Controls

Time synchronization

Time synchronization is the practice of holding every clock on a battery plant to one reference, so that a timestamp written by a protection relay, a revenue meter, a power conversion system and the plant controller all name the same instant. The reference is normally UTC delivered by a GNSS receiver on site and distributed over the plant network by NTP for millisecond-class users, or by IEEE 1588 Precision Time Protocol and IRIG-B for the microsecond-class ones.

On a good day none of it changes how the plant runs. It decides whether the records of a bad day can be assembled into one story, and whether a compliance test whose result is the interval between two timestamps written by two different devices means anything at all.

Reviewed August 2026 by Sergey Syrvachev

New to BESS? Start free with the 7-email fundamentals course — no cost, no account.

Three separate things have to be right

A synchronized plant has a reference, a distribution path and a stamping point, and they fail independently. The reference is a source of UTC — in practice a GNSS receiver, because it delivers the same time everywhere at once without anyone laying a cable between substations. The distribution path carries that time to devices over the plant network or over dedicated timing wiring.

The stamping point is inside each device: the moment at which it decides that an event happened and writes a time against it. A relay whose clock is locked to the reference within a microsecond still produces a useless record if the event was captured by a polling loop that runs every two seconds, and that distinction is the one most site arguments turn on.

GNSS is the usual reference because it is UTC-traceable and available at every enclosure with a sky view. The US Department of Defense's GPS Standard Positioning Service Performance Standard commits the broadcast UTC offset to within 40 ns at 95%, which is far finer than anything the distribution network downstream will preserve, so the receiver is almost never the limiting element. Multi-constellation receivers that also track Galileo, GLONASS or BeiDou reduce dependence on one system.

Two receiver properties belong in the specification rather than the brochure: the holdover behaviour — how long after antenna or signal loss the clock still meets the accuracy class it was bought for — and whether the antenna, its surge protection and its cable run are in somebody's scope, because a rooftop antenna on a single mast is a single point of failure for every timestamp on site.

The third thing worth insisting on is that timestamps carry a quality indication. IEC 61850 attaches a TimeQuality field to its timestamps, including flags for a clock that is not synchronized and a clock that has failed, and synchrophasor data frames carry a time-quality field of the same intent. Where those flags survive into the historian and the event files, an analyst can tell a trustworthy timestamp from an assertion. Where they are stripped at a protocol gateway, every record looks equally authoritative, including the ones written by a device that lost its reference three weeks earlier.

NTP, PTP and IRIG-B are three different accuracy classes

NTP is the default and, for most of the plant, sufficient. RFC 5905, which specifies NTPv4, describes it as typically maintaining time to within tens of milliseconds over the public internet and achieving better than one millisecond on local area networks under good conditions. That is the right class for SCADA alarms, historian tags, controller logs, human-readable event lists and anything a person will read as a wall-clock time.

It runs in software over the same Ethernet as everything else, needs no special switches, and costs a network port on a GNSS clock. Its weakness is that the accuracy it delivers depends on network load and path asymmetry, so the millisecond figure is a good-conditions number rather than a guarantee written into a device datasheet.

IEEE 1588 Precision Time Protocol buys roughly three orders of magnitude more, but only if the network cooperates. It works by timestamping its own packets in hardware at the physical layer and by having every switch on the path either correct for the delay it introduced — a transparent clock — or regenerate time as a boundary clock.

Two power-industry profiles narrow the general standard into something specifiable: IEEE C37.238-2017 and IEC/IEEE 61850-9-3, both written around delivering time to the end application within about a microsecond across a substation network. The failure mode is predictable: run PTP through ordinary managed switches that do not implement it and the queueing delay each hop adds lands directly in the error budget, turning a microsecond-class scheme into a variable millisecond-class one that still reports itself as locked.

IRIG-B is the older answer and it is still installed, because it does not share a network with anything. Time goes out on dedicated coaxial or twisted-pair cable to each device, and the unmodulated DC level-shift form is the accurate one — the amplitude-modulated form is coarser and is chosen for compatibility rather than performance.

The clean way to settle which technology belongs where is to specify by class rather than by product: IEC 61850-5 defines synchronization classes stepping from around a millisecond down to a microsecond and finer, and each application in the plant sits in one of them. Write the class against each device group in the controls specification, and the choice between NTP, PTP and IRIG-B stops being a vendor preference.

“Synchronized” spans eleven decades — specify a class per device group, or the logs look authoritative while drifting apart.
GPS-broadcast UTC offset≤40 ns (95%)PTP under the power profilesonly if every switch is a boundary clock~1 µssynchrophasor budget~26 µs at 60 Hzrelay sequence-of-events1 msNTP on a LAN, good conditions<1 ms — not guaranteedfree-run drift at 1 ppm~86 ms PER DAYGPS vs UTC offset18 s since 2017local time and daylight savingwhole hours1 µs1 ms1 s1 hhow far apart two clocks can be

One millisecond of skew between measurement points reads as 18 degrees at 50 Hz. A clock that has lost its reference generally keeps reporting a time, so loss of lock must raise an alarm the operator sees and the quality flags must survive into the records.

