Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.
All security →SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.
All frameworks →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →Also called a gap letter. It covers the interval between the end of your report period and today, it is signed by management, and no auditor has examined a word of it.
A SOC 2 bridge letter, also called a gap letter, is a short letter from a service organization's management covering the period between the end date of its most recent SOC 2 report and a later date, usually today or a customer's fiscal year end. It asserts that the system and controls have not materially changed and that management is not aware of control failures or incidents that would change the report's conclusions. It is written by the service organization, not the auditor, and no CPA examines it. It carries no opinion and provides no assurance. Convention keeps the covered gap to about three months; beyond that it stops being credible and the answer is a report covering the period, not a longer letter. A bridge letter closes a scheduling gap. It does not close an assurance gap.
A SOC 2 Type II report covers a defined observation period, commonly three to twelve months. The moment that period ends, the report begins ageing. If your report covers 1 January to 31 December and a customer asks for evidence in March, the report is current, valid and says nothing whatsoever about January, February or March.
A bridge letter fills that space with an assertion rather than with evidence. It is typically one page on company letterhead, addressed to customers and their auditors, stating that management has considered the period since the report ended and is not aware of anything that would change the conclusions in it.
The names are interchangeable. Bridge letter is the most common term, gap letter is the same thing, and some firms call it a continuity letter or a letter of no material change. None of the names is a term of art defined in the standards; the document is a practical convention that grew up because report periods and customer fiscal years do not align.
It is worth being precise about what kind of document this is. It is a management representation. It is closer in nature to a signed statement in a security questionnaire than to anything in the report itself. Understanding that shapes both how much weight to put on one you receive and how carefully to write one you issue.
Nearly always, the request is driven by the customer's own calendar rather than by any doubt about you. Three situations produce most requests.
The customer's financial audit. Their auditors are testing internal control at a period end that falls after your report period ended, and they need something covering the interval before they will rely on your report. This request typically arrives from finance or internal audit rather than from security, and it comes with a hard deadline.
The customer's own vendor risk program. Their policy requires current assurance from critical vendors, their review lands three months after your period ended, and the reviewer needs something to close the item. This is usually the easiest request to satisfy because the reviewer wants a defensible file note.
A deal in progress. Procurement or a buyer's security team is reviewing you now, your report period ended a few months ago, and they want confirmation nothing has changed since. Here the bridge letter is unblocking revenue, which is why the request tends to arrive with urgency attached.
In all three cases the underlying need is the same: someone has to write down that the gap was considered. A prompt, well-drafted bridge letter satisfies that need. Slow or defensive handling of the request creates a much bigger problem than the gap itself, because it reads as evasion.
A bridge letter can state facts about the report: which report it refers to, the period it covered, the type, the auditor who issued it, and the opinion given. This anchors the letter and is why the report identifier should always appear in the first paragraph.
It can state that the system described in the report has not materially changed during the gap period. Where something has changed, it can and should describe the change. A letter that discloses a migration to a new cloud region, or the retirement of a service, is more credible than a blanket statement of no change, and the disclosure costs nothing.
It can state that the controls described in the report continue to be in place and operating. This is a statement about the organization's own knowledge, not a tested conclusion, and the wording should make that plain.
It can state that management is not aware of any control failures, deficiencies, security incidents or breaches during the gap that would materially affect the conclusions in the report. The phrase "is not aware of" is doing real work here and should not be upgraded to something stronger, because nobody can assert the absence of an unknown event.
It can state what happens next: that the next examination is underway or scheduled, the period it will cover, and roughly when the report will be available. Customers value this more than anything else in the letter, because it tells them when the item can actually be closed.
It can state who to contact for questions. A named person with an email address turns a one-way document into something a reviewer can follow up on, and reviewers notice.
It cannot extend the auditor's opinion. The opinion applies to the period examined and nothing else. No wording in a management letter can stretch it, and any letter suggesting that the report now covers a longer period is misrepresenting an accountant's work.
It cannot provide assurance. No testing was performed over the gap, no samples were taken, no exceptions were reported, and no independent party looked at anything. The letter is an assertion, and the reader has only the organization's word for it.
It cannot be signed by the auditor. Service auditors do not sign bridge letters, and a letter appearing on an audit firm's letterhead should be read very carefully because it is not what it appears to be. Auditors will sometimes review a client's draft for wording that misrepresents their opinion, but that is not the same as issuing or endorsing it.
It cannot cover the future. A letter dated today can address the period up to today. A statement that controls will continue to operate through the coming months is a prediction, and including one undermines everything else in the letter.
