Skip to main content

SOC 2 Report Bridge Letter

Gain guidance regarding Bridge Letters and view a corresponding template

Micah Spieler avatar
Written by Micah Spieler
Updated over a year ago

A bridge letter, also known as a gap letter, notes any relevant changes in your organization's control environment, provides your clients with additional information about your organization, and asserts confidence in your organization's compliance program.

Bridge letters are typically issued when there's a gap between the end date on your organization's SOC 2 Type 2 report and the end of your organization's calendar year.

Note that a bridge letter is not a replacement for a SOC 2 report; it's wise to send the bridge letter in conjunction with your organization's most recently-issued SOC 2 report.

Commonly associated evidence:

  • Bridge Letter

  • Third Party SOC 2 Report

  • Vendor Contract

  • Vendor Due Diligence

  • Vendor List

  • Vendor Management Policy and Procedures

Who needs a policy like this?

  • All businesses following the SOC 2 compliance framework

How to use the template:

  • Click on the link above to access the template

    • If you are a Google Workplace organization, make a copy by going to File > Make a copy

    • If you are not a Google Workplace organization, download a copy by going to File > Download and selecting your preferred file type (available as DOCX, PDF, and more)

  • Review and then remove instructional text

  • Save in a centralized place

  • Attach to evidence either through Integrations, Automated Collection, or direct upload

If you need help using the template, please let us know.

Did this answer your question?