Bridge Letter
A bridge letter is a document a service organization writes on its own letterhead to cover the time gap between the end of its most recent SOC audit report period and a later date, such as when a customer needs assurance. In it, the organization self-attests that no material changes to its controls have occurred since the last audit. It is meant to cover only short gaps and does not replace an actual audit.
A bridge letter (also called a gap letter) is a self-attestation issued by a service organization to bridge the interval between the end date of its SOC report's examination period and a subsequent date required by a user organization or auditor. The letter is prepared on the service organization's own letterhead, not by the auditor, and typically affirms that no material changes to the relevant control environment have occurred during the gap period. It is intended to cover only short gaps between reporting periods and provides self-reported assurance rather than independent audit coverage; it does not extend the auditor's opinion or constitute an examination of the gap period itself.
Why it matters
In vendor risk management, SOC reports cover a defined examination period, but a customer often needs assurance about a date that falls after the report's end date. A bridge letter addresses this timing problem by allowing a service organization to self-attest that no material changes to its control environment have occurred during the short interval between the SOC report period and the later date in question. This lets a user organization continue relying on an existing report while waiting for the next audit cycle, rather than pausing a relationship or demanding an out-of-cycle examination.
Who it's relevant to
Inside Bridge Letter
Common questions
Answers to the questions practitioners most commonly ask about Bridge Letter.