>
Home5G NRMAC — Medium Access ControlTiming Advance
🧩 MAC — Medium Access ControlIntermediate

Timing Advance in 5G NR

Why uplink timing must be advanced, how it's acquired at RACH (RAR) and maintained by the MAC via the Timing Advance Command MAC CE and timeAlignmentTimer.

📚 3GPP-basedTS 38.321TS 38.213

In the downlink the gNB is the only transmitter, so everything it sends is aligned by construction. The uplink is the opposite: dozens of independent transmitters share one resource grid, and each one is a different distance away. Radio travels at roughly 300 m per microsecond, so a UE 9 km out and a UE 300 m out are separated by about 29 µs of one-way delay. If both simply transmitted at what their own clocks believe is the slot boundary, their symbols would arrive at the gNB tens of microseconds apart — far more than one cyclic prefix — and the FFT the receiver runs over symbol l would contain fragments of symbol l−1 from one UE and symbol l+1 from another.

Contents
  1. 01Why Uplink Time Alignment Exists
  2. 02The gNB Receive Window and the Cyclic Prefix Budget
  3. 03T_c, N_TA, and the Formula That Ties Them Together
  4. 04Granularity and Range, Numerology by Numerology
  5. 05The Initial Value: the 12-Bit Timing Advance Command in the RAR
  6. 06Maintaining It: the Timing Advance Command MAC CE
  7. 07N_TA_offset: the Constant the UE Also Subtracts
  8. 08How the gNB Measures the Error, and How Often It Corrects
  9. 09Timing Advance Groups: pTAG, sTAG and Carrier Aggregation
  10. 10timeAlignmentTimer and the Cost of Expiry
  11. 11Worked Arithmetic, End to End
  12. 12Non-Terrestrial Networks: When 12 Bits Are Not Enough
  13. 13Parameter Reference: ASN.1, Ranges and Effects
  14. 14Timers and Counters
  15. 15Failure Modes and What Each One Means
  16. 16ASN.1 Extracts
  17. 17Illustrative Message Traces
  18. 18Release Deltas: Rel-15 to Rel-18
  19. 19Reading Timing Advance in Logs: A Checklist
  20. 20Glossary
  21. 21References

1. Why Uplink Time Alignment Exists

In the downlink the gNB is the only transmitter, so everything it sends is aligned by construction. The uplink is the opposite: dozens of independent transmitters share one resource grid, and each one is a different distance away. Radio travels at roughly 300 m per microsecond, so a UE 9 km out and a UE 300 m out are separated by about 29 µs of one-way delay. If both simply transmitted at what their own clocks believe is the slot boundary, their symbols would arrive at the gNB tens of microseconds apart — far more than one cyclic prefix — and the FFT the receiver runs over symbol l would contain fragments of symbol l−1 from one UE and symbol l+1 from another.

That is not a mild degradation. OFDM's subcarrier orthogonality is a property of the integration window: it holds only if the receiver's window contains exactly one period-aligned copy of each transmitted symbol. Break the alignment and you get inter-symbol interference and inter-carrier interference simultaneously, and both scale with the misalignment, not with distance or power. A misaligned UE therefore does not merely fail to be decoded — it raises the noise floor for everyone else scheduled in the same symbols.

Timing Advance is the fix, and it is deliberately the simplest possible one. The UE derives its own timing from the downlink it receives, which is already late by one one-way delay τ. It then pulls its uplink transmission forward by N_TA, an amount the network tells it, and the network sets N_TA ≈ 2τ. The uplink then travels τ back and arrives exactly on the boundary. Near UEs get a small advance; far UEs get a large one; the gNB sees one arrival instant.