It cannot substitute for a report. This is the point that matters most in practice. A bridge letter closes a scheduling gap of a few weeks or months for a customer who has already read your report. It cannot be the assurance itself, and an organization offering bridge letters instead of a current report is describing a compliance program that has lapsed.
It also cannot cover controls that were not in the report. If a customer asks about something outside the report's scope, answer that question separately and honestly rather than folding it into the bridge letter, where it will look like part of an audited conclusion.
A bridge letter is signed by an officer of the service organization with the standing to speak for management on internal control. In practice that is the person who signed management's assertion in the report, or an equivalent: the CEO, the CFO, the CTO, or the CISO. At smaller companies it is often the CEO or CTO.
It should not be signed by whoever is handling the customer request. A bridge letter signed by an account executive or a compliance analyst carries no weight, and sophisticated reviewers will ask for it to be reissued.
Signing means something. The signer is asserting knowledge of the gap period, so the signature should follow an actual check rather than precede one. Before signing, someone should confirm with engineering and security that no material architecture change occurred, review the incident record for the gap period, check the control monitoring or compliance tooling for failures, and confirm that no key control owner departures left a control unowned.
That check takes under an hour when the underlying records exist, and it is the difference between a representation and a formality. Where the check surfaces something, disclose it. A letter that says a specific change occurred, describes it, and states why it does not affect the controls in the report is a stronger document than a blanket denial, and it is far safer for the signer.
Keep a copy of every letter issued, to whom, on what date, and covering what period. If the same customer later receives a report with an exception in a period a bridge letter covered, you want to be able to see exactly what was said and when.
The period runs from the day after your report period ended to the date of the letter, or to a specific date the customer has asked about, typically their fiscal year end. State both endpoints explicitly. A letter that says "since our last report" without dates is unusable in a reviewer's file.
There is no rule in the standards setting a maximum gap. The working convention across the industry is around three months, and it exists for a simple reason: the credibility of a no-material-change assertion falls off quickly as time passes. A month of unexamined operation is a rounding error. Nine months is most of a year, and in a growing software company nine months of unexamined operation is a different system.
Between three and six months, expect friction. Some customers accept it, many ask what is happening with the next report, and financial auditors relying on your report for their own testing frequently will not accept it at all.
Beyond six months, a bridge letter is not a serious answer and issuing one invites the question it is trying to avoid. At that point the honest position is that there is no current assurance for the period and the next report is the remedy.
The structural fix for chronic gaps is to align the report period with what customers need. If most of your enterprise customers have a December year end, a report period ending 30 September or 31 December, with the report issued within four to eight weeks, means the gap is short for most of them most of the time. Moving a window is disruptive once and permanent afterwards, and it is usually worth it.
One page, company letterhead, six short paragraphs. Longer letters are not stronger; they are just harder for a reviewer to extract facts from.
Open by identifying the report precisely: the type, the auditor, the exact period covered, the trust services categories in scope, and the opinion. A reviewer who has the report in front of them can confirm every one of these in seconds, and a mismatch is the fastest way to lose credibility.
State the gap period with explicit start and end dates. Then make the no-material-change statement about the system, disclosing any change that did occur. Then make the controls statement, worded as management's knowledge rather than as a tested conclusion. Then make the incidents and deficiencies statement, using "is not aware of" and covering the gap period specifically.
Include an explicit limitation paragraph saying that the letter is a statement by management, that it has not been examined by an independent service auditor, that it provides no assurance, and that the auditor's opinion applies only to the period covered by the report. This paragraph protects you and it also tells an inexperienced reviewer how to weigh the document, which is a service to them.
Close with the next examination: the period it will cover, its current status, and the expected availability of the report. Then the signature block with name, title, date, and a contact address for questions.
Keep a maintained template and refresh it whenever a report is issued so that the identifying details are already correct. Most of the delay in responding to bridge letter requests comes from rebuilding the letter each time rather than from the substantive check.
Bridge letter requests arrive unpredictably and always with a deadline. Three habits make them a ten-minute task.
Maintain the template with current report details, and update it the day each report is issued. Keep it wherever your customer-facing security documents live, alongside the report itself.
Run the underlying check on a schedule rather than per request. If you already hold a monthly or quarterly record of material changes, incidents and control monitoring results, then signing a letter is a matter of reading the record rather than starting an investigation. This record is useful for several other purposes, including management review if you also run ISO 27001.
Decide in advance who signs and who drafts, and make sure the signer knows they are on the hook. A signer who is surprised by the request each time becomes the bottleneck.
