A SOC 1 bridge letter is a short statement from a service organization that tells customers what has happened since the end date of its last SOC 1 report. Customers who rely on that report for their own financial audit often need comfort that controls did not change between the report date and their year-end. The letter supplies that comfort, but it is not the same as auditor assurance, and confusing the two is where problems begin.
This guide covers what a SOC 1 bridge letter contains, who signs it, how long a gap it should cover, and how service organizations and user entities should each treat it. It complements our guides to the SOC 1 report and to Type 1 versus Type 2 reports.
Free gap assessment
How much of your SOC 2 report can you already evidence?
Score yourself against the Trust Services Criteria, free, before an auditor charges you to find out.
Run the free SOC 2 gap assessment → or View premium report sample
Why a SOC 1 bridge letter exists
A Type 2 report covers a defined period, for example 1 January to 30 September. A customer with a 31 December year-end has three months not covered by any testing. The customer’s auditor may ask how the customer knows the controls still worked. A bridge letter, sometimes called a gap letter, addresses that gap by stating that management is not aware of material changes to the control environment since the report period ended.
The need arises because SSAE 18 attestation reports look backwards. The service auditor tests what happened during the period, and says nothing about later dates. The letter is a management representation that fills the time between.
Who signs a SOC 1 bridge letter
Service organization management writes and signs it, not the service auditor. Guidance from CPA firms is consistent on this point. The auditor has done no testing after the report end date, so the letter carries no independent assurance for the gap period. One CPA firm summary puts it plainly: the service auditor is not attesting to the design or operating effectiveness of controls during the gap.
This has a practical effect on how you word it. Because management signs, management is responsible for the accuracy of every statement. Avoid promising more than you know. Use language such as “management is not aware of” rather than “no changes have occurred”, and confirm with control owners before signing.
What to include in a SOC 1 bridge letter
| Element | Why it matters |
|---|---|
| Report title and period | Identifies exactly which report the letter extends |
| Gap period dates | Shows the dates the statement covers |
| Material changes | Lists any changes to systems, controls or subservice providers |
| Confirmation of no other changes | The core representation from management |
| Reminder about user entity controls | Points customers to their own responsibilities |
| Disclaimer | States that it does not replace the SOC report |
| Signature and date | An authorised officer takes responsibility |
The reminder about customer responsibilities links back to your complementary user entity controls. Repeating it in the letter keeps customers aware that some controls are theirs to run.
How long a gap can a SOC 1 bridge letter cover?
Practitioner guidance suggests keeping the gap to no more than about three months. That is a convention, not a rule in the standard. If customers regularly need letters covering longer periods, the underlying problem is the timing of your examination periods. Consider moving the report period so it ends closer to your customers’ year-ends, or issue reports more frequently so the gaps shrink.
Also think about who asks. Customers with a December year-end usually ask in January or February. If your report ends in September, you will issue many letters at the same time. Prepare a standard template and an approval routine before the rush.
What auditors and user entities should not assume
User auditors sometimes treat a bridge letter as if it were a report extension. It is not. It gives them a management representation and nothing more. They may still choose to perform their own procedures, such as inquiring about changes, if the gap is long or if the controls are significant to their audit.
Service organizations should avoid describing the letter as “SOC 1 coverage” for the gap in sales materials. Doing so overstates what management can support, and it invites disputes if a control failed in the gap period. Where a subservice organization is involved, check its own status too. Our guide to the SOC 1 subservice organization explains the carve-out and inclusive methods.
Handling a material change in the gap period
If something significant has changed, say so. Examples include a new data centre, a migration to a different platform, a change of key subservice provider, a new version of a key application or a control that failed. Describe the change briefly and, if relevant, explain how controls were adjusted. A letter that discloses a change and shows it is managed is more credible than one that says nothing. If a control failure occurred, involve legal counsel and your service auditor before you issue the letter, because omission can create liability.
A process for issuing your SOC 1 bridge letter
- Keep a change log throughout the year for systems, controls and providers.
- Receive the request and confirm the report period and gap dates needed.
- Check with control owners for changes and failures since the report end date.
- Draft from the template and add any disclosed changes.
- Approve by an authorised officer, with legal review for disclosures.
- Issue and log the letter, recipient and date.
Our SOC 1 audit checklist shows where the change log fits in your annual preparation, and SOC 1 versus SOC 2 explains why SOC 2 customers ask for similar letters.
Wording tips for the gap period
Precise wording protects both sides. State the exact dates the letter covers, and name the report by title and period so nobody applies it to the wrong examination. Use a factual sentence about what management knows, and avoid adjectives such as “fully effective” that sound like an opinion on controls. If the letter mentions the subservice organizations used, say whether their own reports have changed. Keep the letter to one page, because a long letter invites questions and looks like a substitute for the report.
Finally, consider who receives it. Send it to the customer contact who asked, not to a general mailbox, and store a copy with the customer record. If a customer forwards the letter to its auditor, the wording should still stand on its own without extra explanation.
Bridge letters and your examination calendar
Every letter you issue is a signal that your examination period does not match your customers’ needs. Count how many requests you receive each year and how long the gaps are. If most gaps exceed three months, talk to your service auditor about shifting the period end date, or about using a shorter interim period. Some organizations also add a second, shorter examination period so customers receive fresher coverage. The cost of an earlier examination is usually smaller than the time spent on many bridging letters and follow-up questions.
A hypothetical example
A hypothetical payroll processor has a SOC 1 Type 2 report ending 30 September. A customer with a 31 December year-end asks for a letter in January. The compliance lead checks the change log and finds that the processor moved its file transfer service to a new provider in November. The letter discloses the move, states that management is not aware of other material changes, reminds the customer of its user entity controls and includes the standard disclaimer. The chief financial officer signs. The customer’s auditor asks a follow-up question about the new provider, and the processor answers it directly. The example is invented for illustration.
Common mistakes with a SOC 1 bridge letter
- Having the service auditor sign, or implying the auditor endorses it.
- Writing “no changes” without checking with control owners.
- Issuing a letter for a gap of six months or more.
- Omitting a known change or control failure.
- Failing to log who received which letter.
Read practitioner guidance such as this explanation of bridge and gap letters for another view, and confirm any wording with your service auditor.
Templates for your SOC 1 bridge letter
If you would rather not draft the letter and its change log from scratch, the SOC 1 Toolkit includes documents you can adapt for your control environment. Have your service auditor and counsel review any wording.
SOC 1 bridge letter FAQ
Is a SOC 1 bridge letter an audit document?
No. It is a management letter. The service auditor does not sign it or provide assurance about the gap period.
How long can the gap be?
Practitioner guidance suggests about three months at most. This is a convention, and longer gaps weaken the comfort the letter gives.
Do we have to issue one?
Nothing in the standard requires it. Customers ask because their auditors want comfort about the gap period, so most service organizations prepare a template.
What if a control failed during the gap?
Disclose it, after review by counsel and your service auditor. Silence about a known failure creates risk for your organization.
Who should sign?
An authorised member of management with knowledge of the control environment, such as the chief financial officer or head of compliance.