Networking · Concept · 9 min read

NTP Stratum, How Far a Server Is From the Clock

An NTP stratum is a number for how many network hops a time server sits from the reference clock. Here are the levels, from stratum 0 down to the unsynchronized 16.

Written by Marko Ristic, Editor Updated Sep 17, 2026
0the reference clock: atomic, GPS or radio
1the primary server attached to a stratum 0 device
15the highest usable stratum number
16means unsynchronized: no valid time source
Short answer

An NTP stratum is a number that says how many steps a time server is from the reference clock at the top of the hierarchy. The Network Time Protocol arranges time sources in layers, each a stratum, counted from zero.

Stratum 0 is the reference clock itself, an atomic clock, GPS receiver or radio clock, not reached over the network. Stratum 1 is a server directly attached to a stratum 0 device; stratum 2 syncs over the network to stratum 1, and so on.

Every hop away from the reference adds one, so a server syncing to a stratum n server becomes stratum n plus one. The scale runs 0 to 15, and stratum 16 means unsynchronized.

  • An NTP stratum is how many hops a server is from the reference clock
  • Stratum 0 is the reference clock; stratum 1 is directly attached to it
  • Each network hop adds one to the stratum number
  • The range is 0 to 15; stratum 16 means unsynchronized
  • Lower is closer to the source, though not automatically more accurate
On this page

What NTP isWhat NTP is

The stratum only makes sense once the protocol behind it is clear.

NTP synchronizes clocks over the network. The Network Time Protocol is a protocol for clock synchronization between computer systems over packet-switched, variable-latency networks. It was designed by David Mills at the University of Delaware and has been in operation since before 1985, making it one of the oldest internet protocols still in daily use.

It runs over UDP port 123. A client asks a server for the time, the server answers, and NTP corrects for the round-trip delay so the client can set its clock accurately despite the network in between. The exchange uses UDP port 123.

It is built as a hierarchy. Rather than every device querying one central clock, NTP spreads the load across a tree of servers, each one a step further from the reference. The stratum number is how that tree is labeled.

The hierarchyThe NTP stratum hierarchy

The word stratum is just the name for a level in that tree.

Each level is a stratum, counted from zero. NTP uses a hierarchical, semi-layered system of time sources. Each level of the hierarchy is termed a stratum and is assigned a number, starting with zero for the reference clock at the top. The number is the distance from the source, not a quality score.

The number grows with each hop. A server synchronized to a stratum n server runs at stratum n plus one. So a server that gets its time from a stratum 1 server is stratum 2, one that syncs to that is stratum 3, and so on down the tree.

The range is fixed. The upper limit for stratum is 15. Stratum 16 is used to indicate that a device is unsynchronized, meaning it has no valid time source and should not be trusted as one.

Where the NTP stratum is carried

The NTP stratum is not a setting somebody types in. It is a field in every NTP packet, and RFC 5905 defines it as an 8-bit integer: 1 for a primary server, 2 to 15 for a secondary server, and 16 for unsynchronized. A value of 0 in a packet means unspecified or invalid.

Each NTP server reads the stratum of the source it selected, adds one, and advertises the result to its own clients.

Next to the stratum field sits the reference ID. RFC 5905 says a stratum 1 server puts a short code for its reference clock there, such as GPS, and servers above stratum 1 put the identifier of their upstream server, which can be used to detect timing loops.

The levelsThe stratum levels

Each level has a clear role, and the top three are the ones worth knowing.

Stratum 0 is the reference clock. These are high-precision timekeeping devices such as atomic clocks, GNSS receivers including GPS, or radio clocks. They generate a very accurate signal but are not reached directly over the network; they attach to a stratum 1 computer.

Stratum 1 is the primary server. A stratum 1 server has its system time synchronized to within a few microseconds of its attached stratum 0 device. These are the primary time servers, and they may peer with other stratum 1 servers as a sanity check and backup.

Stratum 2 and below are downstream. A stratum 2 server syncs over the network to one or more stratum 1 servers, and can itself serve stratum 3 clients, which serve stratum 4, and so on. Most organizations run their internal servers at stratum 2 or 3, syncing up to public stratum 1 or 2 servers.

