SOC 2 Bridge Letters: What They Are and When You Need One

SOC 2 Bridge Letters: What They Are and When You Need One

SOC 2 Bridge Letters

SOC 2 Bridge Letters has an expiration problem built into it: it only covers a fixed window of time, but customer reviews, renewals, and fiscal year-ends rarely land exactly when that window closes. A bridge letter is the short document that fills that gap — without pretending to be a substitute for the real audit. This guide covers what a bridge letter actually says, who writes and signs it, how long it’s good for, and the mistakes that turn a routine gap-filler into a red flag for the buyer reading it.

What a SOC 2 Bridge Letter Actually Is

A SOC 2 bridge letter — also called a gap letter — is a short, signed statement from a service organization’s own management confirming that the controls described in its most recent SOC 2 report are still in place and operating as described. It’s not issued by the audit firm, it doesn’t involve new testing, and it isn’t a report in its own right. It exists for one narrow purpose: to cover the calendar days between the end date of your last SOC 2 report and either the issuance of your next one or a customer’s review or fiscal year-end, whichever comes first.

SOC 2 bridge letter is

 Quick definition : Bridge letter (gap letter) = a management-signed statement asserting   that SOC 2 controls have continued operating effectively since the last report’s end date,   used to cover a short reporting gap — typically no more than about three months.

Bridge Letter vs. SOC 2 Report

It helps to be clear about what a bridge letter is not before getting into what it is. The table below lines the two documents up side by side.

SOC 2 Report vs Bridge Letter
Attribute SOC 2 Report Bridge Letter
Issued by Independent CPA firm Company's own management
Basis Tested evidence over a review period Management's own assertion, untested
Typical length 20–100+ pages Half a page to a few paragraphs
Covers A defined audit period (3–12 months) The gap after that period ends (≤ ~3 months)
Signed by The auditor (CPA firm) A company officer — CISO, CTO, or CFO
Replaces a SOC 2 report? No, and it says so explicitly

Why You'd Need One

SOC 2 audit windows almost never line up perfectly with the moment a customer actually wants proof of compliance. A few situations come up again and again:

  • Your report period ended a few months ago and the next Type II audit is still underway.
  • A customer’s fiscal year-end falls outside the window your current report covers.
  • An enterprise deal is sitting in security review and procurement won’t move forward on a report they consider stale.
  • Your auditor was booked later than usual this cycle, leaving an unplanned gap before the new report is ready.
  • An existing customer’s annual renewal or vendor re-assessment happens to fall mid-gap.

 

None of these situations reflect badly on a company by themselves — audit timing rarely matches a customer’s calendar exactly. What matters is having a way to answer the request instead of leaving the customer waiting on a report that may still be months away.

What's Actually Inside SOC 2 Bridge Letters

The AICPA has never published an official bridge letter template or requirement, so the exact wording varies by company and by auditor guidance. In practice, though, nearly every bridge letter that holds up under scrutiny includes the same core elements:

SOC 2 Bridge Letters
Bridge Letter Elements
Element What it covers
Period referenced Start and end dates of the most recent SOC 2 report
Gap period stated The specific dates the bridge letter itself is asserting coverage for
Change disclosure Any material changes to systems, controls, or personnel since the report — or a statement that none occurred
Continuity statement An assertion that controls described in the prior report are still operating effectively
Non-substitution disclaimer Explicit language that the letter is not a SOC 2 report and doesn't certify compliance

What it deliberately leaves out matters just as much: a bridge letter doesn’t walk through individual controls, doesn’t include test results, and isn’t detailed enough for a customer to run a real risk assessment against. That’s by design — it’s a stopgap, not a substitute audit.

 Drafting tip: Keep the tone factual and dated, not promotional. A bridge letter that reads   like a marketing statement, or quietly drops the non-substitution disclaimer, invites more   scrutiny from a buyer — not less.

