Skip to main content
Category: Audit & Attestation

Bridge Letter

Also known as: Gap Letter, SOC Bridge Letter
Simply put

A bridge letter is a document a service organization writes on its own letterhead to cover the time gap between the end of its most recent SOC audit report period and a later date, such as when a customer needs assurance. In it, the organization self-attests that no material changes to its controls have occurred since the last audit. It is meant to cover only short gaps and does not replace an actual audit.

Formal definition

A bridge letter (also called a gap letter) is a self-attestation issued by a service organization to bridge the interval between the end date of its SOC report's examination period and a subsequent date required by a user organization or auditor. The letter is prepared on the service organization's own letterhead, not by the auditor, and typically affirms that no material changes to the relevant control environment have occurred during the gap period. It is intended to cover only short gaps between reporting periods and provides self-reported assurance rather than independent audit coverage; it does not extend the auditor's opinion or constitute an examination of the gap period itself.

Why it matters

In vendor risk management, SOC reports cover a defined examination period, but a customer often needs assurance about a date that falls after the report's end date. A bridge letter addresses this timing problem by allowing a service organization to self-attest that no material changes to its control environment have occurred during the short interval between the SOC report period and the later date in question. This lets a user organization continue relying on an existing report while waiting for the next audit cycle, rather than pausing a relationship or demanding an out-of-cycle examination.

Who it's relevant to

Service Organizations Undergoing SOC Examinations
Companies that have completed a SOC audit and face customer requests for assurance covering a date after their report period can issue a bridge letter to cover the short gap. They should understand that they are making a self-attestation on their own letterhead and are representing that no material changes to controls have occurred, so the statement must be accurate.
User Organizations and Their Vendor Risk Teams
Teams evaluating a vendor's SOC report may receive a bridge letter to cover the interval between the report end date and their current assessment date. They should recognize that a bridge letter is self-reported assurance, not independent audit coverage, and treat it accordingly when the gap is short. For longer gaps, they should request an updated SOC report.
Virtual and Fractional CISOs Advising Clients
A vCISO or fractional CISO supporting a client's compliance program may advise on when a bridge letter is appropriate to provide or accept, and where its limits lie. This is a governance and risk-advisory function: the vCISO can direct how such letters are handled, but accountability for the accuracy of any self-attestation issued by the client organization remains with the client and its officers.

Inside Bridge Letter

Coverage Gap Statement
The core purpose of a bridge letter is to address the gap period between the end date of a prior SOC report (such as SOC 2) and a later point in time, often a customer's fiscal year-end or a due diligence date. It affirms that the described controls were in operation during this interim window not covered by an examination.
Reference to the Underlying SOC Report
A bridge letter identifies the specific SOC report it relates to, including the service organization, the type of report, and the reporting period covered, so the reader understands what examined report is being extended.
Management Assertion
The letter is typically issued and signed by the service organization's management, not by the independent auditor. It represents management's own assertion that no material changes to the control environment occurred during the gap period.
Disclosure of Changes or Exceptions
A properly prepared bridge letter should state whether any significant changes to controls, systems, or the operating environment occurred during the gap period, rather than implying a blanket assurance that nothing changed.
Effective Date Range
The letter specifies the precise start and end of the interim period it is intended to cover, tying the assertion to a defined timeframe.

Common questions

Answers to the questions practitioners most commonly ask about Bridge Letter.

Does a bridge letter extend or renew the coverage period of a SOC 2 report?
No. A bridge letter, sometimes called a gap letter, does not extend the audit coverage of a SOC 2 report and provides no independent assurance for the gap period. It is a representation from the service organization's management, not a work product of the auditor, and it typically states that management is not aware of material changes to controls between the end of the report's coverage period and the letter's date. The underlying controls have not been tested or examined by the auditor for that interim window.
Can a virtual CISO or the auditor sign a bridge letter on the organization's behalf?
In most cases the bridge letter is issued and signed by the service organization's own management, because it is a management representation about the period since the last examination. The auditor generally does not issue bridge letters, since doing so could imply assurance over an untested period. A virtual CISO may help management prepare, review, or coordinate the letter and advise on its language, but signing authority and the accountability for the representations typically remain with the client organization's officers. Practice may vary by provider and engagement scope.
When during an engagement is a bridge letter typically requested?
A bridge letter is often requested when a customer or prospect asks for current assurance but the most recent SOC 2 report's coverage period has ended and the next report is not yet available. This commonly arises during vendor due diligence, contract renewals, or procurement reviews that fall between report cycles. The letter helps cover the gap between the report end date and the present, though it does not substitute for a new examination.
What should a bridge letter typically include?
A bridge letter often identifies the prior SOC 2 report and its coverage period, states the gap period being addressed, and includes a management representation that there have been no material changes to the relevant controls during that gap, or discloses any changes that have occurred. It is usually signed by an authorized officer of the service organization. Specific content and format may vary by provider and by the requesting party's expectations, so a virtual CISO can help ensure the language is accurate and does not overstate assurance.
How long a gap period can a bridge letter reasonably cover?
Bridge letters are generally intended to cover a limited interim period, and many recipients expect them to span only a few months rather than an extended timeframe. As the gap grows, reliance on a management representation with no independent testing becomes weaker, and requesting parties may instead expect a new examination. The acceptable length can vary by the recipient's risk tolerance and internal policies, so scope and expectations should be confirmed with stakeholders.
What are the limitations of relying on a bridge letter for vendor assurance?
The primary limitation is that a bridge letter offers no independent, tested assurance for the gap period; it reflects management's own assertions, so its value depends on the organization's cooperation and candor. It does not confirm that controls operated effectively during the interim, does not replace a SOC 2 examination or certification, and does not guarantee that no material changes occurred. Its usefulness also depends on the requesting party's willingness to accept a management representation in place of a current report.

Common misconceptions

A bridge letter is an audit or provides the same level of assurance as a SOC report.
A bridge letter is generally a management-prepared representation, not an independent examination. It does not carry the assurance of an auditor's opinion and should not be treated as a substitute for a SOC 2 or similar report covering the gap period.
A bridge letter guarantees that controls operated effectively during the gap period.
It typically reflects management's assertion that no material changes occurred, not verified evidence of control effectiveness. The reliability of that assertion depends on the honesty and diligence of the issuing organization, and it should not be read as a guarantee against control failures or breaches.
A virtual CISO can unilaterally issue a bridge letter on behalf of a client.
A bridge letter usually represents an assertion by the client organization's management, who retain accountability for its accuracy. A virtual CISO may advise on, help draft, or review such a letter, but the organization and its officers generally bear responsibility for the representations made.

Best practices

Limit the reliance placed on a bridge letter and treat it as a short-term supplement rather than a long-term replacement for an updated SOC report covering the relevant period.
Ensure the letter clearly references the underlying SOC report and specifies the exact gap period it is intended to cover.
Have the letter explicitly disclose any material changes to controls, systems, or the operating environment during the interim period rather than asserting a blanket 'no change.'
Confirm that the letter is signed by an appropriate member of the client organization's management, since accountability for the assertion typically rests with the organization and its officers.
Advise clients that a bridge letter does not carry the assurance of an independent examination and should not be represented to customers or auditors as equivalent to a SOC report.
When advising on a bridge letter, document scope and limitations so that the roles of management (asserting) and any advisor such as a virtual CISO (guiding or reviewing) remain clearly separated.