A SOC 2 Type II report covers a fixed observation period — say, January 1 through December 31. Your next report won’t exist until the next period ends and the auditor finishes fieldwork. That leaves a standing gap: in March, a customer’s procurement team asks for “current” SOC 2 coverage, and your newest report is already three months stale. The bridge letter is the standard artifact that spans that gap.
Two things it is not. First, it is not an auditor deliverable — your audit firm does not write or certify bridge letters, because attesting to a period they haven’t examined would undermine the attestation model. Second, it is not a new audit opinion. It is a management representation: your company, on its own letterhead, stating that the control environment described in the last report has continued to operate without material change.
That makes it lightweight by design — typically a single page — and it is accepted practice across procurement and security-review teams. Buyers know reports have periods; the letter shows you know it too and that someone is actually watching the controls in between.
Three moments, predictably. A renewal or new deal lands in the months after your report period closed, and the buyer’s security review flags the gap. A vendor-risk platform automatically requests “report plus bridge letter” as a package. Or your own sales team pre-empts the question by shipping both artifacts together in the data room — the pattern we recommend, since it removes a round-trip from every security review.
The cadence follows your audit calendar: most companies issue a letter each quarter after the period ends until the next report is delivered, dating each one freshly rather than stretching a single letter across the whole year.
[Company Letterhead]
Date: July 26, 2026
Re: SOC 2 Type II Bridge Letter — [Company, Inc.]
To our customers and prospective customers:
[Company, Inc.] engaged [Audit Firm LLP] to perform a SOC 2 Type II examination of the [Company] platform for the period [May 1, 2025] through [April 30, 2026]. The resulting report, dated [June 10, 2026], was issued with an unqualified opinion.
This letter covers the period from [May 1, 2026] through the date of this letter. During this period, to the best of management’s knowledge: (1) the system described in the report has continued to operate as described; (2) the control environment, monitoring activities, and control objectives described in the report have remained materially unchanged; and (3) no changes have occurred that would materially affect the conclusions expressed in the auditor’s report.
Management remains responsible for maintaining effective controls, and continuous monitoring of the control environment has remained in place throughout the period. Our next SOC 2 Type II examination, covering the period ending [April 30, 2027], is scheduled for completion by [June 2027].
This letter is provided for informational purposes to supplement — not replace — our most recent SOC 2 Type II report and does not constitute an opinion by our independent auditor.
Sincerely,
[Name]
[Chief Information Security Officer], [Company, Inc.]
[security@company.com]
Six elements, one page. Anything more is decoration.
Management signs — whoever genuinely owns the control environment, usually the CISO or CTO, with the CEO as a fallback at smaller companies. Auditors don’t sign, and a buyer who insists the audit firm certify the gap is asking for something that doesn’t exist in the SOC 2 model; pointing them to this distinction usually resolves it.
On duration, the working convention: a bridge letter comfortably covers up to about three months of gap, and buyers get skeptical past six. If your letter would need to cover most of a year, the real problem is your audit cadence — schedule the next Type II period so reports land back-to-back, and the bridge letter shrinks to a formality.
For companies whose programs Agency operates, bridge letters are drafted, reviewed, and issued as part of the service — backed by the continuous monitoring that makes the “no material changes” sentence true rather than hopeful. The letter is the visible artifact; the substance is a control environment that’s actually watched between audits. That’s the difference between SOC 2 run end to end and SOC 2 as an annual scramble.
Working toward your first report instead? Start with the SOC 2 framework overview or the free SOC 2 readiness checklist.
No — bridge letters are management representations issued by your company on its own letterhead. Audit firms neither write nor certify them, because they haven’t examined the gap period. If a buyer insists on an auditor-signed letter, they’re describing an artifact that doesn’t exist in the SOC 2 model.
Never. It supplements a valid report by covering the months since its period ended. A bridge letter with no underlying report behind it carries no weight — the letter’s credibility is borrowed entirely from the audited period it bridges from.
Issue a freshly dated letter whenever a buyer asks, and proactively each quarter between report periods. Reissuing takes minutes if your controls are genuinely monitored; the discipline that actually matters is keeping the next audit on schedule so gaps stay short.
Disclose it. A bridge letter that lists a material change — a new subprocessor, an architecture migration — plus the compensating steps taken reads as mature governance. A letter that hides a change a buyer later discovers costs you the deal and your credibility.
It’s a formal management representation your customers may rely on, so treat it with contract-grade care: accurate dates, honest change disclosure, and sign-off from someone with real knowledge of the environment. That’s also why the signer should be the executive closest to the controls.