Skip to main content

Explainers

What is a bridge letter, and how much should a buyer trust one?

A bridge letter covers the gap between a SOC report period end and the next report. It is a management statement, not an audit. What it must contain, the 90-day norm, and where it stops.

Solomon AmosPublished 12 Sep 2026Updated 18 Sep 20269 min read

An open notebook and pen on a wooden desk
Photo by Aaron Burden on Unsplash

SOC 2 Type II reports cover a period, and periods end. A report for the twelve months to 31 March is issued in May or June, and by the following March the most recent tested evidence is a year old. Buyers reviewing a vendor in the gap ask for a bridge letter, also called a gap letter, which the vendor writes to cover the months since the period end. This explainer sets out what a bridge letter is, what it must contain, how long it can reasonably run, and how much weight it carries next to the report it extends.

90 days
Standard maximum a bridge letter should cover
IS Partners, Vanta and Thoropass guidance
6 months
Point at which buyers become sceptical
Agency, SOC 2 bridge letter guide
0
Auditor tests behind a bridge letter
It is a management representation

What a bridge letter is

A bridge letter is a formal statement from the vendor’s management that covers the period between the end of the last SOC report and a stated date, usually the letter date. It confirms that there have been no material changes to the system, the controls or the control environment described in the report, or it describes the changes that occurred. It is an interim management assertion, not a new audit.

A SOC 2 bridge letter is a formal letter from a company’s management that covers the gap between its last official SOC 2 report and the present moment. It’s not a new audit, it’s an interim management assertion.

What a bridge letter says

  • The period the last report covered and the date it was issued, with the report type and the auditor named.
  • The date range the letter covers, from the period end to the letter date.
  • A statement by management that there have been no material changes to the system or the controls described in the report, or a description of the changes.
  • A statement about known incidents or exceptions in the gap, when the vendor chooses to include one.
  • A signature from an officer of the vendor, not from the auditor.
A hand signing a document
The signature on a bridge letter belongs to the vendor’s management. The auditor signs nothing in the gap. · Photo by Scott Graham on Unsplash

What it is not

A bridge letter is not an auditor opinion, and no CPA firm has tested anything in the gap. It is a representation by the vendor about itself. That is fine as far as it goes; it extends the usefulness of a report by a few months while the next one is prepared. It does not extend the assurance. Some vendors issue bridge letters for twelve months or longer, which should prompt the question of whether the next audit is happening at all.

ArtefactWho signsTesting behind itCertReports state
SOC 2 Type II reportCPA firmSampled over the periodVerified by auditor when confirmed; otherwise vendor-stated
Bridge letterVendor managementNoneVendor-stated, dated
Trust centre badgeNobodyNoneVendor-stated when it links to a page; otherwise no public evidence

How long a gap is reasonable

Industry guidance converges on 90 days. Most buyers accept a bridge letter covering up to three months after the period end, some accept six, and few accept more without an explanation. A vendor on an annual audit cycle should be able to name the month the next report is due; if it cannot, the letter is doing more work than it should. Compliance platforms and audit firms publish the same threshold, which makes it a reasonable line to write into a contract.

Age of the tested evidence over an annual cycle
  • At report issue (about 2 months after period end)2months
  • End of a standard bridge letter5months
  • Point buyers become sceptical8months
  • Next period end12months

What to check when you receive one

  1. 1

    The dates line up

    The letter starts where the report ended. A letter that starts later leaves an uncovered gap.

  2. 2

    The system matches

    The system description referenced is the one for the product you use, with the same name as the report.

  3. 3

    Changes are listed, not just denied

    A letter that names a new data centre, a subprocessor change or an incident is more credible than one that says nothing changed in a year.

  4. 4

    The signatory is identifiable

    A named officer on the vendor’s paper, not a generated PDF from a compliance platform with no name.

  5. 5

    The next report has a date

    Ask for the expected issue month and record it in your vendor register.

Documents and a laptop on a desk
A good bridge letter reads like a change log for the control environment, with dates. · Photo by Helloquence on Unsplash

When to refuse one

  • The letter covers more than six months and no next-report date is offered.
  • The report it extends is a Type I; a bridge letter cannot turn design-only assurance into operating effectiveness.
  • The letter denies any change while the vendor’s own change log, subprocessor list or status page shows otherwise.
  • The signatory cannot be identified or the letter is unsigned.

How CertReports records it

The index records a bridge letter as a dated, vendor-stated artefact next to the report it extends, so the row shows both the period end and the letter date. When the period end passes twelve months, the row shows as stale regardless of the letter. Read the SOC 2 reading guide for the rest of the report and expiring this month for periods ageing out now.

One line for the contract

"The supplier will provide a SOC 2 Type II report annually and a bridge letter for any gap exceeding 90 days after the period end." It removes the argument before it starts.

People also ask

What is a SOC 2 bridge letter?

A statement from the vendor’s management covering the period between the end of its last SOC 2 report and a stated date, confirming whether the system and controls described in the report have materially changed. It is not an audit.

How long is a bridge letter valid?

Industry practice caps it at about 90 days after the period end. Buyers grow sceptical past six months, and a letter covering a year suggests the next audit may not be happening.

Who signs a bridge letter?

An officer of the vendor. The auditor does not sign it and has not tested anything in the gap; a letter presented as coming from the CPA firm should be questioned.

Is a bridge letter the same as a gap letter?

Yes. Both names describe the same management representation covering the gap between two SOC reports.

Does a bridge letter replace a SOC 2 report?

No. It extends the usefulness of an existing report for a short period. It cannot substitute for the next report and cannot upgrade a Type I to operating-effectiveness assurance.

What should I do if a vendor cannot provide a bridge letter?

Ask for the next report’s expected date. If the period end is more than a few months old and neither a letter nor a date is available, treat the report as stale in your risk assessment.

SOC 2bridge lettergap letterattestationvendor review
S

Solomon Amos · Founder, CertReports

Solomon builds CertReports, the public evidence index for vendor security reviews. PhD in machine learning and cybersecurity, two years embedded at HMRC digital programmes, founder of TapTax. He writes about what registries, trust centres and auditors actually publish, and how buyers can use it before the questionnaire goes out.

You might also like