SOC 2 Bridge Letters: What They Are and When You Need One
SOC 2 Bridge Letters has an expiration problem built into it: it only covers a fixed window of time, but customer reviews, renewals, and fiscal year-ends rarely land exactly when that window closes. A bridge letter is the short document that fills that gap — without pretending to be a substitute for the real audit. This guide covers what a bridge letter actually says, who writes and signs it, how long it’s good for, and the mistakes that turn a routine gap-filler into a red flag for the buyer reading it.
What a SOC 2 Bridge Letter Actually Is
A SOC 2 bridge letter — also called a gap letter — is a short, signed statement from a service organization’s own management confirming that the controls described in its most recent SOC 2 report are still in place and operating as described. It’s not issued by the audit firm, it doesn’t involve new testing, and it isn’t a report in its own right. It exists for one narrow purpose: to cover the calendar days between the end date of your last SOC 2 report and either the issuance of your next one or a customer’s review or fiscal year-end, whichever comes first.
Quick definition : Bridge letter (gap letter) = a management-signed statement asserting that SOC 2 controls have continued operating effectively since the last report’s end date, used to cover a short reporting gap — typically no more than about three months.
Bridge Letter vs. SOC 2 Report
It helps to be clear about what a bridge letter is not before getting into what it is. The table below lines the two documents up side by side.
| Attribute | SOC 2 Report | Bridge Letter |
|---|---|---|
| Issued by | Independent CPA firm | Company's own management |
| Basis | Tested evidence over a review period | Management's own assertion, untested |
| Typical length | 20–100+ pages | Half a page to a few paragraphs |
| Covers | A defined audit period (3–12 months) | The gap after that period ends (≤ ~3 months) |
| Signed by | The auditor (CPA firm) | A company officer — CISO, CTO, or CFO |
| Replaces a SOC 2 report? | — | No, and it says so explicitly |
Why You'd Need One
SOC 2 audit windows almost never line up perfectly with the moment a customer actually wants proof of compliance. A few situations come up again and again:
- Your report period ended a few months ago and the next Type II audit is still underway.
- A customer’s fiscal year-end falls outside the window your current report covers.
- An enterprise deal is sitting in security review and procurement won’t move forward on a report they consider stale.
- Your auditor was booked later than usual this cycle, leaving an unplanned gap before the new report is ready.
- An existing customer’s annual renewal or vendor re-assessment happens to fall mid-gap.
None of these situations reflect badly on a company by themselves — audit timing rarely matches a customer’s calendar exactly. What matters is having a way to answer the request instead of leaving the customer waiting on a report that may still be months away.
What's Actually Inside SOC 2 Bridge Letters
The AICPA has never published an official bridge letter template or requirement, so the exact wording varies by company and by auditor guidance. In practice, though, nearly every bridge letter that holds up under scrutiny includes the same core elements:
| Element | What it covers |
|---|---|
| Period referenced | Start and end dates of the most recent SOC 2 report |
| Gap period stated | The specific dates the bridge letter itself is asserting coverage for |
| Change disclosure | Any material changes to systems, controls, or personnel since the report — or a statement that none occurred |
| Continuity statement | An assertion that controls described in the prior report are still operating effectively |
| Non-substitution disclaimer | Explicit language that the letter is not a SOC 2 report and doesn't certify compliance |
What it deliberately leaves out matters just as much: a bridge letter doesn’t walk through individual controls, doesn’t include test results, and isn’t detailed enough for a customer to run a real risk assessment against. That’s by design — it’s a stopgap, not a substitute audit.
Drafting tip: Keep the tone factual and dated, not promotional. A bridge letter that reads like a marketing statement, or quietly drops the non-substitution disclaimer, invites more scrutiny from a buyer — not less.
Who Writes It, and How the Request Actually Runs
A common point of confusion is assuming the audit firm prepares the bridge letter. It doesn’t. Once a SOC 2 report is issued, the CPA firm has no ability to attest to anything that happens after the report period ends — they simply haven’t tested it. So the letter comes from inside the company being reviewed, typically drafted by whoever owns security or compliance and signed by an executive with real visibility into the control environment.
