Skip to content

SOC 2 bridge letters: what they are and when to send one

By Sam Rivera, Founder, SentinelPanda · May 12, 2026 · 3 min read · SOC 2

A SOC 2 report covers a finite window. Customers who rely on it want assurance that nothing has changed between that window and today — that is what a bridge letter is for.

The gap a bridge letter closes

A SOC 2 Type II report covers a defined observation period — say, 1 April to 30 September. When a customer reviews it in November, they have assurance for that window only. The two months between October and the review date are uncovered. A bridge letter (sometimes called a gap letter, comfort letter, or interim letter) is a written statement from your management that the controls described in the most recent report continued to operate, and that no material changes occurred, between the report end date and the date of the letter.

When customers ask for one

  • A vendor onboarding review where your last Type II is older than six months.
  • A renewal cycle that lands between two Type II observation windows.
  • A security questionnaire that asks for current assurance, not just the most recent report.
  • A regulator or auditor of your customer who wants coverage up to a specific date.

What the letter should say

Bridge letters are short — typically one page. They identify the SOC 2 report, name the observation period it covered, confirm the period the letter covers (the gap), and state that to management's knowledge the controls in the report continued to operate effectively and there were no material changes to the control environment. They are signed by an executive officer of the issuing entity.

They are not assurance from your auditor. The CPA firm does not issue or sign the letter — management does. That is why the language is careful: "to management's knowledge" rather than an audit opinion.

What you need to be true to issue one

You can only honestly issue a bridge letter if the control environment really has been stable. That means no material restructure that affected control owners, no unremediated incidents that touched in-scope systems, no major architecture change that altered how a control operates, and no significant scope expansion. If any of those happened, the right answer is usually to issue a partial bridge that calls out the change, or to accelerate the next report.

A maximum sensible gap

There is no AICPA-mandated limit, but the practical ceiling most enterprise procurement teams accept is three to six months from the previous report end date. Beyond that the bridge letter starts to feel like a substitute for fresh assurance, and a careful procurement reviewer will ask for the next report. Plan your observation periods so the next report drops before the bridge letter you would otherwise issue gets stale.

A clean process beats a reactive scramble

The teams that handle bridge letters well track them like any other deliverable: a register of who received which letter and when, a templated body that pulls the current control inventory and the most recent report metadata, and a quarterly cadence so renewals do not surprise anyone. Treating each request as a one-off is how the letter ends up sitting in someone's drafts for two weeks while the customer's procurement deadline slips.

SOC 2 Type I vs Type II Vendor risk management, explained

Run your compliance program in one workspace.