Publish proactively where you can. Organizations with a trust centre often post a current bridge letter alongside the report so that customers under NDA can self-serve. That removes most requests entirely, and it reads as confidence rather than as something extracted under pressure.
Answer quickly. A bridge letter delivered the same week costs nothing and closes a customer's open item. One that takes three weeks of chasing creates the impression there is something to find, which is expensive in a live deal and hard to undo.
Sometimes the gap is long for a real reason: the audit slipped, a remediation took longer than planned, the auditor changed, or the first Type II was delayed. A longer letter is not the answer. There are four better ones and they can be combined.
Be direct about the timeline. A short note saying the report period ended on a given date, the next examination covers a stated period, fieldwork completes in a stated month and the report is expected by a stated date is worth more to a customer than a vague assurance. Reviewers can plan around a date.
Offer evidence in place of assertion. Where you have continuous control monitoring, a compliance platform dashboard, a recent penetration test report, or your own internal audit results, share what you can under NDA. None of it is a SOC 2 report, but it is observable rather than asserted, and it is what a serious reviewer would rather have.
Consider a shorter examination period. A Type II covering three or six months and issued quickly can close a long gap faster than waiting for the next twelve-month cycle. It costs an additional examination, so it is a commercial decision, but where a large deal is blocked the arithmetic often works. Discuss it with your auditor before promising anything, because their scheduling drives the date.
Where the gap arose because the program lapsed rather than slipped, say so and say what changed. Customers who have run compliance programs know that they slip. What damages trust is discovering the lapse themselves after receiving a letter implying continuity.
Finally, do not let the gap recur. Chronic gaps are a symptom of a program that restarts each year rather than running continuously, and the fix is operational: evidence collected through the period rather than at the end, control owners with recurring tasks, and the next window opened before the current report is issued. That is also the cheapest way to run the second and subsequent audits, which is consistent with what we say about year two SOC 2 cost.
If a vendor sends you one, spend five minutes on it rather than filing it. Four checks catch almost everything.
Check the report details in the letter against the report you hold: type, auditor, period, categories in scope, opinion. Mismatches are usually template errors, but they occasionally reveal that the letter refers to a different report than the one you were given.
Check the gap length. Under three months, this is routine. Three to six, ask when the next report is due and record the answer. Over six, treat the assurance as expired and escalate through your own vendor risk process rather than accepting the letter as closure.
Check the wording for overreach. Any suggestion that the auditor's opinion extends over the gap, or that the letter provides assurance, is a reason to look harder at the whole relationship. Conversely, a letter that discloses a specific change and explains it is a good sign, not a bad one.
Check who signed it. An officer of the company is what you want. A sales contact is not, and asking for reissue is entirely normal.
Then record what you did. Your own auditor will test how you monitor critical vendors, and a file note saying that the report was reviewed, the gap was identified, a bridge letter was obtained and read, and the next report is expected on a stated date is exactly the evidence they are looking for. The same applies in reverse when you are relying on a provider you have carved out of your own report, which is covered in the guide to subservice organizations.
No dates. "Since our most recent report" is not a period. Both endpoints, explicitly.
Wording that implies assurance. "This letter confirms our controls operated effectively through 31 March" asserts a tested conclusion that nobody tested. "Management is not aware of any control failures during the period" says what can honestly be said.
Signed by the wrong person. A letter from someone with no authority to represent management is not usable in a reviewer's file.
Blanket no-change statements that are untrue. If you migrated a database platform, opened a new region or changed a major subprocessor during the gap, the letter must say so. Silence about a change a customer later discovers is far more damaging than the change was.
Missing the limitation paragraph, which leaves the letter looking like it claims more than it does.
Covering a gap of many months as though it were routine, which draws attention to exactly the thing the letter was meant to settle.
Issuing one when the last report was qualified or contained significant exceptions without addressing them. A bridge letter should not be used to move a reader's attention away from the report; where exceptions were remediated during the gap, say what was done.
