From rule to reality in Indian Standard Time

By Dr. Amutha Arunachalam

My earlier article argued that a common national time must also be verifiable. The next question is practical: who must do what, and how will a citizen know that a timestamp can be trusted? The Legal Metrology (Indian Standard Time) Rules, 2026, notified on 27 August 2026, establish the framework.

Rule 1 provides for commencement after 180 days from publication in the Official Gazette. Their stated duties must be distinguished from operational details left to competent authorities and from improvements proposed for effective implementation.

This distinction matters to everyone. A citizen contesting a digital payment, an online filing deadline or a ticketing record needs a timestamp that can be trusted. A policy maker needs rules that can be implemented consistently across sectors. A service provider needs to know the conditions for authorisation.

A bank, telecom network, power utility or data centre needs measurable requirements for accuracy, redundancy, security, evidence and audit. If these questions are answered by informal practice or vendor claims, India may have one legal time but many incompatible interpretations of compliance.

The simplest way to read the new regime is to ask two questions: What has the Gazette already decided? What must the competent authority still specify?

What the Gazette already decides
First, the Gazette identifies the national reference. CSIR National Physical Laboratory maintains UTC(NPLI) and realises IST by adding five hours and thirty minutes. IST is the official time scale for civil, commercial and legal purposes in India. Legal Metrology is responsible for secondary time scales at the Regional Reference Standards Laboratories and for compliance oversight. [Rules 2(f), 5(3), 5(5), 10(4)]

Second, it creates a controlled dissemination chain. CSIR NPL, RRSLs, ISRO and other authorised timing sources shall disseminate UTC(NPLI) and IST through official time and frequency services.

Critical sectors must use an authorised source traceable to UTC(NPLI). The Rules recognise Network Time Protocol (NTP), Precision Time Protocol (PTP), India’s NavIC satellite navigation system and other authorised means; they also require the Director of Legal Metrology to publish and maintain the relevant addresses or access protocols. [Rules 5(4), 8(2), 8(4)–(5)]

Third, it fixes responsibility at both ends. An authorised source must maintain accuracy and traceability. But the organisation receiving the signal remains responsible for accuracy, stability and traceability within its own systems. End users must monitor deviations, retain auditable data and be able to demonstrate their connection to the national time standard. Merely pointing a server at a time source is not proof of compliance. [Rules 6(3)–(5)]

Fourth, the Gazette makes resilience and security part of legal time. End entities must employ redundancy. Organisations must maintain contingency plans for disruptions such as jamming, spoofing and cyberattacks. Critical infrastructure has additional multi source obligations involving NavIC or another authorised source, and users must be able to maintain timing during reference input failure. [Rule 9]

Finally, periodic audits and enforcement are not optional. RRSLs and authorised timing sources are subject to audit for traceability and availability. The Legal Metrology Division oversees compliance, and breaches of the Rules, directions or orders made under them may be dealt with under the Legal Metrology Act after inquiry by the Director or an authorised officer. [Rules 10–11]

Where later directions are still essential
Three categories must be kept separate. The Gazette states duties, such as traceability and redundancy. It expressly leaves some details to official specification, including authorisation requirements, service addresses and security standards. Other measures advocated here, such as a public register, purpose-based accuracy classes and standard audit methods, are recommendations for making the framework workable; they are not requirements already specified in the Gazette. The absence of numerical limits in the Gazette does not establish that no later or sector-specific direction exists.

Where later directions are still essential
Three categories must be kept separate. The Gazette states duties, such as traceability and redundancy. It expressly leaves some details to official specification, including authorisation requirements, service addresses and security standards.

Other measures advocated here, such as a public register, purpose-based accuracy classes and standard audit methods, are recommendations for making the framework workable; they are not requirements already specified in the Gazette. The absence of numerical limits in the Gazette does not establish that no later or sector-specific direction exists.

Topic

Stated in the Gazette

Further specification or recommended action

Authorisation

Timing sources require authorisation by the Director of Legal Metrology and may be suspended or revoked after an opportunity to be heard. [Rule 2(c)]

Official specification: Eligibility, application, technical assessment, validity, renewal, scope, public register and status verification.

Accuracy

Accuracy means conformity to UTC(NPLI) or IST; systems and public displays must be synchronised with accuracy. [Rule 2(a), 8(3)–(4)]

Recommended clarification: Numerical classes or tolerances by use and sector, including uncertainty, offset, holdover and reporting thresholds.

Traceability

Sources must be traceable and end entities must monitor deviations and maintain auditable data. [Rule 6(3)–(5)]

Recommended clarification: The evidence chain, record format, retention period, tamper protection, calibration intervals and acceptable proof.

