Summary
- Redundant power and transport do not establish continuity if every critical system ultimately trusts the same time authority, reception environment or distribution path.
- Buyers should contract for a service-specific time-error budget, independent references, measured holdover, authenticated distribution, continuous comparison and a rehearsed restoration decision.
The outage that does not look like one
Imagine a critical network at 02:17. The generators are carrying the building. Both carrier routes are up. Servers answer health checks. The primary timing receiver, however, has stopped being trustworthy. It may have lost satellite reception, accepted interference, inherited a bad upstream clock or entered holdover without exposing the real error to the service owner.
Nothing needs to go dark immediately. A mobile network can move outside its phase budget. A power-system measurement can become misleading. A certificate check, token lifetime or distributed lock can behave differently from the operator's expectation. Logs from two sites can describe the same incident in incompatible order. The failure is not simply “the clock is wrong”. The organisation has lost a shared basis for coordination and evidence.
That is why time should be treated as infrastructure rather than a free attribute of servers. The UK government's current PNT overview says positioning, navigation and timing underpin telecommunications, computers, emergency services, finance and other critical functions. The 2025 National Risk Register includes loss of PNT services. These are system-level warnings, not proof that a particular operator is fragile.
Four properties that procurement often collapses
A resilient timing service has at least four separate properties.
Accuracy asks how close the delivered time is to the required reference. Availability asks whether the service is present. Integrity asks whether the receiver can detect that a plausible signal is wrong. Independence asks whether nominally separate sources share a satellite constellation, antenna environment, fibre route, power domain, software stack or operating authority.
Authentication addresses only part of that problem. NIST's authenticated NTP service provides cryptographic assurance about the source of replies. That is valuable, but a genuine reply can still arrive late, traverse a failed common path or offer less precision than a radio, grid or financial application requires. Conversely, a high-quality oscillator can hold stable time locally while lacking an independent way to establish whether it has drifted.
The buyer therefore needs an architecture, not a brand name. NIST's PNT programme asks operators to identify dependent assets, detect disruption or manipulation and manage the resulting risk. Its Technical Note 2187 describes GPS-independent ways to distribute UTC to critical infrastructure and uses plus or minus one microsecond as the reference assumption. That number is not universal. It demonstrates why a requirement must be expressed as an error bound tied to the service.
Holdover is expiring inventory
When an external reference disappears, a local clock enters holdover. It does not preserve perfect time; it spends a finite inventory of oscillator stability. Temperature, ageing, vibration, maintenance and prior calibration affect how quickly the error grows. “We have an atomic clock” is no more complete than “we have a generator”. The useful questions are the certified starting condition, the load-specific error limit, the worst environmental case, the monitoring threshold and the time until intervention.
The ITU's 2024 account of the revised G.8272.1 and new G.8272.2 concepts illustrates the point. Under the standard's conditions, an enhanced primary reference time clock can remain better than 100 nanoseconds from UTC for up to 40 days after GNSS loss. The coherent network reference clock goes further: distributed clocks cooperate and are continuously compared. This is not a 40-day guarantee for any installation. It is evidence that resilience comes from specified performance, comparison and architecture rather than from a second receiver on the same roof.
Public investment changes the supply surface
The United Kingdom is building more options. A November 2025 announcement committed £155 million to PNT resilience. NPL's National Timing Centre and its Resilient Enhanced Time Scale Infrastructure are intended to strengthen terrestrial, traceable and geographically distributed timing capability.
Those programmes matter because they can reduce dependence on one satellite-derived channel. They do not remove the buyer's local obligations. A national time source still reaches an application through receivers, fibre, switches, clocks, software, credentials, contracts and staff. The end-to-end service can retain common failure even when the upstream laboratory is exemplary.
The contract should describe the clock's failure shape
The acceptance test should begin with consequences. Which function fails at 100 nanoseconds, one microsecond, one millisecond or one second? How quickly does each clock class approach that limit after losing its reference? Which independent measurement proves the answer? What alarm reaches the service owner before the budget is exhausted?
The operating record should identify every reference, physical path, trust authority and holdover device; show comparison residuals rather than a green “synchronised” light; preserve the uncertainty interval in logs; and name the person who may isolate a suspect source. Re-entry also needs a rule. A clock that suddenly sees a new source cannot always jump without harming the applications it serves. Slewing, quarantining, reconciling event records and restoring legal traceability are part of recovery.
The central distinction is simple. Redundancy counts components. Resilience proves that the system can recognise bad time, remain inside a service limit and regain trustworthy order without one hidden owner deciding the result by default.
Primary sources
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance