Choosing reliable time: redundancy, holdover and traceability
Why choose a premium time server? This guide explains the building blocks of a reliable, traceable time chain: dual time source, failover, holdover and UTC traceability.
Three things make time reliable:
- Dual source and failover: two independent time sources, so one failure does not take time down.
- Holdover: if GPS drops out, the server keeps running accurately on its own oscillator.
- Traceability: you can prove your time is correct, back to the world standard UTC. That is what an audit requires.
1. Redundancy: one failure must not take time down
A critical time chain duplicates its weak links:
- Two time sources: for example two independent GNSS antennas, or GNSS combined with an IRIG or PTP reference. If one drops out, the other takes over.
- Redundant power: two power supplies, so a failed supply does not stop the server.
- Automatic failover: the switchover happens without intervention and without a time jump.
2. Holdover: keep running when the source fails
Even with redundant sources, GNSS can temporarily drop out (interference, jamming, an antenna problem). The internal oscillator bridges that period. An OCXO keeps time within tolerance for days; a Rubidium for months. Holdover is your insurance against a source you do not control.
In depth: Holdover: TCXO, OCXO and Rubidium.
3. Traceability: proving your time is correct
For an audit, 'the clock was right' is not enough. You must be able to trace the time to UTC through a known structure (stratum levels), with a documented source and uncertainty. Regulations such as MiFID II (financial trading) and IEC 61850 (energy) explicitly require that traceability.
In depth: Stratum levels and GNSS disciplining.
Why premium pays off: the total cost
The purchase price is only part of the picture. Consider:
- Cost of failure: what does an hour of wrong or stopped time cost in your environment?
- Lifespan: a professional device lasts 10+ years; a cheap clock often does not.
- Support and warranty: Masterclock devices come with 1 year warranty via Daylight bv and 4 years Masterclock factory warranty, plus local support.
Redundancy architecture
Duplicate the single points of failure: two independent GNSS receivers (preferably multi-constellation: GPS, Galileo, GLONASS, BeiDou), separate antenna paths, redundant power and, where the application demands it, two grandmasters with a deterministic selection mechanism (BMCA in PTP). The switchover must not introduce a time jump (phase step).
Holdover in the error budget
The time deviation during holdover is the integral of the frequency error; over a long outage the drift (ageing, temperature) dominates over the initial offset. Size the oscillator on (permissible deviation) divided by (realistic source recovery time), with margin for temperature gradients in the rack.
Traceability and audit
An auditable chain documents source, stratum, disciplining method and measurement uncertainty to UTC. MiFID II (ESMA RTS 25) requires a maximum divergence from UTC per trading activity; IEC 61850-9-3 (Power Profile) defines the requirements for the full PTP chain in a substation, not just for the grandmaster.
The weakest link determines the result
Antenna placement, cable length, switch jitter and ground loops can neutralise an expensive oscillator. A reliable installation designs the full chain, not just the device. See installation.
Sources: IEEE 1588-2019; IEC 61850-9-3; ESMA RTS 25 (MiFID II); NIST Time & Frequency Division.Frequently asked questions? See the general FAQ on protocols, warranty, installation and support →
Need tailored advice?
Daylight bv has been the authorised Masterclock distributor since 2014. For advice on your specific situation, we are reachable 24/7.
Contact Daylight