The letter that covers the gap between two SOC 2 reports, who has to sign it, how long customers will accept it for, and the situations where it will not save the deal.
A SOC 2 bridge letter, also called a gap letter, is a short signed statement from your own management confirming that the controls described in your last SOC 2 report have continued to operate, covering the period between the end of that report and the start of your next one. Your organisation writes and signs a SOC 2 bridge letter. Your auditor does not. A SOC 2 bridge letter carries no independent assurance, because no audit work sits behind it, and by convention it covers no more than three months of gap.
A SOC 2 bridge letter is usually one page. The AICPA SOC reporting framework defines no template for one, but customers have settled on a consistent set of elements.
| Element | What to state | Example wording |
|---|---|---|
| The prior report | The period and type of your last report | SOC 2 Type II, 1 Jan 2026 to 31 Dec 2026 |
| The audit firm | The CPA firm that issued it | Issued by [CPA firm name] |
| The gap period | Exact start and end dates this letter covers | 1 Jan 2027 to 31 Mar 2027 |
| Control changes | Material changes since the report, or a statement of none | No material changes have occurred |
| Known incidents | Anything that would change the report's conclusions | Nothing has come to our attention |
| Next report | The window in progress and when the report is due | Next window ends 31 Dec 2027 |
| Disclaimer | That this is not an audit or a substitute for the report | Not a substitute for a SOC 2 report |
| Signature | Name, title and date of a signing officer | Signed by the CEO, CTO or CISO |
You do. A SOC 2 bridge letter is drafted, approved and signed by the service organisation, normally by an officer such as the CEO, CTO or CISO. The CPA firm that performed your last SOC 2 audit will not write it, sign it or review it. Independence rules mean an auditor cannot assert that controls were effective during a period they did not examine, so a bridge letter signed by an auditor would be meaningless. Everything in a SOC 2 bridge letter is therefore your assertion, and you are accountable for it.
Three months is the working limit most customers and procurement teams apply to a SOC 2 bridge letter. No standard sets that figure and no expiry is built into the document. It reflects what a reasonable customer will accept on trust before wanting tested evidence again. Beyond three months, the gap reads less like a scheduling overlap and more like a lapse.
| Length of gap | How customers usually treat it | What to do |
|---|---|---|
| 0 to 1 month | Routine, rarely questioned | Send the letter with the prior report |
| 1 to 3 months | Generally accepted with the letter attached | Name the date the new report is due |
| 3 to 6 months | Often escalated to a security review | Add a current security questionnaire response |
| More than 6 months | Commonly treated as a lapse | Prioritise finishing the audit |
The fix is scheduling, not paperwork. Start the next SOC 2 audit around six months into the current report's validity and the periods overlap, so no gap exists. Teams that begin renewal only after the old report expires need a bridge letter every year.
A SOC 2 bridge letter is required when someone asks for proof of your SOC 2 status on a date outside the period your last report covered. In practice that means four situations: a prospect in procurement, an annual vendor review by an existing customer, a security questionnaire asking about current coverage, and a contract clause requiring continuous SOC 2 coverage. No standard requires you to issue one proactively. If nobody asks, you do not need one.
This SOC 2 bridge letter example covers the common case, where nothing material has changed. Replace the bracketed fields. If your controls did change, replace the no-changes sentence with a plain description of what changed and when.
Two mistakes to avoid. Do not cover a period that has not finished, because you cannot assert anything about the future. And do not stay silent about a material change such as a new cloud provider or a reportable incident. A bridge letter found to have omitted one does more damage than the gap it covered.
A SOC 2 bridge letter is a courtesy customers extend, not an entitlement, and it is refused in predictable cases. It will not work if you have never had a SOC 2 report, because there is nothing to bridge from. It will not work off a SOC 2 Type I report, because a Type I tests design at a point in time and says nothing about operation over a period, so there is no continuity to assert. Regulated buyers in financial services and healthcare often accept only tested reports. And if your last report carried qualified opinions or exceptions, a letter asserting nothing has changed is not the reassurance the customer wants.