Because the letter carries the company’s name and an executive signature, it’s treated as a real representation — not a formality. Getting the wording wrong (overstating certainty, omitting a known change) creates more exposure than simply disclosing the change and explaining why it doesn’t affect the control environment.
Signing tip: Whoever signs should be able to personally answer follow-up questions about the control environment. A signature from someone without that visibility undermines the letter the moment a buyer asks a clarifying question.
How Long It's Valid — and Where It Falls Short
| Limitation | Why it matters |
|---|---|
| Short shelf life | Most bridge letters are only considered reliable for up to about three months; beyond that, buyers expect the real report |
| No independent testing | It's a self-assertion — nothing in it has been verified by a third party |
| High-level only | It won't contain enough control detail for a buyer to complete a real risk assessment |
| Depends on reputation | Its usefulness rests entirely on how much the recipient already trusts the organization issuing it |
| Not universally accepted | Some enterprise buyers' internal policies require a current full report regardless of timing |
Timing tip: If you’re issuing a bridge letter two or three cycles in a row, that’s a signal to move your next audit’s start date earlier — not to write a more detailed bridge letter.
Common Mistakes Companies Make With Bridge Letters
Treating it as a rubber stamp instead of a real representation — overstating certainty about controls nobody re-checked.
Leaving out a known material change and hoping it doesn’t come up in the next audit.
Skipping the non-substitution disclaimer, which makes the letter look like it’s trying to pass as a full report.
Having it signed by someone without real visibility into the control environment, rather than a CISO, CTO, or CFO.
Waiting for a customer to ask instead of anticipating the gap and having a letter ready before renewal season.
Using a bridge letter repeatedly, cycle after cycle, instead of tightening the audit schedule so gaps stop recurring.
How B4Q Assurance Helps
As a licensed U.S. CPA firm (AICPA) handling SOC 1, SOC 2, and SOC 3 engagements, B4Q Assurance works with clients to keep audit cycles tight enough that bridge letters stay the exception rather than the routine — and helps structure the letter correctly on the occasions one is genuinely needed, so it holds up to a buyer’s security review instead of raising more questions than it answers.
Ready to Close the Gap Before It Becomes a Problem?
A bridge letter is a useful tool, but the better fix is an audit schedule that rarely needs one. B4Q Assurance CPA PC works with organizations across the US on SOC 1, SOC 2, and SOC 3 engagements — from readiness assessment through Type I and Type II reporting — and can help you plan renewal timing so gap periods, and the bridge letters that cover them, become rare.
Book a free strategy call to review your current audit calendar against your customers’ actual renewal and review dates.
Official Resources & Further Reading
AICPA – Trust Services Criteria (TSP Section 100): the underlying criteria a SOC 2 report — and by extension a bridge letter — references (free account required).
AICPA – SOC 2 Description Criteria: governs how a system description must be written, relevant background for anyone drafting gap-period disclosures.
AICPA & CIMA – Standards and Statements: central index of AICPA standards; useful for confirming that no separate bridge letter standard exists outside general attestation guidance.
FAQs
Does the AICPA require bridge letters?
No. The AICPA has not published a bridge letter standard or template — the practice is a market convention, not a formal audit requirement.
Who signs a bridge letter?
A company officer with real knowledge of the control environment — typically a CISO, CTO, or CFO — never the audit firm.
How long is a bridge letter good for?
Most are only considered reliable for up to about three months; beyond that, buyers generally expect the actual renewed SOC 2 report.
Can a bridge letter replace a SOC 2 report entirely?
No. It’s a temporary, self-asserted stopgap, and every properly written bridge letter says so explicitly.
Will every customer accept one?
Not always. Some enterprise procurement policies require a current full report regardless of timing, so it’s worth confirming expectations before relying on a bridge letter alone.