SOC 2 bridge letter: an outline, plus the hard version

A signed note from you covering the months after your SOC 2 period ended. Easy when nothing changed, harder when something did.

A SOC 2 bridge letter is a short statement, signed by an officer of your company, about the months between the end of your last report period and today. Some buyers call it a gap letter. Either way, your company writes it and your company signs it. The auditor does not.1

The easy version says nothing changed. This page also covers the version you need when something did.

Why the letter comes from you, not the auditor

Picture the calendar. Your report period closed in March, a prospect asks in August whether your controls still run, and the next examination has not begun. The letter fills those five months. It rarely runs past a page.

Ask your CPA firm to write it and they will decline, politely. Their report covers the period they tested. Writing about later months would put a licensed firm’s name on time it never examined, with no procedures behind it, and attestation practice does not allow that.1 A firm may read your draft. Reading is not signing.

So it goes out on your letterhead, addressed to the party asking, over an officer’s signature. Bridge letter, gap letter and continuity letter all mean this same page, so send it whatever the questionnaire calls it.

Five facts the letter states

Keep the content to facts you can point at later. A letter that sticks to these five stays defensible a year from now, when someone pulls it out of a procurement file and reads it against what actually happened.

Which report
Your company name, the report type, the exact period, and the CPA firm that performed the examination. Leave no room to wonder which report you mean.
Which gap
Two dates, written out. The first is the day after the report period ended. The second is the day you sign, never a future date.
Continuity
The controls in the report have continued to operate, to the best of management’s knowledge. Keep that qualifier. It is accurate.
Changes
Any material change to the system or the control environment during the gap. This line says “none” far more easily than it should.
Who signs
An officer who can bind the company, with title and date. A letter signed by an engineer on the company’s behalf carries less weight.

What a bridge letter cannot claim

No one examined the gap, so the letter gives no assurance. A careful reader treats it as a representation by your company and not as audit work. The report still speaks only for its own period,2 which is covered in our page on how long a SOC 2 report stays valid.

It is your signature on a stretch of time nobody tested.
Lines not to cross

Nothing in the letter should suggest the CPA firm stands behind the gap. No firm logo, no paraphrase of the opinion, and no words like covered, certified or attested for the gap months. cybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.

A seven part outline you can copy

Here is the full structure, in order, with no email gate in front of it. Draft yours now, while nobody is waiting, so you can date it and send it the same day a request lands.

  1. Letterhead and date. Your company name and address, and the actual signature date, since that date closes the gap.
  2. Addressee. The customer or prospect by name. A general salutation works when the letter must circulate, but a named recipient reads stronger.
  3. The report. One sentence naming its type, its period and the issuing firm.
  4. The gap. One sentence, two dates: the day after the period ended through the signature date.
  5. The assertion. Management is not aware of any material change to the system or control environment in that period, other than those listed below. Keep the qualifier even if the list is empty.
  6. Changes. Either a sentence saying there were none, or the list. The next section is about writing the list well.
  7. Limitation and signature. A line saying the letter is unaudited and gives no assurance, then name, title, signature and date.

If you want a model for the formal tone, our management assertion template uses the same register, and a bridge letter is a smaller cousin of it.

When something changed during the gap

Every template we have read assumes a clean gap. Real gaps are messier. A reorganization happened. The security lead left. You moved clouds. A vendor on your critical path had an incident. Now the stock sentence, “no material changes have occurred,” is false, and an officer is about to sign it.

Rewrite the section instead of dropping it. A letter that names a change and describes it plainly holds up better than one claiming a clean gap, because the clean version is the one that gets checked. A status page, a news item or a former executive’s updated profile can contradict it.

Disclose the fact, not the effect

One rule runs through every row below. Say what happened and what you did about it. Never say it had no effect, since showing that takes an examination you have not had.

The changeWrite thisDo not write this
The security lead leftThe role, the handover date, the new owner, and when handover finishedThat access reviews and monitoring were unaffected
You changed cloud providersBoth providers, the cutover date, and which controls were rebuiltThat the new setup meets the same criteria
An in-scope vendor had an incidentWhen you learned of it, which systems touch that vendor, and what you changedThat customer data was untouched, unless you can show the work
A new product line shippedWhat it is, and whether it sits inside the described systemThat the existing report covers it
A control lapsed for a whileThe control, the dates it stopped and resumed, and what you did about itNothing. Silence here is what loses deals

That last row matters most. A lapse in the gap will likely show up as an exception in your next report, and a buyer who read the letter first will notice the order. What happens when a SOC 2 has exceptions shows how that reads in a finished report. It is calmer than people expect.

How long a buyer will accept one

No rule sets an expiry date. What decides acceptance is the length of the gap and how much the reader cares. A few weeks looks like scheduling. Close to a year looks like a company that replaced examinations with letters.

The person judging is a security reviewer following their own policy, not an AICPA rule. So ask them directly: what gap will you accept, and do you need the next report by a set date? If they name a date, you are planning an examination now, and the SOC 2 timeline is where to start.

The cost of a letter versus a new report

The letter itself is free. It takes an hour of an officer’s time and it buys goodwill. What it cannot buy is the thing it stands in for, which is a fresh report. For a sense of what that report runs elsewhere, here is one vendor’s own published range.

  • Vanta states that the fees for a SOC 2 audit range between $10K and $50K. Source, checked 2026-07-30.

You do not need a consultant for the letter. You need the outline above and an honest change log. The report is the part you pay for. Continuous evidence collection through the 3-month observation window runs on our software, $199 a month, cancel any time. Audits go through our preferred pricing program, and we negotiate the fee on your behalf, and a Type 2 is quoted once the window completes.

Keep the gap short from here

A bridge letter is a symptom of a gap between reports. The cleanest way to need fewer of them is a tight examination cadence, which starts with how long the observation period has to be.

Two habits help. Keep a finished draft you can date and send in ten minutes. And keep a running log of anything that belongs on the changes list, so you are not rebuilding six months from memory while a deal waits. If you do not have a report yet, start with the free readiness assessment to see how close you are, or compare plans.

Questions

Who signs a SOC 2 bridge letter?
An officer of your company signs it, on your letterhead, addressed to the customer who asked. The audit firm does not, because its report only covers the period it tested, and signing a letter about later months would attach its name to work it never did.
How long does a bridge letter stay valid?
It has no set expiry. It covers the gap it names, from the day after your report period ended to the day you sign. Each buyer decides how long a gap they will accept, and past that point they will want a new report rather than a new letter.
What if something changed during the gap?
Disclose it. State what changed, when, which control it touched and what replaced it. Do not claim the change had no effect, because you cannot test that yourself, and a reader who later learns otherwise will stop trusting the rest of the letter.
Does a bridge letter extend a SOC 2 report?
No. The report still covers only its own period. The letter adds your unaudited statement about what has happened since, and carries no assurance from the auditor.
Is a gap letter the same as a bridge letter?
Yes. Bridge letter, gap letter and continuity letter all describe the same one page document. Send the same letter whichever name a questionnaire uses.

Sources

  1. Statements on Standards for Attestation Engagements AICPA. The attestation standards a SOC 2 examination is performed under. Checked 1 August 2026.
  2. SOC 2 Report AICPA. What a SOC 2 report is and who may issue one. Checked 1 August 2026.

Get audit-ready without a compliance team

The readiness assessment is free, with no payment and no card. When you are ready, the software is $199 a month, cancel any time, and audits go through our preferred pricing program. You can be audit-ready starting at about a week.

Start with a free readiness assessment

cybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.