What is a SOC 2 Bridge Letter?
Updated:
September 30, 2026
A SOC 2 bridge letter, sometimes called a gap letter, is a statement signed by a company’s management that addresses the period after its latest SOC 2 report ends. It tells customers whether material changes have occurred in the controls covered by that report while a newer report is unavailable.
For example, if a SOC 2 Type 2 report covers January–December 2025, a bridge letter could address January–March 2026, confirming that management is unaware of significant control changes during those months.
This article explains SOC 2 bridge letters in detail, including when businesses need them, what they contain, and who signs them. It covers typical coverage periods, their limitations, and how companies use them during customer security reviews.
SOC 2 Bridge Letter in Detail
A SOC 2 bridge letter is a written update from a service provider’s management about its controls after the period covered by its latest SOC 2 report. It references the existing report and states whether material changes have occurred during a specified gap period.
Companies typically provide one when a customer’s security review or financial year-end falls after the report’s coverage ends. Because SOC 2 Type 2 reports examine a defined historical period, customers often need more recent information while waiting for the next report.
The letter identifies the previous report’s coverage dates, specifies the period being addressed, and describes any material changes to the control environment. When no material changes have occurred, management states that it is unaware of such changes during that period.
This update helps customers assess whether the existing SOC 2 report remains useful for their vendor review and whether further questions or evidence are needed. It supports ongoing due diligence by providing management’s current account of the control environment.
Bridge letters commonly address gaps of up to 3 months, although acceptance depends on the recipient’s requirements. They contain no independent testing of the gap period and do not extend the auditor’s opinion. Customers should review the letter alongside the original SOC 2 report.
What’s Included in a Bridge Letter for SOC 2?
A SOC 2 bridge letter identifies the existing report, defines the gap period, and provides management’s update on the control environment.
The AICPA does not prescribe a standard bridge letter format, but typical components include the following:

- Organization And SOC 2 Report Details: The letter identifies the service provider and references its latest SOC 2 report, including the period covered. These details connect management’s statements to the report customers already have.
- Bridge Period Dates: The letter specifies the start and end dates of the gap being addressed. This period begins after the latest report’s coverage ends and extends to a stated later date.
- Management’s Statement About Controls: Management states its understanding of whether the controls described in the report remain in place and continue to operate. This statement provides customers with an update on the control environment during the gap period.
- Material Changes: The letter describes any material changes to the control environment. When no material changes have occurred, management states that it is unaware of such changes during the specified period.
- Customer Control Responsibilities: The letter may remind customers to maintain the complementary user entity controls identified in the SOC 2 report. These are controls customers must perform within their own environments to support the service provider’s control objectives.
- Scope And Limitations: The letter explains that it supplements the existing SOC 2 report and provides no independent audit testing or auditor’s opinion for the gap period. Customers should read it alongside the original report.
- Management Signature And Issue Date: The letter appears on the service provider’s letterhead and includes management’s signature and the issue date. Management takes responsibility for its statements; the service auditor does not sign or validate the letter.
SOC 2 Bridge Letter Template
Date: [Letter Date]
To: [Customer Name]
Subject: SOC 2 Type 2 Bridge Letter — [System Or Service Name]
Dear [Customer Name],
This letter provides an update from [Company Name] management regarding the controls described in our latest SOC 2 Type 2 report for [System Or Service Name].
[Independent CPA Firm] issued that report on [Report Issue Date], covering the examination period from [Report Period Start Date] through [Report Period End Date]. This letter addresses the subsequent period from [Bridge Period Start Date] through [Bridge Period End Date].
Based on management’s knowledge and ongoing oversight, we are unaware of material changes to the system or control environment described in that report during the bridge period, except as disclosed below. Management remains responsible for maintaining and monitoring these controls.
Changes And Other Relevant Matters:
[Enter “None” if accurate, or describe material changes, relevant control failures, or security incidents, including their timing, impact, and corrective actions.]
Please review this letter together with the referenced SOC 2 report, including its findings and any complementary user entity controls that your organization is responsible for implementing.