Timing Advance in One Picture: Three Distances, One Arrival InstantTiming Advance in One Picture: Three Distances, One Arrival InstantEach UE times its uplink from the downlink it receives, then pulls it forward by N_TA = twice its own propagation delaygNBdownlinkDL slot n leaves the gNB antenna at the reference boundaryUE A -- 0.3 kmDL arrives +1.0 µsUL slot n, pulled forward by N_TA = 2.0 µsUE B -- 4.5 kmDL arrives +15 µsUL slot n, pulled forward by N_TA = 30.0 µsUE C -- 9.0 kmDL arrives +30 µsUL slot n, pulled forward by N_TA = 60.0 µsgNBuplink Rxall three uplink slot-n boundaries arrive here,0102030405060708090Time on the gNB clock (µs) -- the reference slot boundary sits at 40 µsEach blue bar starts N_TA earlier than the instant the downlink actually reached that UE, and N_TA is exactly twice theone-way delay -- so every bar's right-shifted arrival lands on the same boundary. The gNB never sees three timings.It sees one, which is the only reason uplink OFDM stays orthogonal across users.
Figure 1. The whole mechanism in one drawing. Note that the UE never measures its own distance — it applies whatever advance it is told, and the network is the only party that knows the arrival error.

What actually invokes the mechanism is worth separating out:

EventWhat the UE getsAbsolute or relativeWhere §
Random Access completes (MSG2 RAR, or MSGB successRAR/fallbackRAR)A 12-bit Timing Advance Command; N_TA is set outright from zeroAbsolute§5
Ongoing operation in RRC_CONNECTEDA Timing Advance Command MAC CE with a 6-bit value, per TAGRelative to the current N_TA§6
IAB-MT alignment, NTN, very large cells (Rel-16+)An Absolute Timing Advance Command MAC CE, 12 bitsAbsolute§6.3
timeAlignmentTimer expiryNothing — N_TA is discarded and the uplink stopsN/A§10
NTN operation (Rel-17)ta-Common, ta-CommonDrift in SIB19 plus UE self-computation from ephemeris and GNSSAdditive components on top of N_TA§12

Table 1. Every way a UE's uplink timing can change. Only two of these five set N_TA from nothing; the rest either adjust it or take it away.

💡
Key Point

Timing Advance is about arrival time, not about power, and the two are corrected by completely separate loops. A UE at the cell edge needs both a large N_TA and a high transmit power, but a UE behind a wall at 300 m needs high power and almost no N_TA. Treating a large TA value as evidence of poor coverage — or a poor SINR as evidence of a timing problem — is the single most common category error in uplink debugging.

2. The gNB Receive Window and the Cyclic Prefix Budget

The cyclic prefix is a copy of the tail of each OFDM symbol prepended to its front. Its job in the downlink is to absorb multipath delay spread; in the uplink it does that and absorbs residual timing error. A UE whose transmission arrives anywhere inside the CP is decoded cleanly, because the receiver's FFT window still sees one whole period-aligned symbol. A UE that arrives after the CP ends is not.

This is why the CP length, not the link budget, is the real constraint on how badly timing can be allowed to drift. The normal CP at 30 kHz is 2.34 µs, and that 2.34 µs must be shared between channel delay spread (often 0.5–1.5 µs in a macro cell), N_TA quantisation, and whatever residual error the closed loop has not yet corrected.

The gNB Receive Window: What the Cyclic Prefix Can and Cannot AbsorbThe gNB Receive Window: What the Cyclic Prefix Can and Cannot Absorb30 kHz SCS, normal cyclic prefix; time measured from the start of the gNB's expected symbol lgNB symbolgridCP2.34useful part of OFDM symbol l (33.33 µs at 30 kHz)CPsymbol l+1UE ATA correctarrives 0.35 µs into the CP -- FFT window sees only symbol l. Clean.UE BTA 0.6 µs shortarrives 0.56 µs past the end of the CP -- ISI from symbol l-1 plus ICIUE Cno TA at all1.8 km, no advance at all -- 12 µs late, a third of a symbol adrift0510152025303540Arrival time at the gNB (µs)The CP is the entire error budget. At 30 kHz it is 2.34 µs wide and must absorb residual TA error, channel delayspread and N_TA quantisation together -- which is why the UE timing-error requirement T_e is a fraction of it, not thewhole of it. A 9 km UE with no advance would be 60 µs late: nearly two whole symbols.
Figure 2. Three UEs against the same receive window. UE B is only 0.6 µs off and it is already broken — the margin is much smaller than engineers coming from a link-budget mindset expect.
µSCSNormal CP (T_c)Normal CP (µs)Extended CP (µs)One-way range error that uses up one whole CP
015 kHz92164.688703 m
130 kHz46082.344351 m
260 kHz23041.1724.167176 m
3120 kHz11520.58688 m
4240 kHz5760.29344 m
5480 kHz2880.14622 m
6960 kHz1440.07311 m

