Sovereign French NTP: Why It Matters
Sovereignty starts with knowing who holds what. The NTP and NTS map measures, country by country, the number of distinct operators and the weight of the largest one: France shows up in amber, with close to a third of its NTS fleet held by a single actor — us.
Time synchronization has become an invisible critical dependency: DNSSEC, TLS certificates, 2FA, legal traceability of logs, MiFID II and NIS2 compliance all rely on a trustworthy clock. When that time source is operated outside Europe, or outside any controlled contractual frame, the entire chain of trust silently inherits an extra-territorial dependency.
This page describes the sovereign time infrastructure operated by RDEM Systems — servers hosted in Paris-Equinix datacenters, announced on our own BGP AS, reachable over authenticated NTS and native dual-stack IPv4/IPv6 — and its concrete relevance for administrations, OIV/OES operators, and fintechs subject to demanding regulatory frameworks.
Why Time Sovereignty Is a State-Level Matter
Network time is one of the deepest and least-discussed dependencies in any IT system. A drifting clock does not stop a service: it silently invalidates the security guarantees you assumed were intact.
- DNSSEC — zone signatures and RRSIG records carry validity windows (inception, expiration). A client whose clock is manipulated may accept replayed signatures or reject valid ones.
- TLS certificates — sufficient time skew makes expired or not-yet-valid certificates pass validation, opening the door to MITM attacks on encrypted sessions.
- Legal traceability of logs — retention obligations and the evidentiary value of logs (GDPR, NIS2, criminal procedure code) require reliable, tamper-resistant timestamps. Without that, the chain of evidence collapses.
- MiFID II / RTS 25 — market operators must demonstrate UTC synchronization at a threshold that depends on their activity: 100 µs for high-frequency algorithmic trading, 1 ms for other forms of algorithmic trading, 1 s for manual order entry. Documented traceability in every case. This is a recurring object of AMF / ESMA audits.
- TOTP authentication (2FA) — one-time codes depend on synchronized clocks on both sides. Drift — accidental or induced — can lock users out of critical systems.
The question of where the time source lives, and under whose jurisdiction, follows directly. When the rest of the stack is hardened against a network attacker, it is consistent for the time source to meet the same bar: operated by a known entity, bound by the law applicable to the customer, and technically verifiable by third parties.
RDEM Architecture — AS206014, French ASN in-house
The RDEM Systems NTP/NTS infrastructure is built on an end-to-end controlled architecture: a French BGP autonomous system operated directly, Stratum 2 servers spread across several Equinix Paris sites, and a resilience site in Frankfurt. All of this is publicly verifiable.
BGP autonomous system run by RDEM Systems SAS. Our French ASN, with public records on PeeringDB and bgp.tools.
Routers reachable through the public BGP looking-glass — verify RDEM peering live.
Servers deployed at Equinix PA3, PA4, PA5 and TH2 — four distinct Paris sites for regional resilience.
One server in Germany for geographic resilience outside the Paris zone, on the same AS.
Physical server presence
Sovereignty: the four layers not to conflate
European sovereignty: complete. French sovereignty: partial but solid — and we document it rather than oversell it.
The sovereignty of a time source is not binary. It reads on four distinct layers that are too often conflated: the operator (who answers for the service), the physical location (where the machine sits), the hosting contract (with which legal entity, hence under which law), and the AS (the autonomous system number the traffic is announced from). The first three carry jurisdiction. The fourth is technical.
European sovereignty: total, no exception. All 12 servers are hosted in the Union, announced by European ASes, and contracted with European entities. For any framework reasoning at EU scope — NIS 2, DORA, GDPR — the chain is sovereign end to end.
French sovereignty: 10 of 12 servers fall entirely under French law. The core is
7 servers on AS206014, our own French AS (ntp-1 to ntp-6 and
ntp-8, in the Equinix PA3/PA4/PA5 datacenters). Add ntp-10 (IELO, AS29075),
ntp-11 (IPSET, AS199275, at TH2) and ntp-9 (Equinix PA4) — the latter
hosted in France under a transit contract with Arelion France SAS, a French entity, even
though AS1299 is registered to the Swedish parent. An AS number is not a legal nationality.
Only two servers depart, and they do so in exactly mirrored ways:
ntp-12: in France (Lauterbourg), but under a German contract and AS — Contabo GmbH, AS51167, prefix registered DE at the RIPE.ntp-7: the exact mirror image — in Germany (Frankfurt), but under a French contract and AS — OVH SAS, AS16276.
