By Marçal Santos, vCISO and founder of SecureLeap. CISM and CDPSE (ISACA). Previously security roles at Aircall, Citibank and Talkdesk. 20 years in cybersecurity.
A timeline showing a SOC 2 Type II audit period ending 30 September, a customer fiscal year ending 31 December, and a shaded bridge period covering the three months between them
A SOC 2 bridge letter is a short memo, signed by your own executives and not by your auditor, stating whether anything material changed in your control environment since your last SOC 2 report period ended. It covers the gap between that end date and today, or your customer's fiscal year end. Most customers accept up to 90 days.
That is the whole thing. The reason this request derails so many deals is not the letter, it is that nobody inside the vendor owns it. The security team assumes the auditor writes it. The auditor cannot. The CEO signs something they have not read. Two weeks disappear.
This guide gives you the letter first, then the operational answers the other guides skip: who signs, what happens when your gap runs past 90 days, whether the same document works for SOC 1 and ISAE 3402, and what to do when a customer rejects it.
What a SOC 2 bridge letter actually is
A bridge letter, also called a gap letter, is a management representation. You are asserting something about a period nobody independently tested. That is the single most important thing to understand about it, and it is what determines everything else in this guide.
Your SOC 2 Type II report covers a defined window, typically 6 to 12 months of operating effectiveness. The moment that window closes, the report starts ageing. A customer whose fiscal year ends 31 December, looking at a report covering 1 October to 30 September, has three months of unexplained time. The letter explains it.
It is worth being precise about what the letter is not, because customers occasionally treat it as more than it is. Andrew Wan, CPA and CFE, an audit partner at Larson & Company, puts the boundary plainly:
"A bridge letter is prepared by management of the service organization and does not need or have any assurance provided by the independent service auditor."
There is also no official form to follow. Megan Kovash, CPA and partner at Linford & Company, notes that "the AICPA doesn't actually cover bridge letter requirements in the SOC guidance so there is no guidance on the specific requirements." The AICPA's SOC suite of services defines the reports themselves, not the memo that fills the gap between them. Practice has converged on a common structure anyway, which is the one below.
Why customers ask for one
Because the person asking is drowning, and your letter is the fastest way out of their queue.
Vanta's 2025 State of Trust Report, conducted with Sapio Research in July 2025 across 3,500 business and IT leaders, found that organisations spend an average of 9 working weeks per year on vendor security reviews and risk assessments, and 12 working weeks per year on compliance tasks overall. In the same study, 61% of leaders said they spend more time proving security than improving it, and 72% said security risks for their company have never been higher, a 17 point jump from 2024.
That is the context for the request. A security analyst with a vendor file open and a date that does not reach their year end has two options: send you a 200-question spreadsheet, or accept a one-page letter. Give them the letter within 48 hours and you have made their week easier. Take three weeks and you have invited the spreadsheet.
The specific triggers, in rough order of how often we see them:
- Customer fiscal year end falls after your report period ends. The classic. Their auditors need coverage through 31 December.
- Your next audit is running late. Auditor scheduling, a scope change, an acquisition.
- Contract renewal or a new enterprise deal where procurement checks report currency as a gating item.
- Your customer is itself being audited and their auditor is testing reliance on your controls.
The template: copy, paste, adapt
Here it is. One page, on your letterhead. Replace the bracketed fields, pick Option A or Option B, and delete the one you do not use.
[COMPANY LETTERHEAD]
SOC 2 Bridge Letter
Date: [Current date] To: Security and Risk Management, [Customer name]
Reference to most recent SOC 2 report
[Your company name] ("the Company") completed a SOC 2 Type II examination for the period [start date] through [end date], performed by [audit firm name]. A copy of that report has been provided to [Customer name] separately.
Bridge period
This letter covers the period from [first day after the SOC 2 end date] through [current date or customer fiscal year end].
Statement regarding material changes
Option A, no material changes:
Management confirms that there have been no material changes to the Company's internal control environment, security controls, or systems since the end of the period covered by the report referenced above. The controls described in that report have continued to operate as designed throughout the bridge period.
Option B, material changes occurred:
Management notes the following material changes since the end of the period covered by the report referenced above:
[Change, date it occurred, and the compensating controls in place][Change, date it occurred, and the compensating controls in place]
Notwithstanding these changes, management believes the control environment continues to provide reasonable assurance regarding the applicable trust services criteria for [security / availability / confidentiality / processing integrity / privacy].
Disclaimers
This letter is not a SOC 2 report. It has not been examined by an independent auditor and does not constitute an attestation or assurance report under AICPA standards. It is a representation by management and should be read together with the Company's SOC 2 Type II report. It is provided solely for the use of [Customer name] and is not intended for general distribution.