The statements in this letter represent management’s knowledge as of [Letter Date]. Our independent CPA firm has not examined the bridge period for purposes of this letter. This letter provides no independent audit assurance, does not extend the examination period or auditor’s opinion, and does not replace the SOC 2 report.
For questions or additional information, please contact [Contact Name] at [Email Address] or [Phone Number].
Sincerely,
[Signature]
[Authorized Management Representative]
[Title]
[Company Name]
SOC 2 Bridge Letter FAQs
1. How do I get a bridge letter if my auditor hasn’t started the next SOC 2 audit yet?
Your company’s management can prepare and sign a bridge letter referencing your existing SOC 2 report. The next audit does not need to have started. Review control records, system changes, and relevant incidents before signing, and describe your renewal plans accurately. The letter provides management’s statements about the gap period without extending the auditor’s opinion.
2. My customer asked for a bridge letter, but my last SOC 2 report ended eight months ago. Can I still issue one?
You can issue an accurate management statement addressing the 8 months, but customer acceptance is uncertain. This substantially exceeds the customary 3-month bridge period. There is no universal AICPA rule prohibiting a longer letter, but it cannot supply independent assurance for those months. Confirm the customer’s requirements and discuss a current or interim examination with your auditor.
3. Who at my company should sign the bridge letter, and does it need a specific title?
An authorized management representative with sufficient knowledge of the control environment should sign. Common signers include the CEO, CTO, or CISO. There is no universally prescribed job title for bridge letters, although a customer can require a particular officer’s signature. Include the signer’s name, title, and signing date, and follow your company’s approval process.
4. What happens to my deals if I discover a control failure during the gap period?
A control failure does not automatically cancel a deal. The customer’s decision depends on its severity, affected services, contractual requirements, and remediation. Assess whether the failure makes your proposed statements inaccurate or incomplete. Disclose relevant matters and provide corrective actions and supporting evidence. Significant failures can lead customers to request additional assurance or postpone approval.
5. Can I reuse the same bridge letter for every customer, or should I write a new one for each request?
You can generally share the same letter when its system scope, dates, statements, and distribution terms fit each customer’s request. A new customer does not automatically require a new letter. Update it when a customer needs a later coverage date or when relevant circumstances change. Changing the date alone is insufficient; management must verify the statements for the additional period.
6. Is a bridge letter enough for me to pass a vendor security review, or will I still need to send the full SOC 2 report?
A bridge letter alone does not replace the SOC 2 report. Customers normally need the report to examine its scope, auditor’s opinion, controls, and exceptions, with the letter supplying management’s subsequent update. A customer can agree to alternative evidence, but acceptance follows its review policy. Provide the full report through an appropriate restricted sharing process when requested.
7. How long should I expect a customer to accept my bridge letter before they ask for a fresh audit?
There is no guaranteed acceptance period. Bridge letters commonly address gaps of up to 3 months, measured from the report period’s end—not an additional 3 months after the letter is signed. Customer policies can differ. For example, a report ending June 30 and a letter addressing July 1–September 30 leave a 3-month gap; issuing another letter in October does not reset that gap.
8. Do I need a bridge letter if my SOC 2 Type 1 report is recent, or does it only apply to Type 2?
A recent Type 1 report does not automatically require a bridge letter. Customers can request a management update after either report type, although bridge letters are most commonly discussed with Type 2 reports. Type 1 evaluates control design and implementation at a specific date. A bridge letter cannot turn it into Type 2 evidence of operating effectiveness over a period.
9. Could I face legal liability if I sign a bridge letter and a breach later shows my controls weren’t working?
Potentially. False or misleading security representations can expose the company to contractual claims, fraud allegations, or regulatory action. Personal liability depends on applicable law, your conduct, and the statements made; signing does not automatically establish it. A later breach alone does not prove an earlier statement was false. Have legal counsel review significant disclosures and retain the evidence supporting your statements.
10. What should I do if my auditor changes and the new firm’s audit period doesn’t line up with my old report?
Work with the new firm to identify the exact gap and determine whether available evidence supports a consecutive examination period. If the old report ends June 30 and the new period starts September 1, July and August form a 2-month gap. Management can provide a truthful bridge letter if the customer accepts it, but independently examined coverage requires an examination that includes those months.


