A bridge letter — also called a gap letter — covers the period between the end of your last SOC 2 report and today. It exists because report periods end but customer due diligence does not, and it is one of the most commonly misunderstood documents in vendor risk.
What it is
A short statement, written and signed by management, confirming that between the report period end and the letter date there have been no material changes to the control environment, and no known control failures. It typically restates the report period, names the system, and confirms continuity.
The critical point: a bridge letter is not audited. The CPA firm does not test the bridge period and generally will not sign it. It is your assertion — which means it carries exactly as much weight as your credibility, and no more.
What it cannot do
- It cannot extend audit coverage. Nothing in the bridge period has been independently tested.
- It cannot substitute for a report. A customer requiring audited assurance for the current period needs a report covering it.
- It cannot cover a material change. If you migrated cloud providers or had a significant incident, the honest letter says so — and saying so is far better than a later discovery.
Know your control status without guessing
GRC Copilot keeps control status and evidence current between audits, so a bridge letter is a statement of fact rather than an optimistic assumption.
Try GRC Copilot free Generate an AI-powered assessment Download checklist Book a demo
How long a gap is acceptable
Three months is routinely accepted. Six is common and starts to attract questions. Beyond six months, sophisticated customers increasingly push back, because an unaudited assertion covering half a year provides little assurance.
The practical implication for your audit calendar: if your report period consistently ends long before your busiest sales quarter, consider shifting the period rather than relying on ever-longer bridge letters.
Evaluating one you receive
When a vendor sends you a bridge letter, check: the report period it bridges from; the length of the gap; whether it explicitly asserts no material changes and no known control failures; whether it is signed by someone with authority; and whether the underlying report itself had exceptions. A bridge letter over a qualified report is not reassurance.
If the gap is long and the service is critical, it is entirely reasonable to ask when the next report is due and to make continued reliance conditional on receiving it.
Writing one
Keep it short and factual: identify the report and its period, state the bridge period, assert no material changes to the control environment, assert no known material control failures, and sign it at an appropriate level. Do not overstate — a letter claiming continuity that later proves false is a credibility problem far worse than the gap it was covering.
Frequently asked questions
Will our auditor sign the bridge letter?
Generally no. It is management's assertion about an unaudited period; auditors avoid implying assurance they have not provided.
Is a bridge letter enough for a customer?
Often, for a short gap. Customers with strict requirements will insist on a report covering the period they care about.
What if something material did change?
Say so. Describe the change and what you did about it. Concealment discovered later is far more damaging than the change itself.
Can we issue one for a Type I report?
You can, but it compounds a weakness — a Type I covers design at a point in time, so a bridge on top of it provides very little.
Key takeaways
- A bridge letter is management's assertion, not audited assurance.
- Three months is routine; beyond six invites pushback.
- Disclose material changes rather than asserting blanket continuity.
- When receiving one, check the underlying report for exceptions too.