SOC 2 Bridge Letter: What to Check Before You Sign
A SOC 2 bridge letter is a management statement about the gap after a report period. Check changes, incidents, control work, dates, and buyer needs before signing.

A SOC 2 bridge letter is management’s statement about the gap after an existing report period. It can give a customer current facts about changes and control operation through a named date, but it does not extend the CPA firm’s opinion. Before signing, check the exact report scope and end date, review what happened since then, and ask the customer what it will accept. If you do not have a SOC 2 report yet, a bridge letter cannot stand in for one.
When does a SOC 2 bridge letter help?
A Type 2 report addresses control operation over a specified period. The AICPA’s SOC 2 reporting guide describes the CPA examination of a service organization’s system and controls. When a customer reviews a report after its period ends, it may ask what has changed since the last covered day.
Forvis Mazars describes bridge letters as letters from service-organization management to report users for that gap. The service auditor does not issue the letter. The recipient still decides how much weight to give the management statement alongside the report.
Use the dates, not a claim that the report has simply “expired.” A report has an actual period, an issue date, a named system, and selected criteria. A buyer may accept that report with a short gap statement, ask for a newer report, or need other information. There is no one period length that every buyer accepts.
| Situation | What to tell the buyer |
|---|---|
| You have no SOC 2 report | State your actual status and ask what interim review the buyer accepts. There is no report period to bridge. |
| You have a Type 2 report with a later gap | Provide the report under its sharing terms, then offer a management letter for the exact gap if the buyer accepts it. |
| The report covers a different service | Explain the scope difference. A letter cannot add that service to the CPA examination. |
| A material system or control change occurred | Describe the change and its date; ask what further evidence or report the buyer needs. |
The first customer-request guide helps when the real question is whether to pursue an initial report. The observation period guide helps plan the next formal Type 2 period with the CPA firm.
Check the gap before drafting the letter
Start with the day after the report period ends and stop at a stated review date. Do not use the report’s issue date as the period end. Name the exact service, entity, and criteria that the report covers, then inspect dated records for the intervening time.
Ask the owners of the scoped controls to check:
- System and scope changes. Did the product, hosting, integrations, data flow, people, or material providers change? Record effective dates and which controls the change affected.
- Control operation. Did access reviews, change reviews, backup tests, training, vendor reviews, and other scheduled or event-driven work occur as required by the company’s actual policies? Note missed or late work.
- Incidents and exceptions. Review security incidents, outages, control failures, open risks, and remediation. Decide which facts are material to the statement and the recipient’s use of the report.
- Next examination. Record the next CPA engagement or candidate plan accurately. Do not call management’s target dates a CPA-agreed period until the engagement sets them.
- Evidence trail. Link each conclusion to source records and name who reviewed them. A signed sentence without a review path is hard to defend when a buyer asks what changed.
The records may support a limited statement, a statement that names changes, or a decision not to issue a letter. Do not force the evidence into “no material changes” wording if the company migrated its production system, replaced a key provider, or found a control failure. Management should review the effect and describe what it can support.
What belongs in the letter?
Keep the letter short enough for a report user to understand without guessing which report or period it refers to. A useful outline is:
- The company, the intended recipient, and the date of the letter.
- The prior SOC 2 report’s scoped system, type, covered period, and issue date.
- The exact gap dates covered by management’s review.
- A factual statement about material changes and known events, including relevant exceptions or a clear reference to an attachment.
- The basis for the statement, such as management inquiries and review of current operating records, without implying CPA testing of the gap.
- An authorized management signer’s name and role.
Avoid a blanket promise that all controls operated effectively through the gap unless management has reviewed enough evidence to support that claim. Even then, the letter remains management’s statement. It does not update the CPA firm’s testing, expand the original report, or guarantee the next opinion. Ask the buyer to confirm whether the combined report and letter answer its review. If the gap is long or the service changed, a newer report may be the only answer it accepts.
Keep the review and delivery traceable
Store the approved letter where authorized recipients can receive it, along with the exact report version and the change review behind it. Keep restricted reports, secrets, and personal data out of a broadly accessible Git repository. Use an approved secure channel for delivery and record which version went to which recipient.
FileGRC can keep the management review connected to its scope, controls, dated work, evidence references, and approved long-form letter. It is a Git-native GRC workspace for SOC 2 work: JSON holds structured records, Markdown holds long-form work, and Git supplies the change history. Starter records are proposals, not compliance claims. Source systems still operate the controls and produce evidence. The independent CPA firm performs the examination and decides whether evidence is sufficient.
Run your SOC 2 program as files in Git.
Keep policies, controls, work, and evidence indexes in a repository your team and agents can inspect. Add optional hosted email and Slack reminders to keep work moving.
Frequently asked questions
What is a SOC 2 bridge letter?
A SOC 2 bridge letter, also called a gap letter, is a statement from the service organization's management about the time after its report period ended. It can tell a report user what management knows about material changes and relevant events through a stated later date. It is not a new SOC 2 report or a CPA opinion on that later period.
Who signs a SOC 2 bridge letter?
An authorized person in the service organization's management signs a management bridge letter. The CPA firm that issued the SOC 2 report does not extend its examination opinion by that signature. Confirm the wording and signer through your company's approval process and with the recipient when needed.
Can a bridge letter replace a SOC 2 report?
No. A bridge letter refers to an existing report and provides a management statement for a later gap. It cannot create an initial report, add a service that was outside the original scope, or turn unexamined months into CPA-examined coverage. Ask the recipient whether it will accept the letter with the report.
How long can a SOC 2 bridge letter cover?
There is no universal acceptance period. The report user decides whether the report and management's gap statement are recent and useful enough for its purpose. A longer or eventful gap needs more scrutiny and may lead the recipient to ask for a newer SOC 2 report.
What if controls changed after the SOC 2 report period?
Review and describe material changes, incidents, control failures, and relevant remediation truthfully. Do not sign an unqualified no-change statement when the records show otherwise. Discuss the wording with the report recipient and your CPA firm or counsel as appropriate.