
A SOC 2 bridge letter is a statement from management that’s used when a customer asks for assurance after your last SOC 2 report period has ended, but before the next report is ready. It can help cover that gap in between, but it does not extend the SOC 2 report, replace the next report, or provide independent auditor testing for the bridge period.
Use one only if management can make an accurate, supportable statement about the relevant period and the customer is okay with accepting management assurance for that request.
What is a SOC 2 bridge letter?
A SOC 2 bridge letter is a management attestation intended to cover the period between the end date of a SOC report and a customer’s relevant assurance date, as described in Google Cloud’s SOC 2 compliance materials. In practice, it is used when a customer wants more current assurance than the last available SOC 2 report provides.
The key distinction is between:
- Report period: the period covered by the completed SOC 2 report.
- Bridge period: the later interim period covered by management’s bridge letter.
For SOC 2 context, a Type I report addresses control design at a point in time, while a Type II report addresses design and operating effectiveness over a period, according to Google Cloud. Most bridge-letter requests relate to the gap after a Type II report period ends, the next Type II report is not ready yet.
A bridge letter usually states whether management is aware of material changes or issues in the internal-control environment after the prior SOC report period ended. Google Cloud notes that a bridge letter may summarize material changes or issues identified after the prior report’s period end.
What a bridge letter can and cannot do
A bridge letter is useful because it gives the customer a current management statement. Its limits matter just as much.
| A bridge letter can | A bridge letter cannot |
|---|---|
| Reference the prior SOC 2 report and its covered period. | Replace a SOC 2 Type II report. |
| Define a specific bridge period. | Extend the prior SOC 2 report’s assurance period. |
| State that management is not aware of material changes, if true. | Provide independent auditor testing of the bridge period. |
| Disclose relevant material changes, if they occurred. | Guarantee the customer will accept the response. |
| Explain the expected timing of the next SOC 2 report. | Prove continued operating effectiveness by itself. |
Microsoft describes its bridge letters as self-attestations issued during a period not yet ready for audit examination, not reports based on an auditor’s examination (Microsoft SOC materials). Grant Thornton similarly describes bridge letters as management-signed statements that reference the prior report and provide interim information, but are not audit deliverables and do not include independent testing or an auditor’s opinion (Grant Thornton).
That means the wording should be careful: management can say what it knows, what it reviewed, and whether it is aware of material changes. It should not imply—really, it should avoid implying—that the auditor validated controls after the prior report period.
When should you use a SOC 2 bridge letter?
A bridge letter is most appropriate when all of the following are true:
- The customer is asking for current assurance.
- Your prior SOC 2 report period has ended.
- The next SOC 2 report is not yet available.
- The requested gap is short and date-specific.
- Management can support the statement it is making.
- The customer will consider a management-issued bridge letter acceptable for the request.
Be cautious, or consider another response, when:
- the bridge period is long;
- the next audit or report is significantly delayed;
- material control changes occurred;
- significant incidents, exceptions, or unresolved control issues may affect the statement;
- the customer requires auditor-attested evidence;
- management cannot confidently support a no-material-change assertion.
A bridge letter should not be used to paper over uncertainty. If the accurate answer is “material changes occurred,” the letter should disclose them carefully rather than use a no-change template.
Who writes and signs a SOC 2 bridge letter?
A SOC 2 bridge letter is generally prepared and signed by service-organization management, not presented as an auditor’s report or attestation. Grant Thornton describes bridge letters as management-signed statements that complement, rather than substitute for, formal assurance (Grant Thornton).
The signer should be someone with authority to make the assertion, such as an executive, security leader, compliance owner, or operations leader with responsibility for the relevant controls. The right signer depends on your governance model and customer risk.
Before signature, internal review may involve:
- security or engineering control owners;
- GRC or compliance;
- legal, especially for customer-specific reliance language;
- customer success or account leadership;
- executive leadership for high-risk or strategic customers.
The main point: accountability. The signer is not forwarding the auditor’s conclusion for a new period; they are making a management statement about the bridge period.
What should a SOC 2 bridge letter include?
