SOC 2

What is a SOC 2 bridge letter?

A bridge letter (or gap letter) is a short letter from a service organization that covers the gap between the end of its SOC 2 report period and a later date, often a customer reliance date. It states that, to management knowledge, no material changes to the control environment occurred in that interim period. It is written by the service organization, not the auditor, and it does not extend the audit or provide new assurance.

Why bridge letters exist

A SOC 2 Type II covers a fixed period that ends on a specific date. Customers often need assurance up to a date after that period ends (for example, their vendor review happens three months later). A bridge letter covers that interim gap.

What it does and does not do

A bridge letter is a management statement that nothing material changed since the report period. It is not an auditor opinion and does not test controls. It typically should not cover more than about three months; for longer gaps, a new report is the right answer.

FAQ

Who writes the bridge letter?

The service organization (you), not the CPA firm. It is signed by management and provided to customers alongside the most recent SOC 2 report.

How long can a bridge letter cover?

As a rule of thumb, no more than about three months. Beyond that, the gap is too long to bridge with a management statement, and customers will expect a fresh SOC 2 report.

Related

What is SOC 2? → SOC 2 Type I vs Type II → How do I prepare for SOC 2? →

Get audit-ready with Keel

The AI-native GRC platform for SMBs: one control-and-evidence graph across SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, and more. Start free, no credit card.

Start free