the date of the letter, nothing material changed in the control environment, or naming what did. You write it, an officer signs it, and your audit firm neither issues it nor reviews it. Buyers generally accept one covering up to about three months, sometimes six, and almost never more than that, at which point they want the next report.

1 page Length, including the signature

3 to 6 months Gap a buyer will usually accept one for

$0 What it should cost you

Why do buyers ask for one?

Because a SOC 2 Type 2 report is historical. A report covering January to December says nothing about February of the following year, and a security reviewer signing off on a vendor in April is being asked to rely on a document whose evidence stopped four months ago. The bridge letter is the vendor's own statement covering that interval. It carries no auditor assurance at all, which is exactly why it is free and why it only stretches so far. The period end is the third thing a reviewer looks at, which is why the gap surfaces so quickly, and what your customer's reviewer checks walks the rest of that reading order.

Do not ask your auditor for one

Some firms will politely decline, some will explain why, and a few will quote you for it. There is no professional standard under which a CPA firm provides assurance over a period it did not examine, so anything you are sold here is either the same letter with a logo on it or a separate engagement. The letter is yours to write.

What goes in it?

Bridge letter contents, and why each element is there
ElementWhat it saysWhy it matters
AddresseeTo the customer, or "To whom it may concern"A named addressee reads better; a generic one lets you reuse the letter
Report identificationReport type, auditor name, exact period coveredThe reviewer is matching it against the report they hold
Bridge periodFrom the day after the period end to the date of the letterVague wording here is the most common reason a letter is bounced
Statement on controlsThat controls continued to operate and no material changes occurredThe substance of the letter
Exceptions, if anyNamed changes: a new cloud region, an acquisition, a security incidentOmitting a known change is the one way this letter creates real risk
Next reportThe period the next report will cover and when it is expectedTurns a gap into a plan and is what unblocks cautious reviewers
LimitationThat this letter is unaudited and management's own statementHonest, and it is what a careful reviewer is checking for
SignatureAn officer: CEO, CTO, or the person who signed the management assertionSigned by a marketing address, it is worth nothing

What counts as a material change?

Disclose rather than argue. A letter that says nothing changed, followed by a customer discovering that you moved cloud providers in month two, is worse than having sent no letter. These are the ones that should be named.

0 of 0 done ·

Ordinary engineering change is not material. Shipping features, adding services inside the same architecture, and hiring engineers are all normal operation, and a letter listing them reads as though you do not understand the question. What matters is whether a control described in the report still operates the way it was described.

What a bridge letter cannot do

Situations where a bridge letter is the wrong instrument
SituationWhy the letter failsWhat actually works
Report period ended 14 months agoThe gap is longer than the reportThe next report, or an interim Type 1
You never had a report and want to cover the waitThere is nothing to bridge fromAn engagement letter from your audit firm with the window dates
The report had significant exceptionsThe buyer's concern is the report, not the gapA written remediation plan with dates
The buyer wants assurance over the gap periodYour own statement is not assuranceA shorter observation window next cycle, or a Type 1 at an interim date
Scope changed and the new system is out of the reportThe letter cannot extend scopeSay so plainly and give the date the new scope enters a report

How to stop needing one every quarter

Align your report period end with your renewal season rather than with your fiscal year. Most Canadian SaaS companies inherit a December period end because that is what the first auditor proposed, then spend every spring bridging into enterprise renewals. Moving the period end to align with when reports are actually requested removes most bridge letter requests permanently, and it costs one transitional period of an unusual length.

The counter-case: a December period end is simpler to explain internally, lines up with other year-end work, and audit firms have more capacity outside their own busy season, which occasionally shows up in the fee. If bridge letters are a minor annoyance rather than a deal problem, leaving it alone is a defensible choice.

The bridge letter is one of several things to set up the week a report arrives. What to publish once your SOC 2 report arrives has the full list.

Who writes a SOC 2 bridge letter?

You do. It goes on your letterhead and is signed by an officer of the company, usually whoever signed the management assertion in the report. Your audit firm does not issue it and should not be asked to.

How long is a bridge letter valid?

It covers the period it names, ending on the date it is signed, so it is never valid into the future. In practice buyers accept letters covering up to three months routinely and up to six with some reluctance. Past that, most vendor security teams want the next report.

Is a bridge letter audited?

No. It carries no assurance whatsoever and is purely a management representation, which is why it costs nothing. Saying so in the letter is better practice than leaving it implied, because reviewers who know the difference trust the letter more when it is honest about what it is.

Do we need one if our report is only two months old?

Usually not, but write it once and keep the template. Most requests arrive from procurement processes that ask automatically regardless of the dates, and sending a signed letter within a day is a better answer than explaining why one is unnecessary.

What else will the buyer ask for alongside it?

A penetration test report, a subprocessor list, insurance evidence and a completed questionnaire, among others. What a US buyer asks for besides SOC 2 has the full list and the lead time on each.

Get the next report scheduled

If bridge letters are covering a gap that keeps growing, the fix is the next window rather than a better letter.

Get matched