Signing without checking. The letter is a representation by an officer. Spending the hour to confirm it is true is not optional.
| Paragraph | What it should say | What to watch for |
|---|---|---|
| Report identification | Type, issuing audit firm, exact period covered, trust services categories in scope, and the opinion given. | Details that do not match the report the reader holds. Usually a stale template, occasionally something worse. |
| Gap period | Explicit start and end dates, running from the day after the report period ended to the letter date or a stated date. | No dates at all, or an end date in the future. A letter cannot cover time that has not happened. |
| System change statement | That the system described in the report has not materially changed, with any change that did occur described plainly. | A blanket denial from a company that visibly shipped major infrastructure change in the period. |
| Controls statement | That the controls described in the report continue to be in place and operating, worded as management's knowledge. | Wording that reads as a tested conclusion. Nothing here was tested. |
| Incidents and deficiencies | That management is not aware of control failures, deficiencies, security incidents or breaches during the gap that would affect the report's conclusions. | An absolute denial rather than a knowledge-qualified one. Nobody can assert the absence of an unknown event. |
| Limitation | That the letter is a management statement, has not been examined by an independent service auditor, provides no assurance, and does not extend the opinion. | Its absence. A letter without this paragraph reads as claiming more than it can. |
| Next examination | The period the next report will cover, its current status, and when the report is expected. | Vagueness. This is the paragraph reviewers care about most because it tells them when the item closes. |
| Signature block | Name, title, date, and a contact address, signed by an officer with standing to speak for management on internal control. | Signed by a sales or support contact. Ask for reissue; it is a normal request. |
A short letter from a service organization's management covering the period between the end of its most recent SOC 2 report and a later date, usually today or a customer's fiscal year end. It states that the system and controls have not materially changed and that management is not aware of failures or incidents that would affect the report's conclusions. It is also called a gap letter.
No. It is written and signed by the service organization's management, and no CPA examines it. There is no testing, no opinion and no assurance. Service auditors do not sign bridge letters, although they will sometimes review a client's draft to check it does not misrepresent their opinion.
No maximum is set in the standards, but the working convention is about three months. Between three and six months you should expect pushback, particularly from customers whose own financial auditors are relying on your report. Beyond six months a bridge letter is not a serious answer and the remedy is a report covering the period rather than a longer letter.
An officer of the service organization with standing to represent management on internal control, usually the person who signed management's assertion in the report: the CEO, CFO, CTO or CISO. A letter signed by an account manager or a compliance analyst carries no weight and reviewers are right to ask for it to be reissued.
No. It closes a scheduling gap for a customer who already has your report; it cannot be the assurance itself. Nothing in it was tested by anyone. An organization offering bridge letters in place of a current report is describing a compliance program that has lapsed, and customers reading carefully will treat it that way.
Be direct about the timeline and give the customer real dates for the next report. Offer observable evidence in place of assertion where you have it: continuous control monitoring output, a recent penetration test, or internal audit results, shared under NDA. Consider commissioning a shorter three or six month examination to close the gap faster. And fix the underlying cause, which is usually a program that restarts each year instead of running continuously.
Yes, if they are material to the system described in the report. A migration, a new region, a significant architecture change or a change of subprocessor should be described, with a sentence on why it does not affect the controls in the report. A letter that discloses and explains is stronger than a blanket denial, and it protects the officer signing it.
That the report details in the letter match the report you hold, that both gap dates are stated and the gap is short, that the wording does not claim assurance or extend the auditor's opinion, and that an officer signed it. Then write a file note recording what you reviewed and when the next report is due, because your own auditor will test how you monitor critical vendors.
traztech Workspace has all 61 criteria of SOC 2 written in plain English, with what the standard asks for, what to do about it, and somewhere to attach the proof. You answer them, it scores you, and nothing is locked behind an upgrade.
No credit card, no trial clock, no locked features. We make money when someone wants help closing the gaps, not from the Workspace.
| traztech Workspace | Other GRC platforms | |
|---|---|---|
| Licence cost | $0. Free forever, no card, no paid tier | $7,500 to $50,000 a year, on an annual contract |
| Control library, evidence register, policy templates, risk register, vendor questionnaires, readiness scoring | Included | Included |
| What it costs inside an engagement with us | $0. You need a workspace either way | Unchanged. The subscription sits on top of the fee |
| What it does to your audit quote | $11,000 off a five-figure quote on one engagement, for a documented readiness position | Nothing. The audit firm prices your readiness, not your tooling |
Pricing in the right column is what compliance automation platforms are publicly reported to charge; none of them publish a number, so treat it as a range rather than a quote. The $11,000 came off the audit firm's own number once the readiness position was documented (the engagement). Where a paid platform is the better buy, and the fuller comparison, is on the Workspace page.
We keep evidence flowing through the observation window, align the report period with the customers who ask for it, and draft the bridge letters so a request takes ten minutes instead of three weeks.
Book a strategy callWant the human version?
Jacob sends a few short, practical notes on getting security and compliance right without the months of pain. No fluff, unsubscribe in one click. Reply anytime; it reaches him directly.
From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.
Track record
Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.
At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.