[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"glossary-bridge-letter::en":3,"gloss-cluster-bridge-letter::en":20,"gloss-next-bridge-letter::en":9},{"slug":4,"category":5,"name":6,"definition":7,"meta_desc":8,"faq":9,"schema_markup":9,"related":10},"bridge-letter","security","Bridge Letter","A bridge letter — also called a gap letter — is a short statement a vendor issues to cover the period between the end of its most recent SOC 2 audit window and the present date. A SOC 2 Type II report examines controls across a defined period, commonly twelve months, and it is published some weeks after that period closes. That leaves a permanent gap: by the time you read a report covering January to December, it is March, and nothing in the report speaks to January or February. The bridge letter fills it, typically asserting that no material changes to the control environment, no significant control failures and no relevant security incidents occurred in the interim. Buyers encounter this during vendor security review, and the practical point is that a bridge letter is management's own assertion, not an auditor's opinion. It is signed by the vendor, not attested by the audit firm, so it carries the weight of a representation rather than evidence. That is normal and generally accepted; it is not a substitute for a current report. What matters is whether the gap is reasonable. A vendor whose last audit period ended two months ago and who provides a bridge letter is operating normally. A vendor bridging a gap of nine or twelve months has effectively stopped being continuously audited, and the letter is covering absence rather than a lag. Ask three questions: when does the next audit period end and when will the report be available, does the letter name the specific report it bridges and the exact dates, and were there any changes to subprocessors, hosting regions or scope during the gap — that last one is where the material change usually hides.","A bridge letter covers the gap between the end of a vendor's SOC 2 audit period and today, asserting nothing material has changed since.",null,[11,14,17],{"slug":12,"name":13},"security-questionnaire","Security Questionnaire",{"slug":15,"name":16},"soc-2","SOC 2",{"slug":18,"name":19},"trust-center","Trust Center",[21,25,29,33,36,39,42,45,48,51,54,57],{"slug":22,"category":5,"name":23,"updated_at":24},"audit-log","Audit Log (Audit Trail)","2026-08-24T02:46:37+00:00",{"slug":26,"category":5,"name":27,"updated_at":28},"blast-radius","Blast Radius","2026-08-24T03:30:02+00:00",{"slug":30,"category":5,"name":31,"updated_at":32},"break-glass-access","Break-Glass Access","2026-08-24T02:46:38+00:00",{"slug":34,"category":5,"name":35,"updated_at":32},"business-associate-agreement","Business Associate Agreement (BAA)",{"slug":37,"category":5,"name":38,"updated_at":24},"byok","Bring Your Own Key (BYOK)",{"slug":40,"category":5,"name":41,"updated_at":32},"cve","CVE (Common Vulnerabilities and Exposures)",{"slug":43,"category":5,"name":44,"updated_at":28},"data-classification","Data Classification",{"slug":46,"category":5,"name":47,"updated_at":32},"data-loss-prevention","Data Loss Prevention (DLP)",{"slug":49,"category":5,"name":50,"updated_at":32},"data-minimization","Data Minimization",{"slug":52,"category":5,"name":53,"updated_at":32},"data-poisoning","Data Poisoning",{"slug":55,"category":5,"name":56,"updated_at":32},"data-processing-agreement","Data Processing Agreement (DPA)",{"slug":58,"category":5,"name":59,"updated_at":24},"data-retention","Data Retention Policy"]