ICDM · Timing Assurance Framework

The ICDM Timing Assurance Framework

Most organisations cannot say how much they depend on satellite timing, what happens when it degrades, or whether they could prove afterwards that it held. MAP grades all three, and shows you where you stand against a national study of 1,000 UK infrastructure respondents.

Measure what you rely on. Address what you find. Prove it holds.

Take the assessmentSix questions, no email required.Read the evidence

The problem this exists to solve

Timing is infrastructure that almost nobody owns.

Satellite timing sits underneath trading systems, payment clearing, network synchronisation, substation protection and data centre operations. It arrives free, it works, and it is treated as a fact of the environment rather than as a dependency with a failure mode. It can be jammed. It can be spoofed. Neither requires sophistication.

The result is a gap that operational resilience work has largely missed. Organisations have mapped their important business services in detail and left out the one input that every timestamp in them depends on.

MAP names that gap and measures it.

What MAP is

Three stages. Six domains. Four levels. It fits on one page and a compliance officer recognises every word in it.

MEASUREwhat do we rely on and what does it cost us

Dependency. Where does precise time enter our operations, including through third parties, and do we understand that those signals can be deliberately attacked?

Tolerance. What fails when time degrades, how badly, and how long could we keep operating?

ADDRESSwhat have we done about it

Ownership. Does a named function own this, with the authority and the budget to act?

Detection. Would we know an interference event was happening while it was happening, and do we know what to do about it?

PROVEwhat can we demonstrate

Testing. Have we tested, on a cycle, against a threat picture kept current?

Evidence. Could we demonstrate afterwards that our timing held?

Why these six, and in this order

Ownership opens Address, and that is the central argument. Cyber risk became governable when it converged on the CISO, and that convergence is what made it fundable and testable. Nothing in Address or Prove moves until someone owns timing. It is the hinge of the whole framework.

Testing sits in Prove, not Address. Testing is not a control you install. It is how you demonstrate a control works. Grouping it with Evidence puts the two things the market is worst at in the same stage, and makes the final stage the one that actually bites.

Six domains, not eight. Third party dependency belongs inside Dependency, because that is what it is. Holding a GNSS independent time source belongs inside Tolerance, because that is what it buys you. Neither needed its own box.

The four levels

NumberLevelWhat it means
0UnexaminedThe question has not been asked. Not weighed and accepted. Never looked at.
1RecognisedAcknowledged as mattering. No figure exists that anyone could state.
2QuantifiedDocumented, with a number and a source behind it.
3AssuredDemonstrated, on a cycle, and current.

The line that does the work is between 1 and 2, and it is whether a figure exists. Below it, an organisation has opinions about its timing dependency. Above it, it has measurements.

Four levels, not five. Five level models exist so that everyone has a middle to sit in. Our finding is that most organisations are at level 0, and a model that lets them feel like a 3 out of 5 while never having examined the question defeats itself.

The grid

Measurewhat do we rely on and what does it cost us

1Dependency

Where does precise time enter our operations, including through third parties, and do we understand that those signals can be deliberately attacked?

  1. 0 · Unexamined

    Nobody has asked where precise time enters the organisation.

    Market position

    Nobody has asked where precise time enters the organisation. Nationally, 34.9% rely critically or heavily on GNSS timing, and 43.3% were only vaguely aware, or entirely unaware, that those signals can be deliberately jammed or spoofed.

  2. 1 · Recognised

    Timing is known to matter. No inventory exists.

    Market position

    Timing is known to matter, but no inventory exists. You are ahead of the awareness gap: 43.3% nationally were only vaguely aware, or entirely unaware, that these signals can be attacked.

  3. 2 · Quantified

    A documented inventory of timing dependent systems and services, including those delivered by third parties.

    Market position

    You hold a documented inventory including third party services. Nationally, 14.2% say core operations would fail without GNSS timing, and almost none of them can show which ones.

  4. 3 · Assured

    The inventory is maintained on a cycle and reconciled against the important business services map.

    Market position

    Your inventory is maintained and reconciled against your important business services map. This is the position the operational resilience regime assumes every firm already holds.

2Tolerance

What fails when time degrades, how badly, and how long could we keep operating?

  1. 0 · Unexamined

    No view of what fails, or how quickly.

    Market position

    No view of what fails, or how quickly. Nationally, 17.0% cannot say what a 24 hour loss would mean, and 46.1% either could keep operating only a few hours, or could not say.

  2. 1 · Recognised

    Degradation is understood to be damaging. No figure exists.

    Market position

    Degradation is understood to be damaging, but no figure exists. Nationally, 29.9% rate a 24 hour loss as serious or catastrophic without a stated window behind that judgement.

  3. 2 · Quantified

    A stated operating window per service, and any GNSS independent source documented.