Who Writes It, and How the Request Actually Runs

A common point of confusion is assuming the audit firm prepares the bridge letter. It doesn’t. Once a SOC 2 report is issued, the CPA firm has no ability to attest to anything that happens after the report period ends — they simply haven’t tested it. So the letter comes from inside the company being reviewed, typically drafted by whoever owns security or compliance and signed by an executive with real visibility into the control environment.

Because the letter carries the company’s name and an executive signature, it’s treated as a real representation — not a formality. Getting the wording wrong (overstating certainty, omitting a known change) creates more exposure than simply disclosing the change and explaining why it doesn’t affect the control environment.

SOC 2 Bridge Letters

 Signing tip: Whoever signs should be able to personally answer follow-up questions about   the control environment. A signature from someone without that visibility undermines the   letter the moment a buyer asks a clarifying question.

How Long It's Valid — and Where It Falls Short

Bridge Letter Limitations
Limitation Why it matters
Short shelf life Most bridge letters are only considered reliable for up to about three months; beyond that, buyers expect the real report
No independent testing It's a self-assertion — nothing in it has been verified by a third party
High-level only It won't contain enough control detail for a buyer to complete a real risk assessment
Depends on reputation Its usefulness rests entirely on how much the recipient already trusts the organization issuing it
Not universally accepted Some enterprise buyers' internal policies require a current full report regardless of timing

 Timing tip: If you’re issuing a bridge letter two or three cycles in a row, that’s a signal to   move your next audit’s start date earlier — not to write a more detailed bridge letter.

Common Mistakes Companies Make With Bridge Letters

Treating it as a rubber stamp instead of a real representation — overstating certainty about controls nobody re-checked.

Leaving out a known material change and hoping it doesn’t come up in the next audit.

Skipping the non-substitution disclaimer, which makes the letter look like it’s trying to pass as a full report.

Having it signed by someone without real visibility into the control environment, rather than a CISO, CTO, or CFO.

Waiting for a customer to ask instead of anticipating the gap and having a letter ready before renewal season.

Using a bridge letter repeatedly, cycle after cycle, instead of tightening the audit schedule so gaps stop recurring.

How B4Q Assurance Helps

As a licensed U.S. CPA firm (AICPA) handling SOC 1, SOC 2, and SOC 3 engagements, B4Q Assurance works with clients to keep audit cycles tight enough that bridge letters stay the exception rather than the routine — and helps structure the letter correctly on the occasions one is genuinely needed, so it holds up to a buyer’s security review instead of raising more questions than it answers.

Ready to Close the Gap Before It Becomes a Problem?

A bridge letter is a useful tool, but the better fix is an audit schedule that rarely needs one. B4Q Assurance CPA PC works with organizations across the US on SOC 1, SOC 2, and SOC 3 engagements — from readiness assessment through Type I and Type II reporting — and can help you plan renewal timing so gap periods, and the bridge letters that cover them, become rare.

Book a free strategy call to review your current audit calendar against your customers’ actual renewal and review dates.

Official Resources & Further Reading

AICPA – Trust Services Criteria (TSP Section 100): the underlying criteria a SOC 2 report — and by extension a bridge letter — references (free account required).

AICPA – SOC 2 Description Criteria: governs how a system description must be written, relevant background for anyone drafting gap-period disclosures.

AICPA & CIMA – Standards and Statements: central index of AICPA standards; useful for confirming that no separate bridge letter standard exists outside general attestation guidance.

FAQs

Does the AICPA require bridge letters?

 No. The AICPA has not published a bridge letter standard or template — the practice is a market convention, not a formal audit requirement.

A company officer with real knowledge of the control environment — typically a CISO, CTO, or CFO — never the audit firm.

 Most are only considered reliable for up to about three months; beyond that, buyers generally expect the actual renewed SOC 2 report.

 No. It’s a temporary, self-asserted stopgap, and every properly written bridge letter says so explicitly.

 Not always. Some enterprise procurement policies require a current full report regardless of timing, so it’s worth confirming expectations before relying on a bridge letter alone.

What do you think?