That symmetry is the instructive part: a flag on a map tells you nothing about who operates the machine, and a server hosted abroad remains under French law as long as a French entity runs and contracts it. The layer that determines the applicable jurisdiction — the only one a regulator will look at — is the service operator: RDEM Systems, a French company based in Pontoise (95). On that layer, all 12 servers are French without reservation.
We would rather document these exceptions than let an auditor discover them. And if your framework demands
strict alignment on France, the answer is simple: configure the ten servers concerned, or
the AS206014 core alone. They are more than enough for a redundant architecture, and they carry
no caveat.
Pushing the honesty to the end: the chain never fully closes
A rigorous auditor will go further than we just did, and they will be right. The datacenters themselves are not European: Equinix PA3, PA4 and PA5 are operated by Equinix Inc., a US company, and TH2 by Telehouse, part of the Japanese KDDI group. Even the AS206014 core therefore runs inside buildings operated by groups subject to non-European law — the US CLOUD Act among them.
And the objection holds even when the contracting party is a French subsidiary —
Equinix France SAS, Arelion France SAS. Contracting with a French-law subsidiary settles the law of the
contract, but does not immunise against the extraterritorial reach of the parent's
jurisdiction. That is true of Equinix, and in fairness we say the same of the argument we made
above for ntp-9: a French contract with Arelion France SAS does not make the Swedish parent
disappear — though in that case the parent sits inside the Union.
No time operator in France can claim otherwise, short of owning its own walls. Claiming absolute sovereignty would be dishonest, and we will not do it.
But the objection, sound as it is, does not mean what it is often made to mean — because it conflates colocation with cloud. Here is the exact division of roles:
But not all our servers fall under the same hosting regime, and our exposure is not the same everywhere. We would rather write it than let you discover it:
- Colocation, our own hardware — 9 servers (Equinix PA3/PA4/PA5). Our machines, our systems, our keys. Seven are announced on our own AS206014; two more run on our clusters but with our transit providers' addressing (Arelion, IELO) — the hardware is still ours, only the IP comes from a third party. Equinix and Telehouse sell walls, power and cooling: they touch neither the OS, nor the keys, nor the data. A colocation landlord has no custody over its tenant's machine — it cannot be compelled to produce what it does not hold.
- Rented physical machine —
ntp-7(OVH, Frankfurt). The hardware belongs to OVH, but there is no hypervisor: the system, the keys and the live memory are accessible to us alone. OVH can physically seize a disk; it has no logical access to the running machine. - Virtualised on a third party —
ntp-11,ntp-12. They run on a host's hypervisor. That host therefore has technical custody of the machine: it can read its memory. On those nodes, and those alone, the argument "the landlord has no custody" does not hold. We will not pretend otherwise. - Transit — Arelion and IELO carry packets and host nothing. IPSET does both:
it carries traffic and hosts
ntp-11on its hypervisor — which is why, and only why, it has technical custody of that node.
In other words: if your regulatory framework demands that no third party can reach the machine, configure only the 9 colocated servers. They are more than enough for a redundant architecture, across three datacenters. This is the kind of precision you will not find elsewhere — because it forces you to name your own weakest link instead of burying it.
The distinction is legally decisive. The CLOUD Act reaches a provider that has possession, custody or control of the data. A landlord has no custody over its tenant's machine: it cannot be compelled to produce what it does not hold — and it does not hold it. That is what separates our exposure from that of an AWS or Azure customer, where the provider runs the machine, owns the hypervisor and, frequently, the keys.
And for NTP the question is largely academic anyway: a time server stores no customer data. None of your files, none of your identities, none of your transactions. It answers with a time. There is, literally, nothing to seize.
The real sovereignty risk in NTP lies elsewhere: availability (can your time be cut off?) and integrity (can you be served a false one?). A landlord can, at worst, close its door to you — a continuity risk, addressed by geographic redundancy, which is precisely why our servers sit across six sites and two countries. But it can neither read your clock nor falsify it.
What grounds our sovereignty is therefore not the walls: it is what we own outright. Our servers, which we alone operate. Our AS, which makes us independent of any host to announce our prefixes. And our Stratum 1, GPS- and PPS-disciplined, which makes us independent of any third-party time source. That is where the sovereignty of a time chain is actually decided — not in the country of incorporation of the landlord.
Native dual-stack IPv4 / IPv6
The entire pool is reachable natively over IPv4 and IPv6. The IPv6 stack is not a tunnel or a gateway: IPv6 prefixes are announced over BGP by AS206014 in the same way as IPv4 prefixes. French administrations subject to the IPv6 directive (DINUM/ARCEP) and operators meeting the general interoperability framework can reference this source without any technical workaround.