Key facts
Reference source
GNSS receiver delivering UTC on site; the US GPS Standard Positioning Service Performance Standard commits the broadcast UTC offset to within 40 ns (95%)
NTP accuracy class
RFC 5905 (NTPv4): typically tens of milliseconds over the public internet, better than 1 ms on a LAN under good conditions — a good-conditions figure, not a guaranteed one
PTP accuracy class
IEEE 1588 under the power profiles IEEE C37.238-2017 and IEC/IEEE 61850-9-3, written around about 1 microsecond at the end application — achieved only where every switch on the path is a transparent or boundary clock
Specification handle
IEC 61850-5 synchronization classes, stepping from roughly a millisecond down to a microsecond and finer; specify a class per device group rather than a product
Sequence-of-events resolution
Commonly 1 ms in numerical relays, against one cycle of 16.67 ms at 60 Hz / 20 ms at 50 Hz and clearing of 3-5 cycles at medium voltage
Synchrophasor timing budget
1% total vector error is about 0.573 degrees if treated as pure phase error — roughly 26 microseconds at 60 Hz, roughly 32 microseconds at 50 Hz; measurement requirements now in IEC/IEEE 60255-118-1:2018
Skew read as angle
1 ms of skew between measurement points appears as 18 degrees at 50 Hz and 21.6 degrees at 60 Hz
Offsets that break reconciliation
GPS time has been 18 s ahead of UTC since the start of 2017; local time and daylight saving add whole-hour errors; a clock free-running at 1 ppm drifts about 86 ms a day, at 20 ppm about 1.7 s a day
North American compliance hook
NERC PRC-002-2 requires sequence-of-events and fault-recording data at the elements it applies to be synchronized to a common reference within the tolerance it states (plus or minus 2 ms in the version in force); applicability is set by the standard's own criteria and does not reach every plant

What the microseconds are actually for

Most of the plant does not need them. Sequence-of-events recording, the reason time synchronization exists on a protection scheme, is commonly resolved at one millisecond in numerical relays and specified at that figure by utilities. Set that against the intervals it has to resolve: one cycle is 16.67 ms at 60 Hz and 20 ms at 50 Hz, and total clearing is the relay decision plus the breaker interrupting time, commonly three or five cycles at medium voltage — 50 to 83 ms at 60 Hz and 60 to 100 ms at 50 Hz.

Ordering breaker operations that are tens of milliseconds apart needs skew well below a millisecond between the devices being compared, which a properly locked NTP or PTP hierarchy delivers. Ordering events inside a single cycle does not survive millisecond-class distribution.

Synchrophasors set the tightest routine requirement. A phasor measurement unit reports a phasor referenced to UTC, and the accuracy metric is total vector error; the 1% TVE limit works out, if the whole error is treated as a phase error, to about 0.573 degrees, which is roughly 26 microseconds at 60 Hz and roughly 32 microseconds at 50 Hz. That is the entire timing budget for the measurement, before any of it is spent on the instrument transformers or the algorithm.

The measurement requirements now sit in IEC/IEEE 60255-118-1:2018, with IEEE C37.118.2 covering the data transfer, and on a battery project PMU data usually appears for disturbance analysis and model validation rather than control. Sampled-value schemes are in the same class for a different reason: at 80 samples per cycle a sample interval is 250 microseconds at 50 Hz, so merging units that are meant to be combined have to agree to a small fraction of that.

The general rule behind both is that any comparison of angles is a comparison of clocks. One millisecond of skew between two measurement points reads as 18 degrees at 50 Hz and 21.6 degrees at 60 Hz — larger than the whole power-factor cone — so point-on-wave records, PMU feeds and relay oscillography from different devices can only be compared as angles once their time alignment has been verified. An angle that looks alarming in commissioning data is more often a timestamp problem than a power-system one, which the phase angle and phasor entries take up from the measurement side.

Compliance and contracts are settled on timestamps

In North America the explicit obligation sits in NERC's disturbance-monitoring standard PRC-002-2, which requires sequence-of-events and fault-recording data at the elements it applies to be time-stamped against a common reference within the tolerance the standard writes — a low-millisecond figure, stated as plus or minus 2 ms in the version in force.