Table 2. Cyclic prefix per numerology. The last column is c·CP/2: how wrong the network's idea of a UE's range can be before the resulting round-trip error consumes the entire cyclic prefix, leaving nothing for delay spread. µ=5 and µ=6 are FR2-2, Rel-17; extended CP is defined only for µ=2.

Cyclic Prefix Against the Uplink Timing-Error BudgetCyclic Prefix Against the Uplink Timing-Error BudgetNormal CP is exact; T_e values are representative rows of TS 38.133 Table 7.1.2-1012345Duration (µs)4.690.3915 kHz2.340.3330 kHz1.170.2360 kHz0.590.11120 kHzNormal CP (µs)UE timing-error limit T_e (µs, representative)Both budgets shrink with numerology; channel delay spread does not. That is the whole reason a millimetre-wavecell is far less tolerant of a stale timing advance than a low-band one.
Figure 3. The CP and the UE's own timing-error requirement T_e, side by side. T_e is what the UE must achieve once it has been told the right N_TA; it does not include the network's own measurement error, which comes out of the same 2.34 µs.
⚠️
Common Pitfall

Cell radius is limited by the preamble format's cyclic prefix during Random Access and by the data symbol's cyclic prefix afterwards, and these are different numbers. A cell can be configured with a long PRACH format that happily detects a 20 km UE, then find that the same UE's PUSCH is unusable because 30 kHz data symbols cannot tolerate the residual error the coarse initial TA leaves behind. The symptom is a UE that completes Random Access reliably and then shows a persistent, distance-correlated UL BLER floor. See the companion 03 Random Access document for the preamble-format side of this.

3. T_c, N_TA, and the Formula That Ties Them Together

Timing advance is never expressed in microseconds on the wire. It is expressed in T_c, the basic NR time unit, so that one integer works unchanged across every numerology:

Time unit and the timing-advance relation
T_c  =  1 / (delta_f_max * N_f)                  [TS 38.211 cl. 4.1]
     =  1 / (480 000 * 4096)  s
     =  0.508 626...  ns          (~0.509 ns, or ~1.966 GHz sample rate)

N_TA =  T_A * 16 * 64 / 2^mu                     [TS 38.213 cl. 4.2]

  T_A   the value carried in the RAR (0..3846) or derived from the
        MAC CE (see below); dimensionless
  mu    numerology of the uplink transmission the command applies to
        0 = 15 kHz, 1 = 30, 2 = 60, 3 = 120, 4 = 240, 5 = 480, 6 = 960
  64    = kappa, the fixed ratio T_s / T_c
  16    the step multiplier, chosen so that one step is 16 * T_s at mu=0

For the MAC CE, T_A in the formula is the *change*:
  N_TA_new = N_TA_old + (T_A - 31) * 16 * 64 / 2^mu ,  floored at 0
  where T_A is the 6-bit field, 0..63, and 31 means no change.

Two things follow from the 16 · 64 / 2^µ factor and both matter when reading logs. First, the step is the same absolute time at 15 kHz as LTE's step was — 16·T_s ≈ 0.521 µs — which is deliberate: the quantisation was already fine enough relative to a 15 kHz cyclic prefix, so 3GPP kept it. Second, the step halves every time the numerology doubles, so the same integer T_A means a different amount of time depending on the SCS of the uplink it is applied to. A TA command value copied between two logs at different numerologies is not comparable.

