Receiving your first SOC 2 report is not the finish line — it is the start of a cycle. A Type 2 report covers a defined observation period, and the day after that period ends customers begin asking: “what about your controls now?”. That is what bridge letters, annual report renewals and continuous compliance are for. Here is how to run the cycle so it does not turn into an annual fire drill.
Why a SOC 2 report “ages”
A SOC 2 Type 2 report describes how controls operated during the observation period — say, 1 January to 31 December. After that, the report remains valid as a historical document but says nothing about the current state. Market practice treats a report as current for roughly 12 months after the period ends. A Type 1 report describes a single date, so its useful life is even shorter.
There is always a gap between the end of the period and the issue of the next report: the auditor needs 4–8 weeks for fieldwork and drafting. Add review time and you have 2–3 months without a current report. The bridge letter covers that gap.
What a bridge letter (gap letter) is
A bridge letter is a letter the service organisation — your company, not the auditor — issues to its customers. In it, management confirms that from the end date of the last observation period to the date of the letter:
- the controls described in the SOC 2 report continue to operate;
- there have been no material changes to the control environment (or lists the changes if there were);
- no incidents occurred that would affect the report’s conclusions (or describes them).
Three points matter. First, a bridge letter is a management assertion, not an auditor’s opinion; the CPA firm neither issues nor signs it. Second, it does not replace the report — it only bridges two reports. Third, it normally covers no more than three months; a longer gap prompts customers to ask why the next audit is late.
What a bridge letter typically contains
- Reference to the latest report: type, observation period, CPA firm, opinion date.
- The period the letter covers (period end date to letter date).
- A statement that there were no material changes to controls, systems, key personnel or subservice organisations.
- A statement on incidents (or their absence).
- The planned date of the next report.
- Signature of an authorised officer — usually the security lead or CFO.
We provide a bridge letter template as part of ongoing support and help phrase changes honestly when they occurred: concealing changes damages trust far more than the changes themselves.
How to plan observation periods
To minimise gaps, observation periods should run back-to-back: the first report covers, say, 1 July – 31 December (six months), the second 1 January – 31 December of the following year, and annually thereafter. Each new report then appears around February–March, with a bridge letter covering January–February.
| Scenario | Observation period | Gap without a report | Solution |
|---|---|---|---|
| First Type 2 | 3–6 months | Audit plus drafting time | Type 1 first, bridge letter after |
| Annual renewal | 12 consecutive months | 2–3 months | Bridge letter for the gap |
| Pause between periods | Gap over 3 months | A real hole in coverage | Avoid; customers may demand a new Type 1 |
Continuous compliance: what to do between audits
The most expensive mistake is to forget about SOC 2 after the report and remember it a month before the next audit. Type 2 controls must operate and leave evidence throughout the period; they cannot be reconstructed retroactively. This is the minimum rhythm we recommend:
Monthly
- review logs and alerts, close incidents;
- verify security patches are applied;
- confirm backups complete and are restorable.
Quarterly
- access reviews with documented results;
- vulnerability scans and remediation tracking;
- review of new vendors and subprocessors;
- risk register review.
Annually
- policy review, approval and staff acknowledgement;
- security awareness training;
- business continuity and disaster recovery test;
- penetration test;
- risk assessment and scope review.
Compliance automation platforms help by pulling evidence from cloud services automatically and reminding owners about manual tasks. But accountability for every control must sit with a named person, not with a tool.
When to change the report scope
Businesses change: new products, hosting regions, data categories, customers with new requirements. Before each new observation period, review:
- whether to add TSC categories (for example Availability or Confidentiality);
- whether in-scope systems and subservice organisations have changed;
- whether to combine the next cycle with ISO 27001 or address GDPR — see SOC 2 and GDPR together.
Scope changes are best made at period boundaries, not mid-period; otherwise the auditor has to describe two different system states in one report.
What to do about exceptions in the report
Exceptions in a Type 2 report are not a disaster — most reports have some. What matters is documenting a remediation plan, executing it and showing in the next period that the issue is closed. Customers react far more calmly to “one exception with a documented fix” than to a vendor with no Type 2 at all.
The consultant’s role after the first report
Once the report is issued, BALTUM offers ongoing compliance support: periodic control checks, bridge letter preparation, policy updates, evidence preparation for the next audit and communication with the CPA firm. It is cheaper than repeating readiness from scratch every year and lets the team focus on the product. The underlying preparation steps are in our SOC 2 readiness checklist, and the Ukrainian market context in SOC 2 for Ukrainian IT companies.
Already have a SOC 2 report and want the next cycle to run without a scramble? Or a customer is asking for a bridge letter and you are not sure where to start? Request a quote — we will assess the current state of your controls and propose a support plan through to the next audit.