SOC 2 Type II reports cover a period, and periods end. A report for the twelve months to 31 March is issued in May or June, and by the following March the most recent tested evidence is a year old. Buyers reviewing a vendor in the gap ask for a bridge letter, also called a gap letter, which the vendor writes to cover the months since the period end. This explainer sets out what a bridge letter is, what it must contain, how long it can reasonably run, and how much weight it carries next to the report it extends.
- 90 days
- Standard maximum a bridge letter should cover
- IS Partners, Vanta and Thoropass guidance
- 6 months
- Point at which buyers become sceptical
- Agency, SOC 2 bridge letter guide
- 0
- Auditor tests behind a bridge letter
- It is a management representation
What a bridge letter is
A bridge letter is a formal statement from the vendor’s management that covers the period between the end of the last SOC report and a stated date, usually the letter date. It confirms that there have been no material changes to the system, the controls or the control environment described in the report, or it describes the changes that occurred. It is an interim management assertion, not a new audit.
A SOC 2 bridge letter is a formal letter from a company’s management that covers the gap between its last official SOC 2 report and the present moment. It’s not a new audit, it’s an interim management assertion.
What a bridge letter says
- The period the last report covered and the date it was issued, with the report type and the auditor named.
- The date range the letter covers, from the period end to the letter date.
- A statement by management that there have been no material changes to the system or the controls described in the report, or a description of the changes.
- A statement about known incidents or exceptions in the gap, when the vendor chooses to include one.
- A signature from an officer of the vendor, not from the auditor.
What it is not
A bridge letter is not an auditor opinion, and no CPA firm has tested anything in the gap. It is a representation by the vendor about itself. That is fine as far as it goes; it extends the usefulness of a report by a few months while the next one is prepared. It does not extend the assurance. Some vendors issue bridge letters for twelve months or longer, which should prompt the question of whether the next audit is happening at all.
| Artefact | Who signs | Testing behind it | CertReports state |
|---|---|---|---|
| SOC 2 Type II report | CPA firm | Sampled over the period | Verified by auditor when confirmed; otherwise vendor-stated |
| Bridge letter | Vendor management | None | Vendor-stated, dated |
| Trust centre badge | Nobody | None | Vendor-stated when it links to a page; otherwise no public evidence |
How long a gap is reasonable
Industry guidance converges on 90 days. Most buyers accept a bridge letter covering up to three months after the period end, some accept six, and few accept more without an explanation. A vendor on an annual audit cycle should be able to name the month the next report is due; if it cannot, the letter is doing more work than it should. Compliance platforms and audit firms publish the same threshold, which makes it a reasonable line to write into a contract.
- At report issue (about 2 months after period end)2months
- End of a standard bridge letter5months
- Point buyers become sceptical8months
- Next period end12months
What to check when you receive one
- 1
The dates line up
The letter starts where the report ended. A letter that starts later leaves an uncovered gap.
- 2
The system matches
The system description referenced is the one for the product you use, with the same name as the report.
- 3
Changes are listed, not just denied
A letter that names a new data centre, a subprocessor change or an incident is more credible than one that says nothing changed in a year.
- 4
The signatory is identifiable
A named officer on the vendor’s paper, not a generated PDF from a compliance platform with no name.
- 5
The next report has a date
Ask for the expected issue month and record it in your vendor register.
When to refuse one
- The letter covers more than six months and no next-report date is offered.
- The report it extends is a Type I; a bridge letter cannot turn design-only assurance into operating effectiveness.
- The letter denies any change while the vendor’s own change log, subprocessor list or status page shows otherwise.
- The signatory cannot be identified or the letter is unsigned.
How CertReports records it
The index records a bridge letter as a dated, vendor-stated artefact next to the report it extends, so the row shows both the period end and the letter date. When the period end passes twelve months, the row shows as stale regardless of the letter. Read the SOC 2 reading guide for the rest of the report and expiring this month for periods ageing out now.
One line for the contract
"The supplier will provide a SOC 2 Type II report annually and a bridge letter for any gap exceeding 90 days after the period end." It removes the argument before it starts.
People also ask
What is a SOC 2 bridge letter?
A statement from the vendor’s management covering the period between the end of its last SOC 2 report and a stated date, confirming whether the system and controls described in the report have materially changed. It is not an audit.
How long is a bridge letter valid?
Industry practice caps it at about 90 days after the period end. Buyers grow sceptical past six months, and a letter covering a year suggests the next audit may not be happening.
Who signs a bridge letter?
An officer of the vendor. The auditor does not sign it and has not tested anything in the gap; a letter presented as coming from the CPA firm should be questioned.
Is a bridge letter the same as a gap letter?
Yes. Both names describe the same management representation covering the gap between two SOC reports.
Does a bridge letter replace a SOC 2 report?
No. It extends the usefulness of an existing report for a short period. It cannot substitute for the next report and cannot upgrade a Type I to operating-effectiveness assurance.
What should I do if a vendor cannot provide a bridge letter?
Ask for the next report’s expected date. If the period end is more than a few months old and neither a letter nor a date is available, treat the report as stale in your risk assessment.
Solomon Amos · Founder, CertReports
Solomon builds CertReports, the public evidence index for vendor security reviews. PhD in machine learning and cybersecurity, two years embedded at HMRC digital programmes, founder of TapTax. He writes about what registries, trust centres and auditors actually publish, and how buyers can use it before the questionnaire goes out.
Read next on CertReports
You might also like
SOC 2 Type I vs Type II: what each one proves to a buyer
Solomon Amos · 14 Sep 2026 · 10 min read