Compliance

Phase 1, Phase 2, then keep it running

A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.

All compliance →
Security

Testing, review and leadership

Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.

All security →
Who we help

Prove you are secure

To the people you sell to, raise from or answer to.

All industries →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Security & Compliance Glossary

SOC 2 Bridge Letter

A SOC 2 bridge letter, sometimes called a gap letter, is a short statement from a service organization's management that covers the gap between the end of a SOC 2 report's observation period and a later date. It affirms that no material changes to the control environment have occurred in the interim. It is written and signed by the service organization, not the auditor, and it is not itself an attestation.

In practice

The letter is routine, but the obligation it states is real: you are asserting that the controls in the last report still operate and nothing material has changed. If something did change, the honest move is to say so rather than paper over it.

It is a stopgap, not a substitute for keeping your observation windows continuous. Companies that let a long gap open up end up leaning on bridge letters that buyers increasingly discount.

// how traztech helps

traztech delivers SOC 2 readiness and audit coordination for startups and growth-stage companies, led by a published security researcher.

Book a call

For a broader look at getting audit-ready, see our SOC 2 readiness work, or talk to a fractional CISO about building a program around it.

Where it comes up

A bridge letter is requested when a customer's own audit or procurement cycle falls after your last SOC 2 report's period ended but before the next one is issued. They want assurance that nothing material changed in the gap. Keeping those windows continuous is part of SOC 2 readiness and audit prep.

The limit worth understanding is that a bridge letter carries no independent assurance; it is management's word, so most parties accept it only for a short gap, commonly up to three months. Beyond that they will wait for the next report rather than extend the letter.

SOC 2 Bridge Letter: common questions

Who writes the bridge letter?

Your management, not the CPA firm. The auditor attests to the period they examined; they do not vouch for the gap, which is precisely why the letter comes from you.

How long can a bridge letter cover?

Usually up to about three months. It is meant to span a short gap between reports, not to extend the life of an ageing one, and most recipients treat a longer gap as needing a fresh report.

Free PDFs, no card

Get the checklists that go with this

SOC 2 readiness, ISO 27001 gaps, incident response and vendor security, as PDFs you can print or forward. Free, no card.

From Jacob Masse, principal of traztech: the files by email, then a few short notes over the next month. No spam, unsubscribe in one click.

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
Zero
Exceptions on a SOC 2 Type II built from nothing in-house

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation with zero exceptions.

Everyone on our list also gets The Compliance Brief, one email every Tuesday on what changed in security and compliance that week. Read the latest issue.