Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

What a SOC 2 bridge letter is and what it is not

Bridge Letter: What It Covers, and What It Does Not

A bridge letter is what a service organisation sends when its SOC 2 report ends in September and a customer needs assurance through December. It is also the most over-trusted document in third-party assurance.

It is written by management, not the auditor. Nothing in it is tested. Understanding exactly what it does and does not carry is the difference between a reasonable stopgap and a false sense of coverage.

What a bridge letter is

What a SOC 2 bridge letter is and what it is not

SOC 2 Type 2 reports cover a defined period. Once that period ends, the report says nothing about what happened afterwards — and customers with a different financial year end, or a diligence deadline, need to cover the interval.

The bridge letter — sometimes called a gap letter — fills it. Typically it states that between the end of the report period and the date of the letter, management is not aware of any material changes to the control environment, and not aware of control failures that would affect the conclusions in the report.

That phrasing is the whole story. Not aware of. It is a management representation about the absence of known problems, not evidence that anyone went looking.

What it is not

Three limits, and none of them is a technicality.

It is not an auditor product. The service organisation’s management writes and signs it. The service auditor does not issue it, does not test the gap period, and expresses no opinion on it. A bridge letter on the provider’s letterhead is exactly what it appears to be.

It is not an attestation. No procedures are performed. There is no examination, no sampling, no testing of operating effectiveness across the gap.

It is not a professional standard. The bridge letter is market convention that grew up around a real scheduling problem. That does not make it worthless — it makes it a representation whose weight depends entirely on how much you trust the party signing it.

How long is too long

Convention keeps bridge letters short, commonly around three months. The logic is straightforward: the further you get from tested evidence, the less a statement of unawareness is worth.

A long gap is a signal, not a formatting problem. If a provider is offering to bridge six or nine months, the useful questions are about the report cycle rather than the letter:

  • When does the next report period end, and when will the report be issued? A predictable annual cycle with a short lag is a sign of a mature programme.
  • Why is the gap this long? Slipped audits, changed auditors and re-scoped systems all show up as extended gaps first.
  • Has anything changed that the letter would not mention? Acquisitions, platform migrations and subservice organisation changes are material even when nobody classifies them as control failures.

The right answer to a long gap is a current report, not a longer letter.

How to read one properly

If you receive a bridge letter, three checks take two minutes and are usually skipped.

Check the dates line up. The letter should start where the report period ended, with no unexplained space between them, and run to a date that actually covers your requirement.

Check who signed it. A named officer of the service organisation with the standing to make the representation — not an account manager.

Check what it actually asserts. Some letters say only that no material changes occurred. Better ones also confirm that the controls continued to operate, and disclose known changes. A letter that discloses a change is more useful than one that is silent, and considerably more credible.

If you are the one issuing it

Two things make a bridge letter defensible for the provider.

Do not represent more than you know. A statement that no control failures occurred is a stronger claim than a statement that management is not aware of any. Only sign the one you can support.

Disclose changes rather than omitting them. A migration or a new subprocessor disclosed in the letter is a routine conversation. The same fact discovered later, after a silent letter, is a credibility problem that outlasts the gap period.

And the structural fix is to stop needing them: aligning your report period with the year end your major customers care about removes the gap for most of your base.

Where the bridge letter sits in your assurance work

Area Connection
SOC 2 compliance The programme behind the report, and why the reporting period is chosen as it is
Type 1 vs Type 2 Bridge letters exist because Type 2 covers a period. A Type 1 speaks to a point in time and raises a different question
Complementary user entity controls The other half of the report that customers must act on — and unlike the bridge letter, it creates obligations for you
Third-party risk management Record report periods and expiry in the supplier inventory, so gaps are anticipated rather than discovered

Where to start with bridge letters

  1. Track report period end dates in your supplier register, so you request a bridge letter before a customer or auditor asks you for one.
  2. Decide your own tolerance — how many months of gap you will accept, and for which suppliers.
  3. Weight it as a representation, not as tested evidence, in whatever risk assessment consumes it.
  4. Escalate long gaps as a question about the provider’s audit cycle.
  5. Read the assertion, not the letterhead. “Not aware of” and “did not occur” are different claims.
  6. If you issue them, align your report period with your customers’ year ends and reduce the need.

This guide describes SOC 2 market practice as at 16 August 2026. Bridge letters are a convention rather than a matter of professional standards, and their content varies between providers — your service auditor is the authority on what a given report covers.

The SOC2 Toolkit provides the documentation pack behind a SOC 2 programme, including the system description, the control descriptions and the evidence records a service auditor works from.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.