Audit

Periodic compliance audits are required; RRSLs and authorised sources are expressly covered. [Rule 10]

Recommended clarification: Audit frequency, scope, methodology, auditor competence and independence, sampling, reporting, remediation and retesting.

Dissemination

NPL, RRSLs, ISRO NavIC, NIC and other authorised sources are recognised; NTP and PTP are named protocols. [Rule 5(4), 8]

Official specification: Official endpoints, access profiles, authentication, onboarding, service availability, geographic coverage and any subscription fee.

Security

Cybersecurity controls, secure hardware and software, contingency planning and protection against spoofing, jamming and attack are required. [Rule 9(1), 9(3)–(5)]

Official specification: The detailed control baseline, incident reporting, testing, key management, supply chain controls and coordination with sector regulators.

Continuity

Redundant timing is required and critical infrastructure has multi source obligations; reference failures must be addressed. [Rule 9(2), 9(6)–(9)]

Recommended clarification: Minimum availability, failover time, holdover performance, monitoring frequency, recovery objectives and service level assurance.

Enforcement

Breaches may be punished under the Act after inquiry by the Director or an authorised officer. [Rule 11]

Recommended clarification: Inspection and notice procedure, evidence rules, remediation windows, risk based escalation, coordination, review and appeal pathways.

Why the distinction protects citizens
Consider a payment recorded at 10:00:00. The number alone tells us very little. Which source supplied that time? Was the source authorised? How far was the payment server from IST at that moment? Did the server lose its primary reference and switch to a backup? Was the backup traceable? Were the event logs protected from alteration? Which accuracy requirement applied to that transaction? A trustworthy timestamp is not simply a clock reading; it is a clock reading supported by evidence.

For the common citizen, this evidence matters when time determines a right, liability or sequence of events. It may decide whether an online application met a deadline, which of two transactions occurred first, whether a transport or emergency record is reliable, or whether digital evidence from different systems can be aligned during a cyber investigation. Citizens should not have to understand atomic clocks or network protocols. They should be entitled to institutions that can prove where their time came from and how it was controlled.

What policy makers should complete during implementation
The implementation period should produce a coordinated package rather than isolated circulars. At minimum, India needs a transparent authorisation scheme and public registry; approved purpose based accuracy classes; a traceability and evidence specification; a common audit and assurance model; published endpoints and access conditions; security and continuity baselines; and a clear enforcement process aligned with natural justice. Sector regulators may add safeguards for banking, power, telecom, transport or other critical services, but those safeguards should remain consistent with one national definition of IST and one traceability chain.

A proportionate approach is essential. A railway display, an e governance portal, a securities trading system and a power grid protection device do not need identical precision. The competent authority should therefore connect accuracy, availability, holdover, redundancy and audit intensity to the risk and purpose of the system. This will prevent both under protection of critical services and unnecessary cost for ordinary uses.

Policy makers should also publish a clear transition pathway. Organisations need to inventory time dependent systems, identify present sources, test primary and backup paths, record deviations, review incident and retention practices, and assign accountable officers. The date of legal commencement should be communicated unambiguously, along with how organisations will be treated while authorised services, endpoints and detailed specifications are being rolled out.

How the whole system protects the citizen
Read the rows from the national reference to the service used by the citizen. Oversight applies across the chain. The last column describes intended benefits, not a guarantee of the outcome of any dispute.

Responsibility

Required contribution

Citizen benefit

National reference
CSIR–NPL

Maintain UTC(NPLI), realise IST and preserve traceability to UTC.
Rules 5(3), 10(3)

A consistent national basis for time.

Authorised source

Disseminate a traceable signal and maintain its accuracy.
Rules 5(4), 6(3)–(4)

Institutions can obtain time from a recognised source.

Service operator
The end entity

Maintain system accuracy, stability and traceability; monitor deviations and keep auditable data.
Rules 6(4)–(5)

Payment and deadline records can be checked against evidence.

Continuity controls

Provide redundant timing and contingency arrangements for disruption.
Rule 9

Essential services are better prepared for timing failures.

Oversight across the chain

Periodic audits and Legal Metrology compliance oversight; inquiry and penalties under the Act.
Rules 10–11

Failures can be investigated and responsibility established.

The next test is proof
India has moved beyond treating time as a background utility. The Gazette recognises trusted time as infrastructure for governance, commerce, critical systems and public confidence. The next test is not whether a clock displays IST. It is whether the complete path from UTC(NPLI) to the final timestamp can be explained, measured, audited and defended.

My earlier article called for one verifiable standard. This follow up makes the immediate task clear: implement what the Gazette already requires, and issue the remaining directions openly, consistently and before uncertainty hardens into practice. One Nation One Time will serve citizens only when every important timestamp rests on one transparent chain of authority, traceability, accountability and proof.

Comments (0)
Add Comment