    Market position

    You have a stated operating window per service. Only 10.2% nationally hold a GNSS independent source at all.

  4. 3 · Assured

    The window is derived from observed behaviour rather than estimate, and independent sources have actually been failed over to.

    Market position

    Your window is derived from observed behaviour and you have failed over in practice. Fewer organisations have proven a failover than hold an independent source, so this position is rarer than the 10.2% figure suggests.

Addresswhat have we done about it

3Ownership

Does a named function own this, with the authority and the budget to act?

  1. 0 · Unexamined

    No owner, or assumed to sit with IT without IT having accepted it.

    Market position

    No owner, or an assumption that IT holds it without IT having accepted it. Nationally, 16.1% can identify no owner at all, and 46.9% place it with IT.

  2. 1 · Recognised

    A function is named.

    Market position

    A function is named, but without budget or a reporting route. This is where most of the market sits. Nationally 46.9% name IT, and only 19.9% place it with a risk professional of any kind.

  3. 2 · Quantified

    Named owner with defined scope, a budget line and a reporting route.

    Market position

    A named owner with defined scope, a budget line and a reporting route. Only 8.9% nationally say a resilience function owns timing.

  4. 3 · Assured

    The owner reports on a cycle, and timing sits inside the organisation's resilience governance rather than beside it.

    Market position

    The owner reports on a cycle and timing sits inside resilience governance. This is the convergence that made cyber risk fundable, applied to timing.

4Detection

Would we know an interference event was happening while it was happening, and do we know what to do about it?

  1. 0 · Unexamined

    No means of knowing.

    Market position

    No means of knowing. Nationally, 50.1% are not confident they would detect a jamming or spoofing event.

  2. 1 · Recognised

    Some monitoring exists. Its coverage is unknown.

    Market position

    Some monitoring exists, but its coverage is unknown. Confidence without documented coverage is what the national 13.3% very confident figure is largely made of.

  3. 2 · Quantified

    Coverage documented, thresholds defined, alerts routed to a named recipient with a defined response action.

    Market position

    Coverage, thresholds and routing are documented, with a defined response. Only 13.3% nationally are very confident they would detect an event, and few of those could show why.

  4. 3 · Assured

    Detection and response demonstrated against a live or simulated event, within a stated time to detect.

    Market position

    Detection and response demonstrated against a live or simulated event within a stated time to detect. This is what confidence looks like when it is earned.

Provewhat can we demonstrate

5Testing

Have we tested, on a cycle, against a threat picture kept current?

  1. 0 · Unexamined

    Never tested.

    Market position

    Never tested. You are with the 42.9% nationally who have never tested, inside the 61.0% with no completed test.

  2. 1 · Recognised

    Testing planned, not done.

    Market position

    Testing is planned but not done. Planned and done are separated by 61.0% of the market having no completed test at all.

  3. 2 · Quantified

    At least one completed test against a defined interference scenario, with results recorded.

    Market position

    At least one completed test against a defined interference scenario. That places you ahead of roughly six in ten organisations nationally.

  4. 3 · Assured

    Testing on a defined cycle against a current threat picture, with findings tracked to closure.

    Market position

    You test formally and regularly, which puts you in the 8.2% nationally who do. Whether the threat picture is current and findings are tracked to closure is what separates a provisional level 3 from a confirmed one.

6Evidence

Could we demonstrate afterwards that our timing held?

  1. 0 · Unexamined

    Nothing could be demonstrated.

    Market position

    Nothing could be demonstrated. Nationally, only 7.1% are very confident they could prove to a regulator or auditor that their timing remained accurate.

  2. 1 · Recognised

    Some records exist. Completeness unknown.

    Market position

    Some records exist, but completeness is unknown. Nationally, 49.0% understand their obligations here not very well or not at all.

  3. 2 · Quantified

    Timing records retained and traceable to UTC, sufficient to reconstruct a period.

    Market position

    Timing records retained and traceable to UTC, sufficient to reconstruct a period. Traceability to UTC is the explicit requirement under MiFID II RTS 25.

  4. 3 · Assured

    An evidence pack produced and tested against a real request from a regulator, auditor, customer or incident.

    Market position

    An evidence pack produced and tested against a real request. Only 7.1% nationally are very confident they could do this, and confidence is not the same as having done it.

Where the market actually sits

Every domain carries a measured national position, from a study of 1,000 UK respondents in financial services and data centre infrastructure. An organisation using MAP does not only learn where it stands. It learns where it stands against everyone else.