Keep the letter specific, factual, and limited to the request. A practical SOC 2 bridge letter usually includes:
- your company name;
- the requesting customer or intended recipient;
- reference to the prior SOC 2 report;
- the prior report period;
- the exact bridge period dates;
- a no-material-change statement, if accurate;
- or a careful description of material changes, if applicable;
- a statement that the letter is a management assertion;
- the expected timing or status of the next SOC 2 report, if appropriate;
- contact information;
- authorized signature and date.
Avoid vague timing such as “to present” unless the date is clear. Use exact dates so the customer can see which period is covered.
How long should a SOC 2 bridge letter cover?
Treat a bridge letter as a short-gap measure, not a long-term substitute for a current SOC 2 report.
Three months is often discussed as a practical benchmark, but it should not be presented as a universal SOC 2 rule. Professional guidance notes no formal three-month rule, while longer periods may reduce reliability or acceptance for external-auditor or recipient use (Grant Thornton; Forvis Mazars Quarterly Perspectives Q3 2024).
For a longer bridge period, confirm:
- whether the customer will accept a management bridge letter;
- why the next SOC 2 report is not yet available;
- whether material changes occurred;
- whether another assurance artifact is more appropriate;
- whether the audit timeline can be accelerated.
If the bridge period keeps expanding, the risk is no longer just wording. It may indicate a reporting cadence, audit-readiness, or customer-assurance issue that needs operational attention.
SOC 2 bridge letter templates: no-change and material-change examples
The following examples are basically starting points only. Review them with compliance, security, and legal stakeholders before sending, especially if the customer has contractual language or specific reliance requirements.
No-material-change example
Use this version only if management can support the no-material-change statement. If changes occurred, use a disclosure version instead.
Material-change disclosure example
Do not use material-change wording to minimize a change that the customer reasonably needs to understand. The safer approach is accurate, non-sensitive disclosure tied to what management actually reviewed.
What if the customer wants more than a bridge letter?
Customer acceptance is not guaranteed. If the customer rejects the bridge letter or asks for more, respond based on the reason.
| Scenario | Practical response |
|---|---|
| Customer says the bridge period is too long. | Provide the next SOC 2 report timeline, explain the current audit status, and ask what interim evidence they will accept. Escalate if the request affects contract closure or renewal. |
| Customer requires auditor-attested evidence. | Clarify that the bridge letter is management-issued. Discuss internally whether another formal assurance option is available or whether the audit timeline can be adjusted. Do not imply auditor validation unless confirmed. |
| Material changes make a no-change statement inaccurate. | Send a revised management statement with appropriate disclosure, or decline to issue a no-change letter. |
| Customer asks for repeated updated letters. | Treat this as a signal that the audit cadence or customer-assurance process may need adjustment. Repeated manual letters increase review burden and wording risk. |
| Next SOC 2 report is delayed. | Be transparent about expected timing if approved for disclosure. Escalate to security, compliance, legal, and commercial leadership before making commitments. |
The goal is not to persuade every customer with the same document. It is to provide the most accurate form of assurance your organization can support for the specific request.
Internal checklist before sending a SOC 2 bridge letter
Use this checklist before management signs. It is not an audit procedure and does not create auditor-level assurance; it is a practical control for issuing a supportable management statement.
- Prior SOC 2 report identified.
- Prior report period confirmed.
- Bridge period start and end dates confirmed.
- Customer request and required dates reviewed.
- Customer acceptance risk considered.
- Next SOC 2 audit or report timeline confirmed.
- Relevant control owners consulted.
- Material changes reviewed.
- Significant incidents, exceptions, or unresolved control issues considered.
- Internal evidence reviewed and retained.
- No-change or material-change wording selected accurately.
- Sensitive details reviewed before disclosure.
- Signatory confirmed.
- Compliance, security, legal, and commercial review completed as appropriate.
- Final letter dated and version-controlled.
Bridge letters are easier to support when evidence, control ownership, audit timelines, and material changes are tracked continuously rather than reconstructed during a customer escalation. From a Ciphrix operational perspective, recurring bridge-letter requests are a reason to strengthen reusable controls and continuous evidence practices, not to rely on one-off document preparation if it can be avoided.
Conclusion
Issue a SOC 2 bridge letter only when it is accurate, date-specific, and supportable by management review. If the gap is long, material changes occurred, or the customer requires more than management assurance, escalate before sending. If these requests are recurring, move the process from ad hoc drafting to clearer audit readiness, evidence ownership, and compliance operations.
