SOC 2 bridge letters: what to write
You write it, not your auditor. It is one page, it costs nothing, and it is the single most common request a Canadian vendor gets between report cycles.
A bridge letter, sometimes called a gap letter, is a one-page statement on your letterhead saying that between the end of your SOC 2 report period and the date of the letter, nothing material changed in the control environment, or naming what did. You write it, an officer signs it, and your audit firm neither issues it nor reviews it. Buyers generally accept one covering up to about three months, sometimes six, and almost never more than that, at which point they want the next report.
1 page Length, including the signature
3 to 6 months Gap a buyer will usually accept one for
$0 What it should cost you
Why do buyers ask for one?
Because a SOC 2 Type 2 report is historical. A report covering January to December says nothing about February of the following year, and a security reviewer signing off on a vendor in April is being asked to rely on a document whose evidence stopped four months ago. The bridge letter is the vendor's own statement covering that interval. It carries no auditor assurance at all, which is exactly why it is free and why it only stretches so far. The period end is the third thing a reviewer looks at, which is why the gap surfaces so quickly, and what your customer's reviewer checks walks the rest of that reading order.
Do not ask your auditor for one
Some firms will politely decline, some will explain why, and a few will quote you for it. There is no professional standard under which a CPA firm provides assurance over a period it did not examine, so anything you are sold here is either the same letter with a logo on it or a separate engagement. The letter is yours to write.
What goes in it?
| Element | What it says | Why it matters |
|---|---|---|
| Addressee | To the customer, or "To whom it may concern" | A named addressee reads better; a generic one lets you reuse the letter |
| Report identification | Report type, auditor name, exact period covered | The reviewer is matching it against the report they hold |
| Bridge period | From the day after the period end to the date of the letter | Vague wording here is the most common reason a letter is bounced |
| Statement on controls | That controls continued to operate and no material changes occurred | The substance of the letter |
| Exceptions, if any | Named changes: a new cloud region, an acquisition, a security incident | Omitting a known change is the one way this letter creates real risk |
| Next report | The period the next report will cover and when it is expected | Turns a gap into a plan and is what unblocks cautious reviewers |
| Limitation | That this letter is unaudited and management's own statement | Honest, and it is what a careful reviewer is checking for |
| Signature | An officer: CEO, CTO, or the person who signed the management assertion | Signed by a marketing address, it is worth nothing |
What counts as a material change?
Disclose rather than argue. A letter that says nothing changed, followed by a customer discovering that you moved cloud providers in month two, is worse than having sent no letter. These are the ones that should be named.
0 of 0 done ·
Ordinary engineering change is not material. Shipping features, adding services inside the same architecture, and hiring engineers are all normal operation, and a letter listing them reads as though you do not understand the question. What matters is whether a control described in the report still operates the way it was described.
What a bridge letter cannot do
| Situation | Why the letter fails | What actually works |
|---|---|---|
| Report period ended 14 months ago | The gap is longer than the report | The next report, or an interim Type 1 |
| You never had a report and want to cover the wait | There is nothing to bridge from | An engagement letter from your audit firm with the window dates |
| The report had significant exceptions | The buyer's concern is the report, not the gap | A written remediation plan with dates |
| The buyer wants assurance over the gap period | Your own statement is not assurance | A shorter observation window next cycle, or a Type 1 at an interim date |
| Scope changed and the new system is out of the report | The letter cannot extend scope | Say so plainly and give the date the new scope enters a report |
How to stop needing one every quarter
Align your report period end with your renewal season rather than with your fiscal year. Most Canadian SaaS companies inherit a December period end because that is what the first auditor proposed, then spend every spring bridging into enterprise renewals. Moving the period end to align with when reports are actually requested removes most bridge letter requests permanently, and it costs one transitional period of an unusual length.
The counter-case: a December period end is simpler to explain internally, lines up with other year-end work, and audit firms have more capacity outside their own busy season, which occasionally shows up in the fee. If bridge letters are a minor annoyance rather than a deal problem, leaving it alone is a defensible choice.
The bridge letter is one of several things to set up the week a report arrives. What to publish once your SOC 2 report arrives has the full list.
Who writes a SOC 2 bridge letter?
You do. It goes on your letterhead and is signed by an officer of the company, usually whoever signed the management assertion in the report. Your audit firm does not issue it and should not be asked to.
How long is a bridge letter valid?
It covers the period it names, ending on the date it is signed, so it is never valid into the future. In practice buyers accept letters covering up to three months routinely and up to six with some reluctance. Past that, most vendor security teams want the next report.
Is a bridge letter audited?
No. It carries no assurance whatsoever and is purely a management representation, which is why it costs nothing. Saying so in the letter is better practice than leaving it implied, because reviewers who know the difference trust the letter more when it is honest about what it is.
Do we need one if our report is only two months old?
Usually not, but write it once and keep the template. Most requests arrive from procurement processes that ask automatically regardless of the dates, and sending a signed letter within a day is a better answer than explaining why one is unnecessary.
What else will the buyer ask for alongside it?
A penetration test report, a subprocessor list, insurance evidence and a completed questionnaire, among others. What a US buyer asks for besides SOC 2 has the full list and the lead time on each.
Get the next report scheduled
If bridge letters are covering a gap that keeps growing, the fix is the next window rather than a better letter.
Get matched