A bridge letter is your company speaking in its own voice: a statement on company letterhead that the control environment from the last SOC 2 report has carried on without material change. Only management can truthfully say that — the audit firm’s opinion stops at the end of the examined period, and no reputable firm will vouch for months it never tested. Procurement teams occasionally request an “auditor-signed” gap letter; the honest reply is that no audit firm issues such a document, which typically settles it.
Pick the executive who genuinely supervises the controls, because the letter is a representation buyers may rely on. At most companies that’s the CISO; where the role doesn’t exist, the CTO or the CEO. What disqualifies a signer isn’t seniority but distance — a board member or outside counsel signing suggests nobody close to the environment would. Include a contact line so a reviewer can follow up with a person, not a mailbox.
The rest of the artifact — required elements, coverage-period conventions, and a complete example you can adapt — is on the SOC 2 bridge letter page, with the quick definition at bridge letter in the glossary.
Better not. The letter’s force comes from management accountability, and reviewers read the signature block as a statement of who stands behind the claims. Have the compliance team draft it — that’s normal — and route the signature to the executive who owns the control environment.
No. Convention is a single signature from an accountable executive on company letterhead, dated, with contact details. Notaries and multiple signers add ceremony, not credibility; accurate dates, honest change disclosure, and a signer who could answer questions about the environment do the persuading.