Blog

SOC 2 Bridge Letter: What It Is and When You Need One

Your SOC 2 Type 2 report covers the year to 31 December. It is now March, a major customer is running their annual vendor review, and they have asked what assurance you can give them for January and February. Your next report will not be ready for months.

That is the gap a bridge letter fills. It is a short, signed statement from your management confirming that nothing material has changed since your report period ended. It is one of the most useful documents an Australian SaaS or services business can have ready, and one of the most misunderstood.

What a SOC 2 bridge letter is

A bridge letter, sometimes called a gap letter, bridges the period between the end date of your most recent SOC 2 report and today, or the customer’s financial year end. It is written and signed by your own management, usually an executive or the person accountable for security.

The important point, and the one that surprises people, is that your auditor does not write it and does not test it. Your audit firm has performed no procedures over the gap period, so the letter carries your assertion, not their opinion.

Timeline showing where a SOC 2 bridge letter sits between the end of the audit period, the report being issued, and the gap before the next report
Where the bridge letter sits for a report covering a calendar year. The gap is the window customers ask about.

Why the gap exists at all

A SOC 2 Type 2 report covers a defined period, commonly three to twelve months, and it takes time after that period closes for fieldwork and reporting to finish. So there is always a stretch of time between your report end date and the day a customer is reading it. The longer you leave between audit periods, the wider that stretch gets.

What it is not

A bridge letter is not a substitute for a SOC 2 report, not a form of certification, and not something you can use in place of an audit period you skipped. If a customer is asking for assurance covering a whole year and your last report ended fourteen months ago, a bridge letter will not save the conversation.

Comparison table of a SOC 2 Type 2 report and a bridge letter across who writes it, whether it is tested, what it covers, its length and how long it holds
The two documents do different jobs. Know which one your customer is actually asking for.

When you need one

Three situations account for almost all requests.

  • A customer’s financial year end falls after your report period ends, and their auditors want coverage up to their year end.
  • A procurement or vendor risk review lands a few months after your report was issued, and the reviewer wants confirmation that nothing has changed.
  • You are closing a deal and the buyer’s security team notices your report is several months old.

A fourth, less common case is a customer who has just signed and wants coverage from your report end date to their onboarding date. Same letter, same rules.

You do not need to publish a bridge letter proactively. Prepare a template, then issue it on request with the dates filled in. Most Australian companies we work with issue a handful each quarter, almost always alongside the report itself under an NDA.

How long a bridge letter can cover

The widely accepted practice is up to three months. Beyond that, you are asking a customer to accept an unaudited assertion over a long stretch of time, and most vendor risk teams will push back.

If your gap is regularly wider than three months, the problem is your audit cadence, not your letter. Moving to consecutive twelve month periods, or shifting your period end to sit closer to when your customers do their reviews, solves it properly.

What goes in the letter

Keep it to one page. A workable structure looks like this.

  • Identify the report: the service organisation, the report type, the Trust Services Criteria covered and the exact period.
  • State the gap period the letter covers, with specific dates.
  • Confirm that the controls described in the report have continued to operate, and that there have been no material changes to them.
  • Disclose anything that has changed, such as a new hosting region, a significant subservice organisation change, or a security incident that affected the services in scope.
  • Remind the reader that complementary user entity controls still apply to them.
  • State plainly that the letter is management’s assertion, that it has not been audited, and that it does not replace the SOC 2 report.
  • Sign and date it, with the name and role of the person signing.

Do not sign it on autopilot

The value of the letter rests entirely on it being true. Before signing, check with your engineering and IT leads whether anything material has changed: a new cloud provider, a change of subservice organisation, a shift in how access is managed, a security incident, or the loss of the person who ran a key control.

If something has changed, say so in the letter. A disclosed change reads as maturity. A change a customer discovers later, after you signed a letter saying there were none, is a very different conversation.

A worked example

Say your Type 2 report covers 1 January to 31 December 2025 and is issued in late February 2026. A customer with a 31 March financial year end asks for assurance through to that date.

You issue a bridge letter in early April that identifies the report and its period, states that it covers 1 January to 31 March 2026, confirms the controls have continued to operate with no material changes, and notes the one change worth mentioning, which was moving your logging platform to a new provider in February. It is signed by your CTO and sent with the report.

That is a three month gap, disclosed honestly, backed by a current report. Almost every vendor risk team in Australia will accept it. If the same customer came back in September asking for coverage through to 31 August, the answer is not a longer letter. It is your next audit period.

What Australian customers ask for instead

Not every buyer asking about your gap period wants a bridge letter. Some are satisfied by a short summary of your continuous monitoring, evidence that your vulnerability scanning is running, or a recent penetration test report showing you are still testing your environment.

It is worth asking what the reviewer is actually trying to establish. Often it is simply that you are still operating the controls you described, and there are cheaper ways to demonstrate that than a formal document exchange.

Bridge letters and ISO 27001

ISO 27001 does not have an equivalent, because a certificate carries a validity period of its own and is checked at surveillance audits. If you hold both, buyers usually accept the certificate for the gap and the SOC 2 report for the detail. That is one of several practical differences worth understanding when you are weighing up SOC 2 against ISO 27001.

Common questions

Who signs a SOC 2 bridge letter?

Someone with the authority to speak for the organisation about its control environment. In a small Australian company that is usually the CEO, CTO or the person accountable for security. If you use a virtual CISO, they can help you prepare it, and the signature should still come from your business.

Can our auditor issue the bridge letter for us?

No. They have not tested the gap period, so there is nothing for them to give an opinion on. Some audit firms will provide a template, which is helpful, but the assertion and the signature are yours.

Is a bridge letter enough to close an enterprise deal?

On its own, rarely. Alongside a current SOC 2 report it usually is. If you do not have a report yet, a bridge letter is not the answer and the honest path is to explain where you are in your SOC 2 audit process and what date you expect a report.

How often should we expect requests?

It depends on your customer base. Companies selling to Australian financial services, health and enterprise buyers tend to see them cluster around 30 June and 31 December, when customer financial years end. Prepare the template once and issuing each one is a short job.

Does a bridge letter cover a security incident?

Only by disclosing it. If you had a material incident during the gap period, the letter should say what happened and what you did about it. Staying silent and signing a no material changes statement is the one genuinely dangerous way to use this document.

Keeping your SOC 2 evidence current

A bridge letter is a small piece of a bigger habit: being ready to answer a security question in a day rather than a fortnight. Have your report, your letter template, your penetration test attestation and your policy set in one place, and the whole vendor review process stops eating your week.

Siege Cyber helps Australian companies get SOC 2 ready and stay ready between report periods. Have a look at our SOC 2 services, or get in touch if you want a hand preparing the evidence pack your buyers keep asking for.