NTS: Cryptographic Security Across the Stratum Chain
Plain NTP is sent in the clear over UDP, with no authentication. A MITM attacker can impersonate a server or modify responses, which is not acceptable for the use cases above. NTS (Network Time Security, RFC 8915) adds the missing layer: cryptographic authentication via TLS 1.3 without encrypting the time payload itself, preserving accuracy.
The entire RDEM pool is NTS-enabled. This is still rare: out of the 4,586 time machines our registry probed from six networks as of 7 August 2026, 265 serve authenticated time — 29 of them in France. The dedicated page covers Chrony configuration and verification: Enable NTS on Chrony in 5 minutes.
Public-Sector and Regulated Use Cases
The set of organizations that have a direct interest in a sovereign time source extends well beyond central administrations alone.
| Entity type | Time-related stake |
|---|---|
| Central and decentralized administration | Public e-service timestamping, PSSI-E traceability, RGS alignment |
| Local authorities | Audit logs, TLS certificates on citizen portals, electronic signature |
| OIV (operators of vital importance) | French Military Programming Law (LPM) — supervision and event correlation |
| OES (operators of essential services) / NIS2 | Incident notification, timestamped journaling, supply-chain control |
| Fintechs and market operators | MiFID II / RTS 25 — UTC within 100 µs for high-frequency trading (1 ms / 1 s depending on activity), AMF/ESMA audit |
| Hosters and network operators | Contractual compliance, time SLAs, signed RBAC logs |
Compliance — RGS, ANSSI, NIS2, GDPR Logs
The table below summarizes the main frameworks that, directly or indirectly, demand a controlled time source. None of them names a specific provider; all of them put the burden on the data controller to demonstrate the reliability and traceability of timestamping.
| Framework | Time-related requirement |
|---|---|
| RGS (Référentiel Général de Sécurité, France) | RGS B.2 — reliable log timestamping. RGS A.5 — signature and proof. |
| ANSSI recommendations | Logging technical note: redundant synchronized time sources, isolation, drift supervision. |
| NIS2 (directive transposed 2024-2025) | Article 21 — cyber risk management measures, including traceability, timestamping and supply-chain control. |
| GDPR — logs | Article 32 — integrity and traceability of processing. Incorrect timestamps undermine evidentiary value. |
| MiFID II / RTS 25 | UTC ≤ 100 µs for high-frequency trading, documented traceability of NTP/PTP sources. |
| PCI-DSS v4 | Requirement 10.4 — clock synchronization across the cardholder-data perimeter. |
Third-party verifiability
A sovereign infrastructure is measured by what a third party can verify without the operator's cooperation. For AS206014, every element is public:
- BGP announcement visible on every public looking-glass (RIPE, Hurricane Electric)
- PeeringDB record — peering policy, datacenter presence
- Public BGP looking-glass operated by RDEM — direct routing-table lookup
- NTP Pool score on ntppool.org/a/rdem-systems — independent accuracy measurement
- Listed in the NTS community repository jauderho/nts-servers
Public-Sector FAQ
What is a sovereign NTP server?
Sovereignty reads on four layers: the service operator, the physical location, the hosting contract, and the AS announcing the prefixes. RDEM Systems operates NTP and NTS on its own AS206014 (a French entity) from Paris-Equinix datacenters, Lauterbourg and a secondary site in Frankfurt. No operator can claim absolute sovereignty: the datacenters themselves belong to non-European groups. What matters is the nature of the link — this is colocation, not cloud: the servers are ours, the landlord has no custody over the machine, and an NTP server stores no customer data anyway. The four layers in detail →
Does France's RGS framework require a sovereign NTP server?
The Référentiel Général de Sécurité does not name a specific NTP service, but it requires reliable timestamping and traceability of audit logs (RGS B.2 and A.5). In practice, a controlled time source legally located in France makes it easier to demonstrate compliance, especially for public e-services and administrations subject to PSSI-E.
Why does NIS2 make NTP sovereignty more important?
NIS2 (transposed in France from 2024-2025) extends cybersecurity obligations to thousands of essential and important entities. Requirements include incident traceability, reliable log timestamping and supply-chain control. A time infrastructure operated by an EU-law entity, on a clearly identified AS and datacenters, simplifies demonstrating that control.
Does MiFID II impose specific NTP synchronization requirements?
