Your customer's security team just asked for a SOC 2 bridge letter, and your last audit report is a few months old. This is normal. It happens to almost every SaaS company between Type II reports, and it has a straightforward answer that does not require rushing your next audit or panicking about a compliance gap.
What a SOC 2 Bridge Letter Actually Is
A SOC 2 bridge letter (sometimes called a SOC 2 gap letter, same document, different name depending on which firm you ask) is a short attestation from your audit firm. It typically runs one to two pages. Its job is narrow. It confirms that nothing material has changed in your control environment between the end of your last observation period and the date the letter is signed.
Say your Type II report covers January through June. It is now October, and your buyer wants current assurance before your next report, which will not cover the second half of the year until it closes in December. The bridge letter fills that four month window. It is not a new audit, and it does not test anything new. It is a statement from the firm that already tested your controls, saying the picture has not changed since they looked.
SOC 2 Bridge Letter vs SOC 2 Gap Letter
These are the same document. "Bridge letter" is the more common term among auditors and platforms. "SOC 2 gap letter" shows up more often in buyer-side security questionnaires, because it names the problem (there is a gap between report periods) rather than the fix. If a prospect's security team asks for a gap letter, send them a bridge letter. Nobody is asking for two different things.
Bridge Letter vs Engagement in Good Standing Letter
These two get confused constantly, and the difference actually matters. An engagement in good standing letter is used before you have a finished report at all. If you are three months into your first Type II observation period and a buyer needs something today, your audit firm can confirm that you are currently under an active engagement, in good standing, with no issues that would prevent a report from being issued at the end of the period. It says, in effect, that the firm is actively watching this company and nothing is wrong so far.
A bridge letter does a different job. It covers the period after a report has already been issued, confirming nothing changed since. The good standing letter covers the time before your first report exists. The bridge letter covers the time after a report exists but before the next one does.
what SOC 2 compliance involves end to end covers where these fit into the overall audit timeline if you want the full picture of Type I, Type II, and renewal.
Who Issues a Bridge Letter and What It Can Say
Only the independent CPA firm that performed your SOC 2 examination can issue the bridge letter, under the same attestation standards (AICPA's SSAE 18 framework) that governed the original audit. A compliance platform or advisory firm cannot write one. They were not the ones who tested your controls and formed the opinion.
What it can say is limited on purpose. It confirms no material changes occurred. It does not test anything new, does not extend your existing report's opinion to the gap period, and does not carry the same weight as an actual Type II report covering that time. Some buyers accept a bridge letter as a stopgap and move on. Others treat it as a formality and will still want the next full report once it is available. Know which one you are dealing with before you promise a timeline.
If you work with a bundled provider like CyberSprint, the request still routes to the independent audit firm that holds the engagement. CyberSprint coordinates the ask and keeps it moving, but the firm that signs the letter is the same firm that signed your report, not CyberSprint itself. how CyberSprint coordinates your SOC 2 audit walks through that division of labor in more depth.
When a Buyer Will Ask You for One
A handful of situations trigger this request more than any others:
- An aging report during an enterprise sales cycle. Security review teams commonly flag a report older than six months, and a bridge letter is the standard way to answer without stalling the deal.
- A cyber insurance renewal where the underwriter wants current confirmation of your control posture, not last year's snapshot.
- A vendor risk re-assessment triggered by an existing customer's annual review cycle, which often lands right in the gap between your reports.
- A due diligence process ahead of a funding round or acquisition, where the diligence team wants the most recent possible signal.
None of these mean something is wrong. A calendar did not line up with a sales cycle, which happens to every company running annual or semiannual audits.
How to Request a SOC 2 Bridge Letter
The process is quick if your audit firm relationship is active. It generally looks like this:
- Confirm the gap period. Identify the exact end date of your last report and the date your buyer needs coverage through.
- Contact your audit firm directly (or your compliance partner, who will route the request to them) and specify the dates the letter needs to cover.
- Confirm there have been no material control changes since the last observation period ended. If something significant did change, say so. The firm needs to know before it puts its name on the letter.
- Receive the signed letter, usually within a few business days for an established client relationship.
- Send it to your buyer alongside your most recent SOC 2 report, not as a replacement for it.
Most firms treat this as routine client service rather than a billable engagement, though a few charge a small flat fee. Ask before you assume it is free.
What a Bridge Letter Cannot Do
It cannot substitute for your next Type II report indefinitely. Buyers who need audited assurance over a specific period, not just a confirmation that nothing changed, will eventually need the real report. It also cannot cover a gap where your controls actually did change materially. If you switched cloud providers, changed your access review process, or had a control failure, the firm will not attest that nothing changed. Have that conversation honestly rather than asking for a letter that glosses over it.
how to read a SOC 2 report is worth a look if you want to understand exactly what the real report says once it lands, versus what a bridge letter is standing in for in the meantime.
Is a bridge letter the same as a SOC 2 report?
No. A bridge letter is a short confirmation that nothing material changed since your last report. It carries far less detail than the report itself and is meant to be paired with your most recent SOC 2 report, not sent alone.
How long does a SOC 2 bridge letter typically cover?
Usually the gap between the end of your last observation period and whenever the next one starts or the letter is requested, commonly one to six months. It should never be asked to stretch across a full missed audit cycle.
Can CyberSprint issue my bridge letter?
No, and no compliance partner legitimately can. Only the independent CPA firm that performed your audit can sign it, the same independence rule that governs the audit itself.
What if my Type II observation period has not finished yet?
Then you likely want an engagement in good standing letter instead, not a bridge letter. That confirms you are under an active, on-track engagement rather than covering a gap after a report already exists.
Do I need to request a bridge letter every time a report ages?
Only when a buyer specifically asks for one or your sales or renewal timeline needs current assurance. Plenty of reports age past six months without anyone requesting a bridge letter at all.
A bridge letter is a small piece of paper that solves a scheduling problem, nothing more dramatic than that. The bigger question worth sitting with is whether your audit cadence keeps landing you in this gap year after year, or whether it is time to talk through a schedule that fits your actual sales cycle. start a conversation with CyberSprint if you want to walk through that with someone who has coordinated this exact request before.
Tired of chasing bridge letters?
We help small cloud-native SaaS companies turn compliance into something enterprise buyers actually trust. Let's talk about where you are and what's next.
Start a conversation