Public pools such as the NTP pool project hand out a rotating set of these upstream servers, which is why a typical client ends up at stratum 3 or 4 without anyone building the hierarchy by hand.

Checking itHow to check the stratum of an NTP server

Every NTP daemon reports the stratum of the local system clock and of each time server it follows. Three commands cover most systems.

SystemCommandWhere the stratum shows
Linux or BSD with ntpdntpq -pThe st column, one row per time server
Linux with chronychronyc trackingThe Stratum line for the local system
Linux with chronychronyc sourcesThe Stratum column, one row per source
Windowsw32tm /query /statusThe Stratum line

Read the result against the hierarchy. A client of an internal NTP server that follows a public stratum 2 server should report stratum 4. If it reports 16, the local NTP daemon has no usable source, and the usual causes are UDP port 123 blocked at a firewall or a wrong server name.

In a Windows domain the hierarchy builds itself. Member computers take network time from a domain controller, and domain controllers follow the one holding the PDC emulator role. That makes the PDC emulator the one machine that needs an external NTP server, as covered under Active Directory.

One stratum value deserves suspicion. An NTP server can be configured to fall back to its own local clock when every upstream source is lost, conventionally at a high stratum such as 10. Clients still get an answer, but the network time they follow is only one machine drifting.

Why it mattersWhy the NTP stratum number matters

The stratum tells you something useful, as long as you read it correctly.

Lower is closer to true time. A lower stratum means fewer hops between the server and the reference clock, so less network delay and jitter has accumulated along the way. Stratum 1 is as close as a networked server gets to the source.

But lower is not automatically more accurate. A well-connected stratum 3 server on a stable network can hold better time than a stratum 2 server across a congested link. The stratum measures distance from the reference, not the quality of the path, so it is a guide rather than a guarantee.

Design for a low, stable stratum. For most networks the goal is not the lowest possible stratum but a low and stable one: internal clients syncing to a couple of reliable internal servers, which sync to several good upstream servers, so no single failure jumps everyone to stratum 16.

Two or three internal servers, each with several upstream sources, is the shape most estates settle on.

Keeping timeHow NTP keeps a clock accurate

The stratum decides where time comes from; these mechanisms decide how accurately each computer follows it.

It measures the round trip. The client timestamps its request, the server timestamps when it receives and answers, and the client timestamps the reply. From those four times NTP works out both the network delay and the offset between the two clocks, which is how synchronization stays accurate over a variable-latency network.

It adjusts the clock gradually. Rather than jumping the system time, NTP usually slews the clock, speeding it up or slowing it slightly until it matches, so time never runs backward on the computer. A large initial offset may be stepped once at startup.

It polls repeatedly. A client polls its time servers at intervals, from tens of seconds to many minutes, and keeps refining the offset, because every clock drifts and the network delay between the devices changes over time.

When several servers are configured, NTP compares them and discards any that disagree, so one bad source does not pull the client off the correct time.

The current version is NTPv4. NTP version 4, defined in RFC 5905, is the version in general use. It improved accuracy over earlier versions and added support for IPv6, while keeping the same stratum hierarchy and protocol model.

Network Time Security, defined in RFC 8915, adds authentication of the time server and leaves the NTP stratum levels unchanged.

PitfallsWhere people go wrong

Reading stratum as an accuracy rating. It is a distance count, not a quality score. A stratum 2 server is not guaranteed to be more accurate than a stratum 3 server; it is just fewer hops from the reference.

Chasing stratum 1 unnecessarily. Most organizations do not need to run their own stratum 1 hardware. Syncing internal servers to reliable public servers at stratum 1 or 2, and clients to those, is accurate enough for almost everything.

Ignoring stratum 16. A device showing stratum 16 is unsynchronized and its time cannot be trusted. Treating it as a working time source is a common and damaging mistake, because everything below it inherits the problem.

Building a single point of failure. If every client syncs to one internal server and that server fails or loses its upstream, the whole estate drifts or jumps to unsynchronized. Multiple time sources at each level keep the hierarchy resilient.

Confusing NTP with PTP. For sub-microsecond precision, PTP is the tool, not NTP. NTP is accurate to milliseconds over a network, which is fine for logs and authentication but not for the tightest timing needs.