DomainNational position
Dependency34.9% rely critically or heavily on GNSS timing, and 14.2% say core operations would fail without it. Yet 43.3% were only vaguely aware, or entirely unaware, that those signals can be deliberately jammed or spoofed.
Tolerance29.9% rate a 24 hour loss serious or catastrophic, and 17.0% cannot say what the impact would be. 10.2% hold a GNSS independent source. 34.8% put their operating window at about a day. 46.1% either could keep operating only a few hours, or could not say.
Ownership46.9% place the risk with IT. Only 19.9% place it with a risk professional of any kind. 16.1% can identify no owner at all. 19.2% work in a resilience function, but only 8.9% say such a function owns timing.
Detection50.1% are not confident they would detect a jamming or spoofing event. Only 13.3% are very confident.
Testing61.0% have no completed test. 42.9% have never tested. Only 8.2% test formally and regularly.
EvidenceOnly 7.1% are very confident they could prove to a regulator or auditor that their timing remained accurate. 49.0% understand their obligations not very well or not at all.

Source: Running Blind, ICDM Research Report 01. Base 1,000, unweighted, distributions published in full.

The stall point

Read that table down the column and the pattern is unmistakable.

The market has largely measured, barely addressed, and has not reached prove. Dependency is broadly recognised. Almost nothing downstream has been done about it.

And it stalls at the first domain of Address. With the risk parked in a function that has neither claimed it nor been resourced for it, there is nobody whose job it is to move the rest. Detection is not built, testing is not commissioned, and evidence is not retained, because none of those is anyone's objective.

That is a diagnosis, not a scolding. It also points at the cheapest available move. Getting Testing from level 1 to level 2 is a single test. No reorganisation, no new function, no capital programme. It produces three things an organisation does not currently have: a quantified exposure, a measured tolerance, and a baseline to improve against.

What each domain answers to

MAP is not a parallel structure competing with operational resilience obligations. It is those obligations, applied to a dependency most organisations have left out of them. Mapping, impact tolerances, severe but plausible scenarios. That is the regulator's language, not ours.

DomainThe obligation it serves
DependencyIdentification and mapping of important business services, and the people, processes, technology, facilities and data that deliver them. FCA PS21/3 and PRA SS1/21. Third party dependency also engages DORA and the Critical Third Parties regime.
ToleranceSetting impact tolerances, the same regime's central obligation.
OwnershipSenior manager accountability, and ICT risk management governance under DORA.
DetectionIncident identification, feeding the FCA, PRA and Bank of England operational incident reporting regime.
TestingTesting that services remain within impact tolerance under severe but plausible scenarios. PS21/3. Sustained GNSS interference is both severe and plausible.
EvidenceClock synchronisation traceable to UTC under MiFID II RTS 25, plus audit trail and incident reporting obligations.

An organisation that mapped its important business services without mapping its timing dependency has an incomplete map, and the transitional period for completing that work has closed.

How MAP is scored

Three views of the same six numbers. None of them is ever shown alone.

The MAP Score is the sum of the six domain levels, out of 18, with a sub score out of 6 for each stage. It rewards capability wherever it sits, and it is what you track year on year.

The position is named by the first stage you have not completed: Unexamined, Measuring, Measured, Addressing, Addressed, Proving, Assured. A stage is complete when both its domains are at level 2 or above. Unlike the score, position is sequenced, because monitoring that cannot be scoped against an inventory is capability rather than assurance.

The profile is the grid. Six domains at four levels, with the market position beside every one, so each gap comes with a comparison rather than a judgement.

Reported together, always, in this form:

MAP Score 9 / 18 · Measuring

There is no single percentage. An organisation at Measure 2 of 2 and Prove 0 of 2 has a specific, nameable problem. An organisation on 58% has nothing.

Scope, and what MAP does not claim

MAP grades timing assurance, not incident response. Response is captured within Detection at levels 2 and 3. Organisations needing a full incident response maturity assessment should look to established operational resilience frameworks alongside MAP.

MAP covers timing, not the whole of PNT.For positioning and navigation, and for recovery after a disruption, the Royal Institute of Navigation's Resilient PNT best practices remain the reference. MAP is built on that guidance rather than beside it. Its Prepare stage is where most of MAP sits, and MAP has no equivalent of its Recover stage.

MAP is derived from self reported positions, not audit evidence. It is a diagnostic and a benchmark. It is not an audit standard.An assessment result attests that an assessment was completed and produced a given profile. It does not attest that an organisation's timing is resilient. Evidence for that comes from actual testing by a competent test provider.

Find your position

Six questions, one per domain. No email required, and none requested.

The ICDM Timing Assurance Framework (MAP: Measure, Address, Prove) is published by the Institute of Critical Infrastructure Decision Making, a trading name of Direct Intelligence Ltd, company number 16278923. The framework, its level descriptors and its assessment may not be reproduced or adapted without permission.

Report 01, Running Blind, is available in full at /icdm/research/running-blind. The senior practitioner study is written directly against these level descriptors and aims to show how MAP scores are distributed across the sectors and regions of UK infrastructure.

Testing services: pnt.directintelligence.co.uk