Contact
[Name, title, email]
Signatures
[Name], Chief Executive Officer, [Date]
[Name], Chief Technology Officer or Chief Information Security Officer, [Date]
Two notes before you send it. Read Option A out loud before you sign it, because you are attesting to it personally. And if you are hesitating over whether something counts as material, it probably does. Use Option B.
What has to be in it
Every element earns its place, and each one exists because a customer's auditor will look for it.
Who signs it, and who does not
Your auditor does not sign it. This is the most common misunderstanding and it costs the most time, because vendors email their CPA firm, wait a week, and get told no. CompliancePoint describes the letter as a "self-assertion" that "does not constitute a formal attestation or assurance report under the AICPA standards." An auditor attesting to a period they never tested would break the independence model the report depends on.
Signature authority sits with executives who can genuinely speak to the control environment.
In practice, we recommend at least one signatures: CEO , CTO or CISO.
How log it can cover, and the 90-day rule
Three months is the working ceiling. It is convention rather than a rule written down anywhere, which is exactly why it holds: no standards body set it, so nobody can waive it either.
The logic is straightforward. SOC 2 examinations recur annually. A bridge of a few months is a small extrapolation from tested controls. A bridge of eight months is management asserting most of a year on its own authority, which is not a bridge, it is a replacement.
What to do depends on your actual gap:
If you are in the third or fourth row, the underlying problem is audit cadence, not documentation. A SOC 2 Type II programme that slips a quarter every year eventually produces a gap no letter can cover.
Decision tree showing four gap-length branches from a SOC 2 report end date, each leading to a recommended action
When material changes did happen
Most vendors reach for Option A automatically. Slow down, because this is where the actual liability lives.
Material means anything that would change how a reasonable customer assesses your control environment. Concretely: a security incident affecting customer data, a cloud provider or region migration, a change of subprocessor handling customer data, the loss of a key security role with no backfill, a significant architectural change to the production environment, an acquisition or divestiture, or a control you have quietly stopped operating.
When one of these applies, Option B is not a confession, it is normal. The structure that works is three sentences per change: what changed, when, and what control covered the risk in the meantime.
"On 14 March 2026 the Company migrated production workloads from AWS eu-west-1 to eu-central-1. The migration was executed under the existing change management process, with access controls, logging and encryption configurations replicated and verified prior to cutover. An independent penetration test of the new environment was completed on 2 April 2026 with no critical findings."
That paragraph does more for you than Option A would have. It shows a functioning change process. The failure mode is not disclosing a change, it is signing Option A when your customer later learns about the change from a breach notification, a status page, or a press release. Your letter is then a signed misstatement, and the conversation moves from procurement to legal.
Does the same letter work for SOC 1 and ISAE 3402?
Yes, with two adjustments. Almost nothing written about bridge letters covers this, even though the request arrives just as often.
The mechanics are identical because SOC 1 and ISAE 3402 are, like SOC 2, period-based attestation reports with a defined start and end date, so they produce the same gap. Use the same template and change the reference line to name the correct report.
Adjustment one, the audience. A SOC 2 bridge letter is read by a security team. A SOC 1 bridge letter is read by your customer's financial statement auditors, who are testing whether they can rely on your controls for their opinion on the customer's financials. Your material changes statement has to speak to controls relevant to financial reporting, which means transaction processing, calculation accuracy, completeness of data, and access to financial systems. A change that matters enormously for SOC 2 (say, a new SSO provider) may be irrelevant for SOC 1, and a change that barely registers for SOC 2 (a billing engine version bump) may be exactly what the financial auditor cares about.
Adjustment two, the standard cited. ISAE 3402 is the international equivalent of SOC 1, issued under the IAASB rather than the AICPA. If your customer is European and asked for an ISAE 3402 bridge letter, reference the ISAE 3402 report and drop the AICPA wording from the disclaimer. The substance does not change.
If you hold both a SOC 1 and a SOC 2, do not merge them into one letter. Issue two, each referencing its own report and each addressed to the team that asked. Merging them produces a document that neither audience can rely on cleanly.
When a customer rejects your bridge letter
It happens, and the guides never cover it. Three reasons account for almost every rejection.
The gap is too long. Nothing in the letter will fix this. Offer the supporting evidence from the gap table above and give a firm date for the next report.
Their policy requires independent attestation. Some regulated buyers, particularly in financial services, have third-party risk policies that do not recognise management representations at all. Do not argue the point, it is their policy. Offer a Type I over the interim period, or ask whether an independent penetration test report and continuous monitoring evidence would satisfy the control owner. Our pentest reports are formatted as audit evidence for exactly this reason.
