Bridge (gap) letters
A bridge (gap) letter is a formal document provided by a service organization to its clients that covers the period between the end date of the most recent SOC 1 report and the current date. It asserts that there have been no material changes in the control environment during this interval, providing continuous assurance to the client's auditors.
What it means
SOC 1 Type II reports cover a specific historical window (e.g., January 1 to December 31). Because audit reports are retrospective and take time to produce, there is often a "gap" between when the report period ends and the current date or the client's fiscal year-end.
The intent of a bridge letter is to mitigate the risk that controls failed or were significantly altered during this gap. It does not replace the SOC 1 report; rather, it supplements it by confirming that the control objectives described in the most recent report remain relevant and operational.
From a compliance perspective, if you are the service provider, you are providing a representation of your current state. If you are the client, you are collecting this to satisfy your own auditor's requirement for "complementary" evidence regarding third-party risks.
How to meet it
- Maintain an active SOC 1 cycle: Ensure your audit periods are timed so that gaps remain small and manageable (typically less than six months).
- Perform a gap period review: Before signing a bridge letter, conduct an internal check of change management logs and incident reports to verify no material changes occurred.
- Develop a standard template: Create a formal letter on company letterhead that explicitly references the specific SOC 1 report (by date range) it is bridging.
- Define "Material Change": Establish internal criteria for what constitutes a material change in controls so the signer knows exactly what they are attesting to.
- Assign an authorized signatory: Ensure the letter is signed by an officer with oversight of the control environment, such as a CISO, CFO, or Compliance Lead.
- Establish a distribution workflow: Create a process for delivering both the latest SOC 1 report and the accompanying bridge letter to clients upon request or on a set schedule.
Evidence an auditor asks for
- The signed Bridge Letter: A PDF copy of the dated and signed letter provided to customers.
- The referenced SOC 1 Type II Report: The full audit report that the bridge letter is extending.
- Internal Validation Records: Documentation (such as a sign-off email or checklist) proving the organization verified there were no material changes before issuing the letter.
Common pitfalls
- Overstating stability: Signing a bridge letter stating "no material changes" when significant infrastructure migrations or policy overhauls occurred during the gap.
- Incorrect date ranges: Failing to align the start date of the bridge letter exactly with the end date of the SOC 1 report period, leaving an uncovered window.
- Treating it as a substitute: Assuming a bridge letter can replace a missing or expired SOC 1 report; auditors will not accept a bridge letter if there is no underlying Type II report to bridge from.