SOC 2 bridge letter: an outline, plus the hard version
A signed note from you covering the months after your SOC 2 period ended. Easy when nothing changed, harder when something did.
A SOC 2 bridge letter is a short statement, signed by an officer of your company, about the months between the end of your last report period and today. Some buyers call it a gap letter. Either way, your company writes it and your company signs it. The auditor does not.1
The easy version says nothing changed. This page also covers the version you need when something did.
Why the letter comes from you, not the auditor
Picture the calendar. Your report period closed in March, a prospect asks in August whether your controls still run, and the next examination has not begun. The letter fills those five months. It rarely runs past a page.
Ask your CPA firm to write it and they will decline, politely. Their report covers the period they tested. Writing about later months would put a licensed firm’s name on time it never examined, with no procedures behind it, and attestation practice does not allow that.1 A firm may read your draft. Reading is not signing.
So it goes out on your letterhead, addressed to the party asking, over an officer’s signature. Bridge letter, gap letter and continuity letter all mean this same page, so send it whatever the questionnaire calls it.
Five facts the letter states
Keep the content to facts you can point at later. A letter that sticks to these five stays defensible a year from now, when someone pulls it out of a procurement file and reads it against what actually happened.
- Which report
- Your company name, the report type, the exact period, and the CPA firm that performed the examination. Leave no room to wonder which report you mean.
- Which gap
- Two dates, written out. The first is the day after the report period ended. The second is the day you sign, never a future date.
- Continuity
- The controls in the report have continued to operate, to the best of management’s knowledge. Keep that qualifier. It is accurate.
- Changes
- Any material change to the system or the control environment during the gap. This line says “none” far more easily than it should.
- Who signs
- An officer who can bind the company, with title and date. A letter signed by an engineer on the company’s behalf carries less weight.
What a bridge letter cannot claim
No one examined the gap, so the letter gives no assurance. A careful reader treats it as a representation by your company and not as audit work. The report still speaks only for its own period,2 which is covered in our page on how long a SOC 2 report stays valid.
Nothing in the letter should suggest the CPA firm stands behind the gap. No firm logo, no paraphrase of the opinion, and no words like covered, certified or attested for the gap months. cybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.
A seven part outline you can copy
Here is the full structure, in order, with no email gate in front of it. Draft yours now, while nobody is waiting, so you can date it and send it the same day a request lands.
- Letterhead and date. Your company name and address, and the actual signature date, since that date closes the gap.
- Addressee. The customer or prospect by name. A general salutation works when the letter must circulate, but a named recipient reads stronger.
- The report. One sentence naming its type, its period and the issuing firm.
- The gap. One sentence, two dates: the day after the period ended through the signature date.
- The assertion. Management is not aware of any material change to the system or control environment in that period, other than those listed below. Keep the qualifier even if the list is empty.
- Changes. Either a sentence saying there were none, or the list. The next section is about writing the list well.
- Limitation and signature. A line saying the letter is unaudited and gives no assurance, then name, title, signature and date.
If you want a model for the formal tone, our management assertion template uses the same register, and a bridge letter is a smaller cousin of it.
When something changed during the gap
Every template we have read assumes a clean gap. Real gaps are messier. A reorganization happened. The security lead left. You moved clouds. A vendor on your critical path had an incident. Now the stock sentence, “no material changes have occurred,” is false, and an officer is about to sign it.
Rewrite the section instead of dropping it. A letter that names a change and describes it plainly holds up better than one claiming a clean gap, because the clean version is the one that gets checked. A status page, a news item or a former executive’s updated profile can contradict it.
Disclose the fact, not the effect
One rule runs through every row below. Say what happened and what you did about it. Never say it had no effect, since showing that takes an examination you have not had.
| The change | Write this | Do not write this |
|---|---|---|
| The security lead left | The role, the handover date, the new owner, and when handover finished | That access reviews and monitoring were unaffected |
| You changed cloud providers | Both providers, the cutover date, and which controls were rebuilt | That the new setup meets the same criteria |
| An in-scope vendor had an incident | When you learned of it, which systems touch that vendor, and what you changed | That customer data was untouched, unless you can show the work |
| A new product line shipped | What it is, and whether it sits inside the described system | That the existing report covers it |
| A control lapsed for a while | The control, the dates it stopped and resumed, and what you did about it | Nothing. Silence here is what loses deals |
That last row matters most. A lapse in the gap will likely show up as an exception in your next report, and a buyer who read the letter first will notice the order. What happens when a SOC 2 has exceptions shows how that reads in a finished report. It is calmer than people expect.
How long a buyer will accept one
No rule sets an expiry date. What decides acceptance is the length of the gap and how much the reader cares. A few weeks looks like scheduling. Close to a year looks like a company that replaced examinations with letters.
The person judging is a security reviewer following their own policy, not an AICPA rule. So ask them directly: what gap will you accept, and do you need the next report by a set date? If they name a date, you are planning an examination now, and the SOC 2 timeline is where to start.
The cost of a letter versus a new report
The letter itself is free. It takes an hour of an officer’s time and it buys goodwill. What it cannot buy is the thing it stands in for, which is a fresh report. For a sense of what that report runs elsewhere, here is one vendor’s own published range.
- Vanta states that the fees for a SOC 2 audit range between $10K and $50K. Source, checked 2026-07-30.
You do not need a consultant for the letter. You need the outline above and an honest change log. The report is the part you pay for. Continuous evidence collection through the 3-month observation window runs on our software, $199 a month, cancel any time. Audits go through our preferred pricing program, and we negotiate the fee on your behalf, and a Type 2 is quoted once the window completes.
Keep the gap short from here
A bridge letter is a symptom of a gap between reports. The cleanest way to need fewer of them is a tight examination cadence, which starts with how long the observation period has to be.
Two habits help. Keep a finished draft you can date and send in ten minutes. And keep a running log of anything that belongs on the changes list, so you are not rebuilding six months from memory while a deal waits. If you do not have a report yet, start with the free readiness assessment to see how close you are, or compare plans.
Questions
Who signs a SOC 2 bridge letter?
How long does a bridge letter stay valid?
What if something changed during the gap?
Does a bridge letter extend a SOC 2 report?
Is a gap letter the same as a bridge letter?
Sources
Get audit-ready without a compliance team
The readiness assessment is free, with no payment and no card. When you are ready, the software is $199 a month, cancel any time, and audits go through our preferred pricing program. You can be audit-ready starting at about a week.
Start with a free readiness assessmentcybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.