📘
Spec Detail

N_TA is a transmit-timing offset held by the UE, not a message field. The RAR carries a 12-bit T_A and the MAC CE carries a 6-bit T_A; N_TA is the running total the UE maintains from them, in T_c, per Timing Advance Group. Vendor logs differ in which of the three they print, and they are off by factors of hundreds. Always check the units on the field name before believing a value.

The actual transmit instant combines N_TA with a second, constant term covered in §7 TS 38.211 cl. 4.3.1:

Uplink transmission timing
T_TA = (N_TA + N_TA_offset) * T_c

The UE begins transmitting uplink frame i exactly T_TA seconds BEFORE
the start of the corresponding downlink frame i as it observes it.

Special case: for PRACH, N_TA = 0.  The preamble is deliberately sent
with no advance -- its arrival time is the measurement.

4. Granularity and Range, Numerology by Numerology

Because the step size scales with numerology and the field widths do not, both the resolution and the maximum expressible advance depend on µ. This table is the one worth keeping to hand:

µSCSStep (T_c)Step (ns)One-way metres per stepMax N_TA from RAR (µs)Max one-way range
015 kHz1024520.878.1 m2003300.2 km
130 kHz512260.439.0 m1001150.1 km
260 kHz256130.219.5 m500.775.1 km
3120 kHz12865.19.8 m250.437.5 km
4240 kHz6432.64.9 m125.218.8 km
5480 kHz3216.32.4 m62.69.4 km
6960 kHz168.11.2 m31.34.7 km

Table 3. One TA step, and the ceiling imposed by the 12-bit RAR field (T_A ≤ 3846). "Max N_TA" is a round-trip figure; the range column halves it and converts at c. µ=4 carries SSB only; µ=5 and µ=6 are FR2-2. Values rounded.

🧮
Worked Calculation

T_A = 205, uplink at 30 kHz (µ = 1):

N_TA = 205 × 16 × 64 / 2 = 205 × 512 = 104 960 T_c

= 104 960 × 0.508626 ns = 53.39 µs (round trip)

One-way delay = 53.39 / 2 = 26.69 µs

Distance = 26.69 µs × 299 792 458 m/s = 8.00 km

Quantisation at this numerology: one step = 512 T_c = 0.2604 µs round-trip = 0.1302 µs one-way = 39.0 m of path. So the TA value alone locates this UE to within about ±20 m of range — which is why TA is genuinely usable as a coarse ranging measurement, and why ta-Report was added for NTN (§12).

A TA value read as a distance is one of the few cheap sanity checks available on a live cell. If a UE reports RSRP consistent with 500 m and the gNB is holding N_TA equivalent to 9 km, the likely explanations are, in order: the UE is being served by a repeater or an RF-over-fibre remote radio head whose feeder delay is in the loop; the dominant path is a strong reflection rather than the line of sight; or the log is quoting a different cell's TAG. All three are real, and none of them is "the UE moved".

5. The Initial Value: the 12-Bit Timing Advance Command in the RAR

A UE arriving from RRC_IDLE has no idea how far away the gNB is, and the gNB has no idea the UE exists. The PRACH preamble breaks the deadlock because it is sent with N_TA = 0: whatever lateness the gNB measures on its arrival, relative to the nominal PRACH occasion, is the round-trip delay. The gNB quantises that into a 12-bit field and returns it in the Random Access Response.

