SOC 2
What is a SOC 2 bridge letter?
Your Type II report covers a period that ended months ago. The buyer wants to know nothing has changed since. That is what a bridge letter is for.
Certifyi compliance team · Updated September 2026
Short answer. A SOC 2 bridge letter (also called a gap letter) is a short statement written and signed by the service organisation, not the auditor, confirming that there have been no material changes to the control environment between the end date of the last SOC 2 Type II report and the date of the letter. It typically covers up to three months and is provided to customers on request while the next report is in progress.
Why the gap exists
A SOC 2 Type II report describes controls over a fixed observation period, usually six or twelve months. The auditor then needs several weeks to finish fieldwork and issue the opinion, and the report is typically dated one to two months after the period ends. If your period ended on 30 June and a buyer performs due diligence in October, the report is already four months stale. Procurement teams know this, which is why they ask for a bridge letter.
Who writes it and who signs it
The service organisation writes and signs the letter. Auditors do not issue bridge letters because they have not performed procedures over the gap period. It is normally signed by an executive responsible for security or compliance, on company letterhead, and dated. Some companies have the auditor acknowledge the letter, but that is not required and most firms decline.
What a bridge letter must say
Contents of a defensible bridge letter
- The report it bridges: report type, service auditor, period covered and report date.
- The period the letter covers, ending on the letter date.
- A statement that management is not aware of any material changes to the system, controls or control environment since the period end.
- Disclosure of any changes that did occur, even if judged immaterial, such as a new sub-processor or a platform migration.
- A statement that the next examination is in progress and its expected period and issue date.
- A caveat that the letter is not an auditor opinion and that the reader should rely on the report itself.
- Signature, title and date.
How long can it cover?
There is no rule, but buyers and auditors treat three months as the reasonable limit. Beyond that, a letter is asking the customer to trust an unaudited period longer than a quarter, and many enterprise security teams will refuse it. If your report is older than that, the fix is a shorter cycle, not a longer letter: many companies move to consecutive twelve-month periods so a fresh report is always within a few months.
How to avoid needing one
The cleanest answer is a continuous audit cycle with no gap between periods, plus a public Trust Center that shows live control status. When a buyer can see that MFA, encryption, access reviews and vulnerability scans are green today, the bridge letter becomes a formality rather than a negotiation. In Certifyi, the Trust Center publishes live posture from the same evidence record the auditor reads, and the next observation period starts the day the previous one ends.
Bridge letters, answered
Can the auditor sign the bridge letter?
No. The auditor has not tested the gap period, so the letter is management’s representation. Some firms will acknowledge receipt, but the signature is yours.
Is a bridge letter legally binding?
It is a written representation from management. If it turns out to be knowingly false, it can be treated like any other misrepresentation in a commercial relationship, so disclose changes honestly.
Do we need one for a Type I report?
Rarely. A Type I is a point-in-time design assessment, so buyers usually ask when the Type II will be available instead.
How often do customers ask for one?
Whenever due diligence happens more than about two months after your report date. Enterprise buyers, banks and public-sector customers ask most often.
Get audit-ready in 8 to 12 weeks
Certifyi pairs the platform with a named compliance lead who implements with your team, priced on scope and due at audit sign-off.