The bridge letter, including the version nobody writes
It covers the months since your report period ended, it is signed by you, and every template we have read assumes the easy case.
A SOC 2 bridge letter, also called a gap letter, covers the stretch of time between the end of your report period and today. You write it. Your auditor does not. It is a management assertion on your letterhead,1 signed by an officer, and it carries exactly the weight of anything else you put your name to.
Every template we have read assumes nothing changed during the gap. Eventually something does. The second half of this page is the letter for that case.
Your report period ended in March. It is now August, a buyer wants evidence you are still operating the controls, and the next examination has not started. That is the hole a bridge letter fills. It is a short document, usually one page. The part founders get wrong is who holds the pen.
Who writes it, and why that surprises people
You do. Founders ask their audit firm for a bridge letter and are told, politely, to write it themselves. This is not the firm being difficult. The report the firm signed covers a specific period it tested. Writing about any later period would mean putting a licensed firm name on months it never examined, with no procedures behind the words, and that is the one thing an attestation practice cannot do casually.1
So the letter comes from you. It goes out on company letterhead, signed by an officer, and it is addressed to the party who asked. Your firm may review the wording. Some will. Review is not the same as authorship, and the signature at the bottom is still yours.
Bridge letter, gap letter and continuity letter all refer to the same document. Vendor questionnaires pick one term more or less at random. If a security reviewer asks for any of the three, send the same page.
What the letter asserts
Five things, and no more than five. Each one is a fact you can point at, which is what keeps the letter defensible if somebody comes back to it in a year.
- The report it refers to
- The service organization name, the report type, the exact period covered, and the CPA firm that performed the examination. A reader should not have to guess which report you mean.
- The gap period
- Start and end dates, written out. The start is the day after your report period ended. The end is the date you sign, not some future date you hope to reach.
- The continuity statement
- That the controls described in the report have continued to operate, to the best of management’s knowledge. That qualifier is doing real work and belongs there.
- Changes
- Material changes to the system or the control environment during the gap. This is the line that gets filled in with “none.” Sometimes that is false.
- The signer
- An officer with authority to speak for the company, with a title and a date. A security engineer signing on behalf of the company is a weak letter.
What it cannot do
A bridge letter adds no assurance. None. It is unexamined, and a careful reader treats it as a representation from the company rather than as a work product of the audit. The report still speaks only for the period the examination covered,2 which is the subject of how long a SOC 2 report stays valid.
Do not write anything that implies the CPA firm stands behind the gap period. Do not reproduce the firm logo. Do not paraphrase the audit opinion inside your own letter, and do not describe the gap as covered, certified or attested. Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.
The structure, line by line
Nothing below sits behind an email form, because a letter you cannot read before you need it is not much use. Seven parts, in order.
- Letterhead and date. Company name, address, and the date of signature. The signature date is what sets the end of the gap, so it is a real date and not a placeholder.
- Addressee. The specific customer or prospect, by company name. A letter addressed “To whom it may concern” is fine when it must circulate, and weaker than one written to a named recipient.
- Identification of the report. One sentence naming the report, its type, the period it covers, and the firm that issued it.
- The gap period. One sentence with two dates. From the day after the report period ended, through the signature date.
- The assertion. That management is not aware of any material change to the system or the control environment during that period, other than the changes listed below. Keep the escape hatch even when the list is empty.
- Changes, or the absence of them. Either the sentence stating none, or the list. The next section is about writing the list.
- Limitation and signature. A sentence stating the letter is unaudited and provides no assurance, then name, title, signature and date.
How long a buyer will accept one
There is no published expiry date on a bridge letter and no rule that sets one. What actually governs acceptance is the size of the gap and how much the reader cares. A gap of a few weeks reads as a scheduling artifact. A gap approaching a year reads as a company that stopped doing examinations and started writing letters instead.
The reader deciding this is usually a security reviewer working from a checklist, and their tolerance is set by their own policy rather than by anything the AICPA publishes. So ask them. The question takes one line in an email and saves a round trip: what gap will you accept, and do you need the next report by a date. If the answer is a date, you are now planning an examination rather than a letter, and the SOC 2 timeline is the page for that.
When the gap gets long, the honest fix is another examination, not more careful wording. A Type 2 examination here is $5,000 per examination, and continuous evidence collection during the 3-month observation window runs $600 per month on a 12-month term. A letter costs an hour and buys goodwill. A report costs money and buys the thing the letter is standing in for.
The letter for when something did change
Now the case the templates skip. You reorganized. Your security lead left. You moved off one cloud provider and onto another, or a vendor in your critical path had an incident. The template says “no material changes have occurred,” and that sentence is now a false statement signed by an officer.
Rewrite it rather than deleting the section. A letter that discloses a change and describes it plainly is stronger than one that claims a clean gap, because the second kind gets checked. Buyers do run diligence. Press coverage, a status page, a departed executive’s updated profile: any of it can contradict a letter you signed.
Say this, not that
The rule underneath every row below is the same one. State what happened and what you did. Do not state that it had no effect, because establishing that is examination work and you did not do the examination.
| What changed | What the letter says | What it must not say |
|---|---|---|
| Your security lead resigned | The role, the date it changed hands, who holds it now, and the date the handover finished | That the transition had no effect on access reviews or monitoring |
| You migrated cloud providers | Both providers, the cutover date, and which controls were rebuilt on the new infrastructure | That the new environment meets the same criteria. That is a question for an examination |
| A vendor in scope had an incident | The date you learned of it, which of your systems touched that vendor, and what you changed in response | That customer data was unaffected, unless you can show the work behind it |
| You shipped a new product line | What it is, and whether it sits inside the system described in the report | That the existing report covers it |
| A control stopped operating for a while | The control, the dates it lapsed, when it resumed, and what you did about the gap | Nothing at all. Silence here is the version that ends deals |
The last row is the hard one. A control that lapsed during the gap will very likely surface as an exception in the next report, and a buyer who reads the letter first and the exception second will remember the order. What happens when a SOC 2 has exceptions covers how that actually reads in a finished report, which is less dramatic than founders expect.
Where the bridge letter sits in the cycle
A bridge letter is a symptom. It exists because a report period ended and the next one has not closed, and the cleanest way to need fewer of them is to keep the examination cadence tight enough that the gap stays small. That is a scheduling decision, and it starts with how long the observation period has to be.
Two habits. Write the letter once and keep it somewhere you can date and send in ten minutes. Then keep a running note of anything that would belong in the changes list, so you are not reconstructing six months from memory while a deal waits. The second habit is what makes the first one honest.
Questions
Who writes a SOC 2 bridge letter?
How long is a bridge letter valid?
Can a bridge letter cover a period where something changed?
Does a bridge letter extend my SOC 2 report?
What is a SOC 2 gap letter?
Sources
Get audit-ready without a compliance team.
$4,000 one time for SOC 2 Type 1, with the first examination and the auditor engagement fee included. audit-ready starting at about a week.
Get startedPolara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.