How many hops separate your clock from a UTC atomic reference?
The mental image most people have is a direct line to the master timekeeper. They imagine a single, all-powerful atomic clock somewhere, and their laptop asks it nicely for the time.
That is not how it works.
If every device on the internet tried to connect directly to the few dozen atomic clocks that define Coordinated Universal Time, those clocks would be swamped. More critically, they are not even on the network. A caesium fountain at the US Naval Observatory in Washington, D.C., does not have an IP address. It sits in a temperature-controlled room doing nothing but counting 9,192,631,770 oscillations of a caesium atom per second. Getting time from it requires a physical cable, not a packet.
So NTP invented a ladder. Each rung is called a stratum, from 0 to 16. The number tells you how many network hops you are from the real thing. Lower is better.
Stratum 0: the atomic reality
Stratum 0 devices are the time sources themselves. They include:
- Atomic clocks (caesium or rubidium)
- GPS receivers that decode the time signal from satellites
- Radio receivers tuned to national time signal stations like WWVB in Colorado or DCF77 in Germany
These devices do not talk to the network. They talk to a computer through a direct hardware connection: serial cable, USB, or a dedicated timing card. The computer listening to them becomes a stratum 1 server.
There are not many stratum 0 sources. The Bureau International des Poids et Mesures (BIPM) in Paris computes UTC from about 450 atomic clocks worldwide, but most of those are not directly accessible by anyone outside the lab. The publicly available stratum 1 machines are connected to maybe a few dozen of these primary references.
Stratum 1: the network's best
A stratum 1 machine is a computer directly attached to a stratum 0 device. It has no other source of time. It trusts the cable from the atomic clock. This gives it accuracy within a few microseconds of UTC, provided the hardware link is clean.
These are the best time sources you can reach over the internet. The US Naval Observatory's tick.usno.navy.mil is stratum 1. So are the NIST machines in Boulder, Colorado. If you can get a stratum 1 host to respond to your query, you are getting time that is essentially as good as the atomic clock itself, minus network delay.
The problem: stratum 1 hosts are scarce and heavily loaded. NIST's public endpoints handle billions of requests per day. They are not meant for every desktop computer.
Stratum 2: the workhorses
Stratum 2 hosts synchronise to stratum 1 machines over the network. They ask the stratum 1 hosts for the time, apply NTP's filtering algorithms to remove outliers and compensate for network jitter, and then serve that time to clients.
A well-run stratum 2 host can maintain accuracy within 1 to 10 milliseconds of UTC. That is good enough for almost everything: database timestamps, log files, email headers, financial transactions, industrial control systems.
Most corporate time infrastructure runs at stratum 2 or 3. If your company has an internal time host in the server room, it is almost certainly stratum 2, syncing to a pool of stratum 1 machines, and then distributing time to your workstations. This is the smart way to do it: one host in your network talks to the outside world. Everyone else talks to that one host.
Stratum 3 and beyond: getting closer to you
Stratum 3 synchronises to stratum 2. Stratum 4 to stratum 3. Each step adds a small amount of uncertainty, typically another millisecond or two of potential error.
The stratum number can go up to 15. Stratum 16 is a special value meaning "unsynchronised." Your computer sits at stratum 16 until it gets its first successful NTP query.
In practice, most desktop computers and mobile devices operate at stratum 3 or 4. They talk to public NTP pools or to a local host provided by their internet service provider. The accuracy is still within tens of milliseconds. Invisible to humans. Your system clock does not need microsecond precision to display the correct time on a web page.
How NTP chooses which source to trust
A client does not just ask one host and accept the answer. NTP clients typically query multiple sources (the default in many configurations is four) and run a statistical filter.
The algorithm works like this:
- Send a query to each source, recording the time the request was sent.
- The source responds with its current time.
- The client records the time the response arrived.
- The client calculates the round-trip delay and estimates the offset.
Then comes the clever part. NTP assumes network delay is asymmetric: the packet took longer to arrive than to return, or vice versa. It uses a set of filters (the "clock filter algorithm") to discard outliers. If one source returns a time that is 50 milliseconds off from the other three, that source gets dropped. The remaining values are averaged, and the clock is adjusted gradually.
Gradual is critical. NTP never jumps the system clock backward. If your clock is 10 seconds fast, NTP will slow it down over the course of a few minutes until it catches up. This is called "slewing." Jumping backward would break database transaction ordering, file timestamps, and any system that assumes time only moves forward.
Public NTP pools: the internet's timekeeping commons
The largest source of NTP service for the general public is the pool.ntp.org project. It aggregates thousands of volunteer-run hosts, mostly at stratum 2 and 3, and distributes requests across them using DNS round-robin.
When you configure your device to use "pool.ntp.org" or "0.pool.ntp.org", you are not connecting to a single host. You are connecting to a randomly selected machine from a pool of hundreds or thousands, depending on your geographic region. The pool project has hosts on every continent except Antarctica, serving billions of queries per day.
The pool relies on volunteers. If you have a machine that stays online and has a stable internet connection, you can contribute a stratum 2 or 3 host to the pool. The project's monitoring systems check that your host is accurate within acceptable limits before adding it to the rotation.
When will the UTC stratum model change?
The leap-second system that UTC uses to stay aligned with Earth's rotation is being phased out. The General Conference on Weights and Measures (CGPM) passed Resolution 4 in 2022, planning to stop leap seconds by 2035. After that, the difference between UTC and astronomical time (UT1) will be allowed to grow beyond the current limit of 0.9 seconds, possibly to a minute or more.
What does that mean for NTP? Nothing immediate. NTP already handles the current leap-second system by distributing leap-second notification bits and handling the 23:59:60 insertion. When leap seconds stop, the protocol will simply stop receiving those notifications. The stratum hierarchy will continue to operate exactly as it does now: atomic clocks at the bottom, your device at the top, with the same query-and-filter dance in between.
The bigger change for most users is the ongoing improvement in NTP security with Network Time Security (NTS), which authenticates time sources to prevent man-in-the-middle attacks. If you manage an NTP host, expect NTS support to become the default over the next few years. Check your NTP daemon's documentation for the nts or -N flag.