08/18/2026 | Press release | Distributed by Public on 08/17/2026 20:32
In the digital economy, the concept of sovereignty is often associated with data control or infrastructure localization. However, there is an invisible yet omnipresent element that serves as a true 'pillar' for the entire system: Time. Therefore, time control is not merely a technical necessity but the fundamental prerequisite for exercising genuine digital sovereignty.
Why is time fundamental?
There is a subtle but crucial distinction between these two concepts: While sovereignty refers to the exercise of control, independence represents the capacity to operate autonomously. There is extensive debate surrounding this terminology, representing two approaches that are not mutually exclusive for maintaining control over digital infrastructure and services in specific geographic areas. Regardless of the context, the synchronization of digital systems is critical in various sectors, including, in addition to research and defence:
The vulnerability of GNSS: An invisible risk
Today, the vast majority of the time used in digital systems originates from space via satellite systems such as Global Navigation Satellite System (GNSS), the most widespread of which is the American GPS. Exact data is not known, but some reports suggest 90% of synchronization relies on GNSS. These are satellite technologies that provide, in addition to the location of a receiving device, a very accurate time signal, useful for most consumer and many industrial applications. When higher accuracy is required, atomic clocks (such as caesium) are used as a reference.
The massive reliance on satellite systems conceals significant risks. The GNSS signal can be subject to random interference (solar activity, multipath) or intentional attacks such as jamming (signal blocking) and spoofing (sending false signals). There are continuous reports of such problems in various parts of the world, most evident in areas of higher geopolitical tension, as evidenced by the GPS interference map, which highlights them daily across different regions.
A GNSS outage can cause losses of up to 1 billion euros per day. If the satellites stopped working or were blocked, services would start to fail due to system 'drift'.
Last, but not least, all GNSS systems, except Galileo, are based on non-European technology, which, speaking from an EU perspective, raises questions about source traceability and system redundancy.
Security starts with time
International regulations are already integrating time as a security requirement. The necessity (and therefore the obligation) to implement secure, reliable, and adequately accurate synchronization systems is included, for example, in the following regulations:
ISO27001:2022, which, within the standardization of the Information Security Management Systems (ISMS), has introduced a focus on the use of reliable time sources in information processing systems.
NIS2, the new European cybersecurity directive imposing advanced security requirements and severe penalties on entities and companies, requires that involved entities can ensure all their systems have adequate synchronization, as stated in Article 21(2).
MiFID II, the European regulatory framework governing financial markets and investment services, requires trading entities to synchronize their business clocks with Coordinated Universal Time (UTC) to ensure precise and traceable control.
IEEE C37.118 is a standard increasingly adopted for the synchronization of electric power distribution systems, which requires accuracy below one microsecond to ensure errors below 1%.
In short, it can be stated that cybersecurity today begins with the security and reliability of time.
The role of Internet Exchange Points
To address the vulnerabilities outlined above, several European Internet Exchange Points (IXPs) have started offering resilient time distribution services. These services build on the unique advantages of IXPs, including their neutrality, extensive network reach, and close proximity to operators. As a result, IXPs are increasingly positioning themselves as neutral, business-focused providers of 'Time as a Service', delivering synchronization through Network Time Protocol (NTP), Precision Time Protocol (PTP), and, where the highest levels of accuracy are required, White Rabbit technology.
Leading examples include LINX, ESpanix, Netnod, and AMS-IX. Among these, Netnod's initiative in Sweden stands out. As part of what has become known as the 'Swedish Model', the Swedish Post and Telecom Authority (PTS) has mandated the deployment of a redundant national time synchronization service from 2025. The objective is to strengthen resilience for organizations that currently depend solely on GNSS or on timing sources located outside Sweden. In practice, this represents a tangible example of digital sovereignty and national infrastructure independence.
The service is operated by Netnod, monitored by the Research Institutes of Sweden (RISE), which is also active in metrology and certification, and funded by PTS. It consists of six geographically distributed time nodes across Sweden, all continuously monitored and synchronized to UTC(SP), Sweden's national realization of Coordinated Universal Time. Each node is equipped with two atomic clocks that maintain independent time scales, ensuring high availability and redundancy. Even in the unlikely event that a node loses connection to all external reference sources, it is designed to maintain highly accurate time within strict limits for several months.
What about Italy?
In Italy, TOP-IX began addressing the challenges related to time reference dissemination about 10 years ago. Today, TOP-IX guarantees the provision of independent and resilient time services, ensuring traceability to UTC(IT) thanks to the strategic collaboration with INRiM (the national metrological institute that maintains the national time standard and is also active in certification).
The technological solution is based on the use of the NTP protocol for basic needs, alongside premium solutions based on PTP+SyncE to meet requirements for very high precision. This service enables the fulfilment of rigid regulatory obligations, including the parameters defined by MiFID II for managing high-frequency financial operations.
The infrastructure is designed with a redundant node architecture, located at the data centres where TOP-IX is present, to safeguard operational continuity and reliability in signal distribution. The evolutionary path has culminated in the extension of coverage nationwide, consolidated through significant partnerships with other sector or contiguous operators such as Aruba, VSIX and, last but not least, NaMeX (within the ARGO Alliance, which aims to promote a collaborative framework to simplify the interconnection and provision of advanced services between IXPs, to support the growth of the entire community).
Conclusion: It's time to act
Resilience is not a luxury but a necessary policy. In an era characterized by increasing geopolitical tensions and digital fragmentation, the security of critical infrastructure cannot disregard the accuracy and reliability of temporal synchronization systems. Through a strategic approach that effectively combines bottom-up initiatives with institutional visions and strategies (top-down), it becomes essential for public and private organizations to adopt terrestrial, secure, and fully traceable time sources. In this context, some IXPs have demonstrated that they are able to play an important role, as highlighted in the previous examples, with their ability to provide services to the community.
Relying exclusively on satellite solutions exposes networks to relevant systemic and economic risks, making source diversification and redundancy a priority for operational continuity. Only by guaranteeing an independent, stable, and compliant time reference with the most stringent international regulatory standards can the economy's system and individual entities truly protect their strategic assets, thereby consolidating the very foundations of their sovereignty and digital independence in the long term.
Luca Cicchelli is the Interconnection Manager at TOP-IX with interests in time synchronization and digital sovereignty.
Adapted from the original post on LinkedIn.
The views expressed by the authors of this blog are their own and do not necessarily reflect the views of APNIC. Please note a Code of Conduct applies to this blog.