skip to content

What is a SOC 2 bridge letter, who issues it, and what assurance does it give an enterprise customer?

level: middleimportance: should knowfreq 35%

answer

  1. period end to today
  2. gap letter
  3. signed by management
  4. no auditor opinion
  5. until the next report

basics

~20 s

A SOC 2 bridge letter covers the gap between the end of the last report's period and today. Management of the service organization issues it, stating no material changes or failures; it carries no auditor opinion, so its assurance is limited.

solid answer

~50 s

A SOC 2 Type II opinion stops at the last day of its period, but a customer's procurement review happens months later. A **bridge letter** (also called a gap letter) covers that gap. It is written and signed by the **service organization's management**, not the service auditor, and typically states: the period of the last report; the gap period covered; that there have been no material changes to the system or controls described, or what they are; that management knows of no significant control failures or security incidents in the gap, or discloses them; and when the next report is expected. Because no auditor tested anything, it is a management representation with no opinion. It is accepted for a limited gap, commonly up to a few months; a much longer gap, or a letter disclosing material changes, calls for more evidence or the next report.

go deeper

for a junior

Recall that a bridge letter covers the time from the report period's end to today and is signed by the vendor's management, not the auditor.

for a middle

Explain what the letter states, why its assurance is limited, and how long a gap customers typically accept.

for a senior

Show how you judge a bridge letter that discloses changes or incidents, and how you spot non-contiguous report periods it cannot fix.

for a principal

Discuss how a vendor should align its report periods and issue dates to its sales cycle so bridge letters stay short and credible.

## The problem a bridge letter solves A **SOC 2 Type II** report gives an opinion on controls **throughout a specified period** — say 1 January to 31 December. The report is issued some weeks after that period ends. A customer's procurement team reviewing the vendor in June is looking at an opinion about last year, with a gap of about six months in which nothing has been examined. A **bridge letter** (often called a **gap letter**) is the conventional way to cover that gap until the next report is issued. ## Who issues it The **service organization's management** writes and signs it. The **service auditor** does not issue it, has not tested the gap period, and gives no opinion on it. This is the most important fact about a bridge letter: it is a **representation**, not an attestation. ## What it usually contains | Element | Purpose | |---|---| | Reference to the last report | Type, categories, period and auditor | | Gap period covered | From the day after the period end to the letter date | | Statement on system changes | No material changes to the system description, or a description of them | | Statement on controls | No known significant deficiencies or failures, or a disclosure of them | | Statement on incidents | No known security incidents affecting the system, or a disclosure | | Next report | Expected period and issue date | | Signature | An officer of the service organization | ## How much weight it carries - It relies on management's honesty and knowledge, not on testing. - It is usually accepted for a **limited gap**, commonly up to around three months, and customers often question longer ones. - It cannot cure a gap in the **coverage periods** between two reports: if one period ended in June and the next starts in October, those months were never examined, and the bridge letter only asserts about the time since the last report. - A letter disclosing **material changes** — a new hosting provider, a re-architected authentication system, a significant incident — is a signal to ask for more evidence rather than to file it. ## A B2B SaaS vendor's example The vendor's last Type II covered 1 January to 31 December and was issued in February. In May an enterprise customer's procurement team asks for assurance. 1. The vendor provides the Type II report under NDA. 2. It provides a bridge letter covering 1 January to 30 April, signed by its chief technology officer, stating no material changes to the system description, no known control failures, one low-severity incident handled under its incident procedure, and that the next report will cover the current calendar year. 3. The procurement team accepts it, notes the incident for follow-up, and diarises the next report. ## What a customer should check - The letter refers to the correct report and period. - The gap is short enough to be credible. - Changes and incidents are disclosed rather than silently absent. - The signer has authority over the controls. - The next report's period starts where the last one ended. ## Misreadings - "The auditor signed off the gap" — the auditor did not. - "A bridge letter extends the report's validity" — SOC 2 reports have no validity term; the letter only adds management's word for the gap. - "One bridge letter can cover a year" — at that length it is a substitute for an examination, and customers should treat it as such.

  • Can a bridge letter cover a gap between two report periods?
    No. It covers the time from the end of the latest report's period to the letter date. If one report ended in June and the next period started in October, the months between were never examined, and a letter written later cannot turn them into audited time. Customers should check that consecutive reports' periods are contiguous.
  • What should a customer do if the bridge letter discloses a material change?
    Treat it as new scope that no auditor has examined: ask what changed, what controls now apply, and whether the next report will cover it. Depending on the change's risk, request supporting evidence, a call with the vendor's security team, or contractual commitments until the next Type II report is issued.

saying these in an interview costs you the question

  • The service auditor issues and signs the bridge letter.
  • A bridge letter carries the same assurance as the report.
  • A bridge letter can cover any length of gap.
  • A bridge letter fills gaps between two report periods.
  • A bridge letter extends the SOC 2 report's validity term.