A bridge letter, also known as a gap letter, notes any relevant changes in your organization's control environment, provides your clients with additional information about your organization, and asserts confidence in your organization's compliance program.
Bridge letters are typically issued when there's a gap between the end date on your organization's SOC 2 Type 2 report and the end of your organization's calendar year.
Note that a bridge letter is not a replacement for a SOC 2 report; it's wise to send the bridge letter in conjunction with your organization's most recently-issued SOC 2 report.
Commonly associated evidence:
Bridge Letter
Third Party SOC 2 Report
Vendor Contract
Vendor Due Diligence
Vendor List
Vendor Management Policy and Procedures
Who needs a policy like this?
All businesses following the SOC 2 compliance framework
How to use the template:
Click on the link above to access the template
If you are a Google Workplace organization, make a copy by going to File > Make a copy
If you are not a Google Workplace organization, download a copy by going to File > Download and selecting your preferred file type (available as DOCX, PDF, and more)
Review and then remove instructional text
Save in a centralized place
Attach to evidence either through Integrations, Automated Collection, or direct upload
If you need help using the template, please let us know.