The letter was vague. Undated bridge period, no reference to the underlying report, no signature, or a material changes statement so hedged it asserts nothing. This one is your fault and it is fixable in an hour. Resend using the template above.
Five steps to stop scrambling every quarter
The letter takes 20 minutes to write when you have prepared, and two weeks when you have not. The difference is entirely in these five habits.
1. Name an owner before the request arrives. One person drafts, one executive signs, one person maintains the evidence. Write it down. In every engagement where a bridge letter turned into a fire drill, the cause was that three people each assumed one of the other two owned it.
2. Keep a change log from the day your audit period ends. A running list of infrastructure changes, subprocessor changes, incidents, and personnel changes in security roles. Two lines per entry. This log is the entire evidence base for your material changes statement, and reconstructing it eight months later from Slack and Jira is how vendors end up signing Option A when Option B was the honest answer.
3. Keep both template versions ready. Option A and Option B, pre-approved by legal, sitting in a folder. The version you need is never the one you expected.
4. Align your audit window with your customers' fiscal years. If most of your enterprise base closes on 31 December, a report period ending 31 December eliminates the gap entirely. Moving your period is a one-time inconvenience during an audit cycle and it removes a recurring quarterly task.
5. Have supplementary evidence on the shelf. A current pentest report, a vulnerability scan summary, and continuous monitoring output turn a contested bridge letter into an accepted package.
Common mistakes
- Asking your auditor to issue it. They cannot. You lose a week finding out.
- Signing Option A without checking the change log. Or without having a change log, which is the same mistake with an extra step.
- Leaving the bridge period undated. "Since our last report" is not a period. Give both dates.
- Reusing last quarter's letter with the dates changed. The changes statement has to be re-evaluated each time, and reviewers notice when it never varies.
- Sending it as an image or a locked PDF export with no signature. Reviewers need to see signatures and be able to attach it to their file.
- Treating it as an alternative to the next audit. It buys weeks, not quarters. Plan the audit anyway. If you are budgeting for that, our breakdown of SOC 2 costs covers what the next cycle actually runs.
SOC2 Bridge Letter FAQs
What is a SOC 2 bridge letter?
It is a memo signed by your management stating whether material changes occurred in your security controls since your last SOC 2 report period ended. It bridges the gap between that end date and your customer's fiscal year end or the current date. It is a management representation, not an audited document.
Who signs a SOC 2 bridge letter?
Senior leadership: typically the CEO plus the CTO or CISO, or the CFO when the request came from a finance audit. Your CPA firm neither signs nor issues it, because auditors cannot attest to a period they have not tested.
How long is a SOC 2 bridge letter valid?
Up to about 90 days is accepted routinely. Between 90 and 180 days, pair it with supporting evidence. Beyond roughly 270 days, customers will generally reject it and you need a new report.
Is a SOC 2 bridge letter mandatory?
Not under any standard. The AICPA publishes no bridge letter requirements or template. In practice, enterprise customers frequently make it a contractual or policy requirement during vendor due diligence.
What happens if material changes occurred during the gap period?
Disclose them. State what changed, when it happened, and what compensating controls covered the risk. Signing a no-material-changes statement when significant changes occurred turns a routine document into a signed misstatement.
Can I use one bridge letter for all my customers?
Draft one master version and address each copy to a specific customer, since the letter should state the customer it is provided for and the bridge period may differ if fiscal year ends differ.
Does a bridge letter work for SOC 1 or ISAE 3402?
Yes. Same structure, referencing the correct report. For SOC 1 and ISAE 3402, your material changes statement should address controls relevant to financial reporting rather than security controls, because the audience is your customer's financial auditors.
How often will I need to issue one?
Most vendors issue between two and six a year, concentrated around customer fiscal year ends, typically Q4 and Q1. Aligning your audit period with your largest customers' year ends reduces this substantially.
Need the audit behind the letter?
A bridge letter only works when there is a current SOC 2 report underneath it and a control environment that has genuinely held. SecureLeap runs SOC 2 consultancy and audit facilitation for seed to Series B B2B SaaS companies: gap analysis, policy and control design, evidence collection, and managing your external auditor so the report period lands where your customers need it.
Book a 30 minute call and we will look at your report dates against your customer base and tell you whether you have a bridge letter problem or an audit timing problem.
This guide describes common practice, not a standard. The AICPA publishes no bridge letter requirements. Confirm expectations with your auditor and your customer before issuing one.