Yes. MiFID II / RTS 25 requires trading-system clocks to be synchronized to UTC within 100 µs for high-frequency operators, with documented traceability. NTS (RFC 8915) provides cryptographic proof that the source used is authentic, which limits impersonation risk and simplifies the audit.
What is AS206014 and why does it matter?
AS206014 is the BGP autonomous system run directly by RDEM Systems. It is referenced on PeeringDB, bgp.tools and bgp.he.net. Operating one's own AS means not depending on a third party for routing: the IP prefix is announced directly by RDEM, providing full network traceability and resilience against transit-operator decisions.
Are RDEM servers reachable over IPv6?
Yes. The entire NTP/NTS pool is native dual-stack IPv4 + IPv6. This is a prerequisite for French administrations subject to the IPv6 directive (ARCEP/DINUM reference) and for operators meeting the general interoperability framework requirements.
Can a sovereign NTP/NTS infrastructure be outsourced?
Yes. RDEM Systems offers Essential / Pro / Critical managed-server plans with 24/7 on-call coverage — including time-drift monitoring, security maintenance, TLS/NTS certificate management and compliance reporting. Useful for public-sector IT teams or MiFID II fintechs that want to industrialize time reliability without staffing a dedicated team.
Is there a sovereign European time server?
Yes, and more than one: as of 7 August 2026 our registry measures 2598 time machines located in Europe, 192 of which serve NTS (RFC 8915), run by 42 distinct European operators — national metrology institutes (PTB in Germany, ROA in Spain, BEV in Austria, DFM in Denmark), research networks and private operators (Netnod in Sweden, SIDN Labs in the Netherlands). The question is therefore not whether they exist, but whether your country has one: 21 European countries serve NTS, and in the other 17 we found no public reference serving it. Full verifiable registry: the measured European registry
Is my NTP server exposed to the US Cloud Act?
Not in the way usually assumed, and the distinction matters. The Cloud Act lets US authorities compel a provider subject to US law to hand over data it holds, wherever that data is hosted. NTP carries no content: there is no data to seize. The real exposure is twofold. First, dependency: if time.google.com or time.windows.com stops answering you, or changes its leap-second policy, you are subject to a non-European third party's decision. Second, metadata leakage: querying a US server exposes your machines' IP addresses, their query volume and their activity hours — not their content, but their map. It is a dependency and observation risk, not a disclosure risk.
Can Europe do without Google and Cloudflare for time?
Yes, technically without compromise. Our registry measures 192 machines serving authenticated time over NTS in Europe as of 7 August 2026, held by 42 distinct operators across several countries. It is therefore possible to build a fully European chrony configuration, authenticated with NTS, across several independent operators — which is good practice anyway: you never base a clock on a single source, sovereign or not.
Which European NTP servers are run by European operators?
Our registry names them one by one, with their measured stratum and their NTS status verified from 6 networks: 42 European operators serve NTS, among them national metrology institutes (PTB in Germany, ROA in Spain, BEV in Austria, DFM in Denmark), research networks (SWITCH, University of Strasbourg) and private operators (Netnod, RDEM Systems, Hetzner, SIDN Labs, Nothing to hide). Two absences are deliberate, and they show what a declarative list cannot. METAS, in Switzerland, announces and serves NTP only: its stratum 1 servers answer from all six of our observation points, port 4460 stays silent. The University of Zagreb (UNIZG FER REMLAB) announces NTS and has genuinely deployed it — its NTS-KE succeeds from all 6 of our probes — but only 3 of our probes obtain authenticated time: the other 3 get nothing. NTS there works or does not depending on which network you ask from, and that is why we do not count it. Their operational log records, on 18 March 2026, a revalidation of the NTS-KE configuration «to improve availability and compatibility»: the work is under way on their side, and as of 7 August 2026 it is not settled from our observation points. For the 17 countries where we found no NTS at all, the registry also names the institute or network that serves stratum 1 there without authentication. The full list is published as CSV and JSON under CC BY 4.0.
- Enable NTS on Chrony in 5 minutes — client-side configuration and verification
- NTP stratum levels — the 16 levels and typical accuracy
- Our NTP infrastructure — technical detail of the stack
- RDEM ASN record — AS206014 and peering policy
- NIS2 and backup compliance — for the immutability layer of journals
Free NTP Tools
Three independent tools to diagnose your time synchronization:
Is sovereignty measured at the last link?
A French authenticated server whose source is out of sight raises a question this page does not settle. It is taken up, with figures, in must NTS be proven end to end?