The global average cost of a data breach reached $4.45 million in 2023, according to IBM. With risks this high, organizations must prove that their security and compliance controls are not only effective during an audit, but consistently maintained over time.
However, a SOC 2 Type II report only reflects a defined audit period, not continuous validation. This creates a natural gap between the end of one SOC 2 reporting cycle and the start of the next, leaving stakeholders without an up-to-date report to reference.
To address this, organizations often issue a SOC 2 bridge letter — a document that maintains assurance between reporting cycles. This guide explains what a bridge letter is, why it matters, and how to use it to support continuous SOC 2 compliance.
A SOC 2 bridge letter — sometimes called a gap letter — is a document issued by a service organization to explain what has occurred since the end of its last SOC 2 reporting period. It bridges the gap between your most recent completed SOC 2 report and the current date, providing stakeholders with visibility into the status of internal controls while a new audit is in progress or pending.
Unlike a formal SOC 2 audit report, a bridge letter is prepared internally and is not the product of an independent examination. Its purpose is transparency: it tells stakeholders whether the control environment documented in the last report remains intact, and whether any significant changes have taken place since then.
A SOC 2 report reflects a defined period — typically 12 months — and cannot account for changes that occur after the audit window closes. A bridge letter fills that gap by confirming whether internal controls and system and organization controls remain consistent with what was documented in the previous report.
This is especially valuable when a customer or partner requests current compliance documentation before your next SOC 2 report is finalized.
Yes — a bridge letter and a gap letter refer to the same document. The term "gap letter" emphasizes the time gap it covers, while "bridge letter" emphasizes its role in connecting two reporting periods. Both terms are used interchangeably in the compliance industry.
Maintaining SOC 2 compliance is a continuous responsibility, not an annual checkbox. Because a SOC 2 report only covers a specific audit period, organizations must address the window between the last verified report and current operations.
A bridge letter extends assurance beyond the last SOC 2 report by documenting the current status of internal controls and alignment with security and compliance standards. For stakeholders relying on your SOC 2 documentation — customers, partners, or prospective clients — this added visibility is often critical to moving business forward.
A bridge letter confirms that controls from the last SOC 2 report continue to operate as expected. It typically references the results of the most recent audit and explains whether those controls still meet the relevant trust services criteria.
By doing so, it demonstrates continued operating effectiveness even outside the formal audit window — a key signal of a mature compliance program. Organizations that want to go further in demonstrating ongoing risk discipline may also benefit from reviewing their broader risk assessment and compliance posture.
A strong bridge letter covers the key details stakeholders need to evaluate what has changed since the previous SOC 2 report.
Common elements include:
A bridge letter is not a replacement for a full SOC 2 audit, but it plays a key role in maintaining transparency between reports.
A bridge letter is prepared internally by the service organization — not by an external auditor. Unlike a formal SOC 2 audit report, it is not part of a regulated examination process.
That said, it should still align closely with the language and scope of the last SOC 2 report. To ensure credibility, the document should be reviewed internally, aligned with prior SOC 2 report language, and formally approved. The letter should be signed by an authorized party within the organization — typically a CISO, Compliance Officer, or equivalent.
Many organizations benefit from starting with a structured template. A well-designed template ensures your bridge letter consistently covers the required elements: the reporting period, any material changes, and the current status of your internal control environment.
We've created a professional SOC 2 Type II bridge letter template to help organizations streamline their documentation and provide stakeholders with clear, actionable assurance between SOC 2 reporting periods.
Bridge letters work best when they are issued proactively — before stakeholders ask — and when they are kept concise and factual. Avoid vague reassurances; instead, reference specific controls, scopes, and timeframes. Align the language with your existing SOC 2 report to reinforce consistency.
Issue a bridge letter when there is a meaningful gap between the end of your last SOC 2 audit and the availability of your next report. This is especially important when a stakeholder or customer requests current compliance documentation before the new report is finalized.
Common scenarios include:
To support a credible bridge letter, organizations should continuously document changes to their internal controls throughout the year — not just at audit time. This includes tracking updates to the control environment, monitoring configurations, and ensuring alignment with trust services expectations. Strong internal documentation practices also make it easier to prepare for the next audit cycle with minimal rework.
A well-prepared bridge letter supports SOC 2 attestation, complements existing SOC report documentation, and keeps stakeholders informed. It also plays a useful role in setting expectations ahead of the next SOC 2 audit cycle.
For stakeholders, a bridge letter provides visibility into the gap between SOC 2 reporting cycles. It reassures them that the internal control environment remains stable even after the last report period ends — a particularly important signal for customers evaluating vendors during renewals or new contracts.
A strong bridge letter addresses the trust services criteria most relevant to your SOC 2 scope — commonly security, availability, and confidentiality. It helps demonstrate that operating effectiveness continues across the defined reporting period, even outside the formal audit window.
While useful, a bridge letter is not always sufficient. If there are major material changes to systems, infrastructure, or internal controls — or if evolving risks have emerged since the last audit — stakeholders may require a new SOC 2 Type II report for full assurance. A bridge letter is best used when changes are minimal and core controls remain stable. If your organization is navigating broader risk scenarios that fall outside a standard SOC 2 scope, a structured risk analysis framework like FAIR can help quantify and communicate those gaps more precisely.
A SOC 2 bridge letter is a practical solution for maintaining assurance between reporting cycles. While it does not replace a formal SOC 2 audit, it helps organizations communicate the current state of their internal control environment to stakeholders during the gap between reports. As expectations around security and compliance continue to grow, organizations that proactively issue bridge letters will be better positioned to maintain trust, support stakeholders, and prepare confidently for their next audit cycle.
A SOC 2 bridge letter is a document that explains what has changed since the end of your last SOC 2 audit period. It helps organizations provide updated assurance to stakeholders while waiting for a new SOC 2 report, ensuring continued transparency around internal controls.
SOC 2 reports only cover a defined timeframe. A bridge letter fills the gap between audit periods by confirming whether controls remain effective — reassuring stakeholders that compliance is still being maintained between official reports.
A SOC 2 bridge letter should include the date, a reference to the last report, and a summary of any material changes. It should also confirm whether internal controls and systems remain consistent with the prior audit period.
A SOC 2 bridge letter is prepared internally by the service organization, not by an external auditor. It should align with the previous SOC 2 report and be reviewed and signed by an authorized individual — typically a CISO or Compliance Officer.
A company should issue a bridge letter when there is a gap between the end of its last SOC 2 audit and the availability of a new report — especially when stakeholders request up-to-date assurance during that window.
No. A SOC 2 bridge letter is not part of a formal audit and does not replace a full SOC 2 Type II report. It acts as a temporary update between official reporting periods to maintain stakeholder confidence.
A bridge letter may not be sufficient if there are significant changes to systems or internal controls. In those cases, stakeholders may require a new SOC 2 Type II report for full assurance. It works best when changes are minimal and core controls remain stable.