NTP STRATUM: DISTANCE FROM THE REFERENCE CLOCKStratum 0the reference clock: atomic, GPS or radio, not networkedStratum 1primary server, directly attached to a stratum 0 deviceStratum 2syncs over the network to stratum 1 serversStratum 3 to 15each syncs to the level above, one hop further outStratum 16unsynchronized: no valid source, do not trust+1 pernetworkhopLower is closer to the source, not automatically more accurate; NTP runs over UDP port 123.
The NTP stratum ladder: stratum 0 is the reference clock, stratum 1 is attached to it, and each network hop down adds one, until stratum 16, which means unsynchronized. Lower is closer to the source, not automatically more accurate.

ComparisonThe NTP stratum levels at a glance

CriterionWhat it isReached over the network
Stratum 0Reference clock: atomic, GPS, radioNo, attached to stratum 1
Stratum 1Primary server on a stratum 0 deviceYes, the top networked level
Stratum 2Syncs to stratum 1 serversYes
Stratum 3 to 15Each syncs to the level aboveYes
Stratum 16Unsynchronized, no valid sourceNot a usable source

The pattern is the whole idea: zero is the clock, one is attached to it, and every number after that is one more network hop away, until 16 says there is no source at all.

FAQFrequently asked questions

What is an NTP stratum?

A number that indicates how many steps a time server is from the reference clock at the top of the NTP hierarchy. Stratum 0 is the reference clock, stratum 1 is directly attached to it, and each network hop away adds one to the number.

What is stratum 0 in NTP?

The reference clock itself: a high-precision device such as an atomic clock, a GPS or other GNSS receiver, or a radio clock. Stratum 0 devices are not reached over the network; they attach directly to a stratum 1 server.

What is a stratum 1 NTP server?

A server whose time is synchronized to within a few microseconds of an attached stratum 0 device. Stratum 1 servers are the primary time servers, the closest networked source to the reference clock.

How is the stratum number decided?

By counting hops from the reference. A server that synchronizes to a stratum n server runs at stratum n plus one. So syncing to a stratum 1 server makes a server stratum 2, and so on down the tree.

What is the maximum NTP stratum?

The usable range is 0 to 15. Stratum 16 is a special value that means a device is unsynchronized and has no valid time source, so it should not be used as one.

Does a lower stratum mean more accurate time?

Not automatically. A lower stratum means fewer hops from the reference, so less accumulated network delay, but a well-connected higher-stratum server can hold better time than a poorly connected lower-stratum one. Stratum measures distance, not path quality.

What stratum should my servers be?

Most organizations run internal servers at stratum 2 or 3, syncing up to reliable public stratum 1 or 2 servers, with clients syncing to the internal servers. A low, stable stratum with redundancy matters more than the lowest possible number.

What port does NTP use?

UDP port 123. A client sends a request to a server on that port, and the server replies with the time, with NTP correcting for the round-trip delay.

What does stratum 16 mean?

That the device is unsynchronized: it has no valid time source and its clock cannot be trusted. Anything syncing to a stratum 16 device inherits the lack of a source.

Do I need my own stratum 1 server?

Usually not. Running stratum 1 hardware means attaching a GPS or radio clock, which few organizations need. Syncing to reliable public servers at stratum 1 or 2 is accurate enough for logging, authentication and most operations.

What is the difference between NTP and PTP?

NTP synchronizes clocks to within milliseconds over ordinary networks and uses the stratum hierarchy. PTP, the Precision Time Protocol, targets sub-microsecond accuracy for demanding applications and uses different mechanisms. NTP is the general-purpose choice; PTP is for the tightest timing.

Can a stratum 1 server fail over to another source?

Stratum 1 servers often peer with other stratum 1 servers as a sanity check and backup, and a server can sync to several sources, so if one path fails it uses another rather than jumping to unsynchronized.

Read next · Protocols PTP, NTP, and Why a Clock Breaks Authentication First The precision time protocol for sub-microsecond accuracy, where NTP is not enough. Open this next10 min
Also worth reading
One packet a weekA short, illustrated explainer every Tuesday. No vendor pitches, unsubscribe in one click.