Applicability is set by the standard's own criteria and does not reach every battery plant, so the test is whether the facility falls inside them rather than whether it is large. Under FERC Order 901 the inverter-based-resource standards are still moving: PRC-029 is the ride-through standard the protection relay entry covers, and disturbance-monitoring requirements for inverter-based resources have been developed alongside it, so the version in force at the time of registration is the one to read rather than any summary of it.

Elsewhere the requirement is real but is not written as one number. IEC 61850-5's synchronization classes are the international handle, and national grid codes, connection agreements and system-operator event-reporting rules impose the rest — GB, the Australian NEM and the ENTSO-E member systems each set their own evidence expectations for compliance testing and post-event reporting, and none of them should be assumed from another.

Market timing is a separate axis again: the EU's electricity balancing regulation harmonised the imbalance settlement period at 15 minutes (the Irish SEM excepted at 30 minutes), while several North American ISO markets settle energy at five-minute intervals, and interval boundaries only line up between the meter and the market if both are working from the same reference. That boundary belongs to the revenue meter; the clock behind it belongs here.

The practical consequence is that a compliance test result is usually a difference between two timestamps written by two different devices. A ramp-rate test, a response-time measurement, an AGC signal-following run and a witnessed capability test all measure the elapsed time between a command recorded in one system and a response recorded in another, so the plant's timing accuracy sets a floor under the resolution of the result.

Four things belong in the controls scope of work rather than in a commissioning punch list: whose package supplies the GNSS clock and its antenna, which accuracy class each device group must hold, that event records and oscillography are stamped in UTC and retrievable in a documented format, and how long they are retained. The protection relay entry already makes time-synchronized, retrievable relay event files a contract item; this is the same requirement seen from the clock's side.

How alignment fails on a real site

The first family of failures is whole-number offsets, and they are the easiest to fix and the most common. A device configured in local time rather than UTC produces records that appear correct in isolation and are an hour or several out against everything else, and a plant that observes daylight saving gains one ambiguous hour and one missing hour every year, which is enough to make an autumn event log unorderable.

GPS time is a separate scale that does not observe leap seconds, and it has been ahead of UTC by 18 seconds since the last leap second at the start of 2017 — a device fed raw GPS time and reported as if it were UTC lands exactly 18 seconds away from the rest of the plant. The General Conference on Weights and Measures resolved in 2022 to stop inserting leap seconds by 2035, which removes the source of new offsets but not the ones already embedded in older equipment.

The second family is drift, which shows up on devices that sync at boot and then free-run, or that lost their reference and nobody noticed. The arithmetic is unforgiving: a clock running 1 part per million fast or slow moves about 86 ms in a day, and an uncompensated crystal at 20 ppm moves about 1.7 seconds a day, so a month of free-running puts a device far outside any class it was specified to. Related is where the timestamp is created rather than what the clock says.

Modbus registers carry no time of their own, so an event read over Modbus is stamped when the master polled, not when it happened; DNP3 and IEC 61850 can carry a device-generated timestamp, which is why the boundary between them in the plant is also the boundary between real event times and poll times. The telemetry entry owns that data path; the point here is that a perfect clock does not rescue a poll-time stamp.

The third is the reference itself. A single GNSS antenna serving the whole site takes every timestamp with it when its cable is damaged, its surge protector fails or the signal is jammed or spoofed, and the plant may not find out until an event needs reconstructing. Ask for the holdover specification, an alarm on loss of lock that reaches the operator rather than a log file, and a documented decision about whether a second receiver or a second reference path is worth it for the plant's compliance obligations.

What all three families produce is the same outcome, and it is the reason the topic is worth a specification of its own: after a trip, two logs that disagree by an unknown amount cannot be merged into a sequence, so the question of what caused what has no evidence-based answer — only the recollections of whoever was on site, arriving in a meeting where a utility is waiting for a report.

Common misconception

The site has a GPS clock and everything runs NTP, so the timestamps in the event logs line up.

In reality: Locking to a reference and producing comparable timestamps are different achievements. NTP is a millisecond-class service — RFC 5905 puts NTPv4 at better than a millisecond on a LAN under good conditions and tens of milliseconds across the public internet — which is enough to order breaker operations recorded at 1 ms resolution, provided each device actually holds lock and is not stamping at poll time, free-running between syncs, or writing local time instead of UTC. Microsecond work does not come from the same infrastructure: synchrophasors, whose 1% total vector error budget is roughly 26 microseconds at 60 Hz, and sampled-value schemes need PTP or IRIG-B and network equipment that supports them. And a clock that has lost its reference generally keeps reporting a time, so unless loss of lock raises an alarm the operator sees and the quality flags survive into the records, the logs will still look authoritative while drifting apart.

Visuals & further reading
Go deeper

Time synchronization, in context.

The Grid-Scale BESS course covers time synchronization — and the rest of the system — from the ground up, the way it actually gets deployed.

Browse the course