The SOC 2 Bridge Letter, Explained
A SOC 2 bridge letter, also called a gap letter, is a short statement issued by a service organization's management confirming that since the end date of its most recent Type 2 report, the controls described in that report have continued to operate and nothing material has changed. Management signs it, not the auditor: no CPA firm can extend assurance over a period it did not examine. A bridge letter typically covers up to three months, occasionally six, and enterprise buyers treat anything longer as a request for a new report. It carries no independent assurance whatsoever. It exists to keep procurement moving through the inevitable gap between annual reports, and used correctly, it does exactly that.
Why bridge letters exist at all
A Type 2 report covers a fixed window, say October 1 through September 30, and is issued several weeks after the window closes. A buyer reviewing your security package the following March is looking at controls last examined more than five months earlier. Annual audit cycles guarantee this gap; even a flawless program spends most of the year with a report that ends in the past. Vendor risk teams know it, which is why the standard request is the most recent Type 2 report plus a bridge letter covering the period from the window's end to roughly the present. The letter is procurement lubricant rather than a security artifact, and both sides understand that. What buyers are really testing is whether you know what changed in your own environment and are willing to put a signature under the answer.
Who issues it, and who cannot
Management issues the bridge letter: typically the CISO, CTO, or CEO, on company letterhead. The auditor does not, and this is worth being precise about because the request comes up constantly. An auditor's opinion is bounded by the period examined during fieldwork; signing a statement about the months after that period would mean issuing assurance without evidence, which attestation standards do not permit. As a firm that performs SOC 2 examinations through our attest arm, BD Emerson CPA, we decline this request every time it appears, and so will every licensed firm. A vendor offering you an auditor-signed bridge letter is offering something that should make you question the rest of their paperwork too.
What a bridge letter contains
Keep it to one page. A letter that gets accepted without follow-up questions contains:
- The most recent report: type, audit period, issuing CPA firm, and opinion date
- The exact period the letter covers, with a start date and an end date
- A statement that controls have continued to operate as described, or a plain description of any material changes
- Disclosure of any security incidents in the period that would affect the report's conclusions, or a statement that there were none
- The scheduled window and expected delivery date of the next Type 2 report
- Signature, printed name, and title of the responsible officer, plus the date of issuance
Specific dates and plain declarative sentences read as confidence. Hedged language, undefined periods, and letters dated months before the request read as a draft nobody wanted to own.
What buyers actually accept
Up to three months of bridge coverage is routine and rarely questioned. Three to six months draws scrutiny, and the buyer may ask for interim evidence alongside the letter: recent access reviews, vulnerability scan summaries, a current penetration test report. Past six months, most sophisticated vendor risk teams stop accepting letters entirely and start asking when the new report arrives, because at that point management is asserting more unexamined time than the auditor examined. Regulated buyers, banks and healthcare systems in particular, often codify these thresholds in policy and cannot waive them for you regardless of the relationship. This is worth engineering around rather than arguing with: schedule your audit window to end shortly before your renewal-heavy quarter, and the letters you issue stay comfortably inside the three-month zone.
What a bridge letter does not do
It provides no assurance. Nobody tested anything, and the letter is a representation by the party being evaluated, made about itself. Buyers weight it accordingly: a good-faith statement backed by the credibility of the last report and by the consequences of misstating it. Those consequences are real. A bridge letter that glosses over a known incident or a major system change becomes a contract problem and a credibility problem the moment either surfaces, and security addenda increasingly make such representations enforceable. Treat the letter with the same care as a representation in a financing round: accurate, dated, specific, and reviewed by someone who actually knows what changed in the environment since the window closed.
When a buyer will insist on a new report instead
Expect the letter to be refused, reasonably, in five situations. The gap has passed six months. The environment changed materially: a cloud migration, a re-architecture, an acquisition folding new systems into scope. A security incident occurred during the gap period. You are a new vendor presenting an old report, so the buyer has no relationship history to lend the letter weight. Or the buyer operates under fixed evidence policies that simply do not include management letters. In every case the productive response is the same: get the next window scheduled, share the engagement letter with dates, and offer interim evidence while the report is in flight. Arguing that the letter should suffice, when the buyer has already said it does not, burns goodwill you will want during contract negotiation.
Keeping the gap short in the first place
Bridge letters are a symptom of calendar management, good or bad. Run the Type 2 window annually with no lapse between windows, engage the auditor before the current window closes so fieldwork starts immediately, and the distance between window end and report issuance stays at six to ten weeks, which a three-month letter covers with room to spare. Companies that let a window lapse face a much worse conversation, because a lapsed window means months that no report will ever cover, and no letter fixes that retroactively. The cadence discipline, along with the rest of the program mechanics, is laid out in our SOC 2 compliance checklist.
Where BD Emerson fits
Our attest arm performs SOC 2 Type 2 examinations on schedules built so the report renews before buyers start asking about its age, and we advise clients on what a defensible bridge letter should and should not say, though the signature on it will always be management's, including when we are the auditor. If your report has aged past what a letter can carry, the fix is a window that opens now, and that is a scheduling conversation worth having this week rather than next quarter.