When a SOC 2 bridge letter is refused, the options are to accelerate the audit, offer a shorter observation window for the next report, or supply other current evidence such as recent penetration test results and a completed security questionnaire.
No. ISO 27001 has no bridge letter, because the gap does not arise. An ISO 27001 certificate is issued for a three year cycle and stays valid throughout, subject to annual surveillance audits, so at any moment you either hold a valid certificate or you do not. A SOC 2 report instead describes a period that has already closed, so a new period must be tested and issued before anyone can rely on it. That is one of the practical differences covered in the CertAssist guide to SOC 2 versus ISO 27001.
A SOC 2 bridge letter costs nothing in fees. No auditor performs work, so no auditor invoices for it, and drafting takes an hour or two using the structure above. The real cost is the delay behind it: a compressed engagement, or deals stalled in procurement while the report is outstanding. The audit fee is the significant number in a SOC 2 programme, and CertAssist breaks it down in its guide to how much SOC 2 costs.
The platform you keep evidence in is the other line item. As of September 2026, CertAssist costs US$225 per month as a limited-time launch price, normally US$375 per month, or US$3,999 per year, which is twelve months for the price of eleven. All CertAssist prices are in USD. CertAssist lays out the SOC 2 Trust Services Criteria control by control with editable policy and evidence templates and read-only auditor access, which is what keeps the next observation window on schedule.
A SOC 2 bridge letter is the wrong answer when it is papering over a programme that has stopped running. The letter asserts that your controls continued to operate. If access reviews were skipped, offboarding was missed or change management lapsed, fix the controls before writing anything. Signing an assertion you cannot support is worse than admitting a delay, and the next audit tests that same period against the standard of proof set out in the CertAssist guide on what auditors really look for in your evidence.
CertAssist is also not right for everyone. CertAssist has no integrations by design, so it does not connect to your cloud, identity provider or code repository and will not collect evidence automatically. If continuous monitoring across a large estate saves more than it costs, a platform built around integrations fits better. No platform writes or signs your bridge letter, and none removes the need for an independent CPA firm to perform the examination.
The service organisation writes its own SOC 2 bridge letter, and an officer such as the CEO, CTO or CISO signs it. The CPA firm that issued your last SOC 2 report does not write, sign or review it. Auditors cannot assert that controls operated effectively during a period they did not examine, so the letter is a management assertion and carries no independent assurance.
A SOC 2 bridge letter is commonly accepted for up to three months. No standard sets that limit and the letter has no built-in expiry, but three months is the convention most customers and procurement teams apply. Gaps beyond three months are frequently escalated to a full security review, and gaps beyond six months are usually treated as a lapse in coverage rather than a scheduling overlap.
A SOC 2 bridge letter is required when a customer or prospect asks for proof of SOC 2 coverage on a date that falls after the period your last report covered. Typical triggers are a procurement review, an annual vendor reassessment, a security questionnaire asking about current coverage, or a contract clause requiring continuous SOC 2 coverage. If nobody asks, you do not need to issue one.
SOC 2 reports do not contain bridge letters. A bridge letter is a separate one page document you issue alongside your existing SOC 2 report, covering the period after that report ended. You send the two together: the report provides the tested evidence for the period it covers, and the bridge letter asserts continuity for the months since. Neither document replaces the other.
A SOC 1 bridge letter serves the same purpose for a SOC 1 report, which covers controls relevant to your customers' financial reporting rather than the SOC 2 Trust Services Criteria. The format, the three month convention, and the rule that your management rather than your auditor signs it are all identical. Organisations that hold both a SOC 1 and a SOC 2 report normally issue one letter covering each.
CertAssist lays out every SOC 2 control with editable policy and evidence templates and read-only auditor access, so the next observation window starts on time. CertAssist has no integrations and no system access, and costs US$225 a month as a launch price.
See pricing FrameworksFlat US$225 a month launch price (normally US$375), or US$3,999 a year (12 months for the price of 11). All prices in USD.