Carrier of the commandBitsRangeSemanticsTypical use
MAC RAR in MSG2 TS 38.321 cl. 6.2.3120 … 3846Absolute: N_TA is set to T_A · 16 · 64 / 2^µEvery 4-step Random Access procedure
successRAR / fallbackRAR in MSGB TS 38.321 cl. 6.2.3a120 … 3846Absolute, identical arithmetic2-step Random Access
Timing Advance Command MAC CE TS 38.321 cl. 6.1.3.460 … 63, 31 = no changeRelative: N_TA += (T_A − 31) · 16 · 64 / 2^µAll ongoing maintenance in RRC_CONNECTED
Absolute Timing Advance Command MAC CE (Rel-16)120 … 3846Absolute, same as the RARIAB-MT alignment; NTN; re-basing a badly wrong N_TA without a RACH

Table 4. Every field in NR that carries a timing advance. Confusing the 6-bit relative field with the 12-bit absolute one is the classic hand-decoding mistake — a 6-bit T_A of 45 is +14 steps, not 45 steps.

The initial command must be absolute and must span the whole cell because there is nothing to be relative to. The ongoing commands can be relative and narrow because they only have to track drift. That asymmetry is the entire reason for two different field widths, and it is also why 12 bits at 15 kHz reaches 300 km one-way while a single 6-bit adjustment at the same numerology moves the UE by at most 2.5 km.

One consequence for 2-step Random Access: MSGA's PUSCH payload is transmitted before any RAR has been received, so it goes out with whatever N_TA the UE already holds — zero, for a UE coming from RRC_IDLE. That is the real reason msgA-RSRP-Threshold gates 2-step selection: the payload has to survive being untimed, which only works when the UE is close enough that its round-trip delay already fits inside the cyclic prefix.

6. Maintaining It: the Timing Advance Command MAC CE

Propagation delay is not static. A UE at 100 km/h changes its distance to the gNB by up to 27.8 m per second, which at 30 kHz is a whole TA step every 1.4 seconds. Correction therefore has to be continuous, and it has to be cheap — which is why it lives in MAC and not in RRC. There is no RRC message anywhere in NR that carries a timing advance.

6.1 The control element and its subheader

Timing Advance Command MAC CE, as a Complete MAC subPDUTiming Advance Command MAC CE, as a Complete MAC subPDUTS 38.321 cl. 6.1.2 (R/LCID subheader for a fixed-size CE) and cl. 6.1.3.4bit76543210Oct 1RRLCID = 61 (Timing Advance Command)Oct 2TAG Id0..3Timing Advance Command T_A = 0..63 (31 = no change)Two octets total, and one of them is addressing. Because the CE is fixed size there is no L field: the subheader isR/R/LCID only. T_A is a *relative* index -- 31 means leave N_TA alone, 63 means add 32 steps, 0 means subtract 31.
Figure 4. Two octets, and the whole of the second one is the payload. Because the CE is fixed size, its subheader carries no length field — see the companion 07 MAC PDU and Control Elements document for the general subheader rules this specialises.
FieldBitsRangeMeaningConsequence of getting it wrong
TAG Identity
20 … 3Which Timing Advance Group the correction applies to. 0 is always the pTAG.The correction lands on the wrong group: one TAG drifts while another is over-corrected. Symptom is UL BLER on one carrier only.
Timing Advance Command
60 … 63Relative index. 31 = no change; 63 = +32 steps; 0 = −31 steps.Read as absolute, a value of 31 looks like a real correction when it is a keep-alive, and 0 looks like "align to the antenna" when it is the largest possible retard.

Table 5. Timing Advance Command MAC CE fields, TS 38.321 cl. 6.1.3.4.

6.2 The loop, and when the correction takes effect

The Timing Advance Maintenance LoopThe Timing Advance Maintenance LoopMeasureCorrectKeep aliveLapseUEgNB-DU PHYgNB-DU MACRRC_CONNECTED, 30 kHz SCS, pTAG only. N_TA = 104 960 T_c (53.4 µs).timeAlignmentTimer ms2560, running.SRS, periodic, 40 msSRS-Resource usage=codebook; also PUSCH and PUCCHDMRS between SRS instances1correlate against expected arrival:error +0.61 µs late = 2.3 stepstiming error estimate (internal)per TAG, filtered over several measurement instancespast the correction threshold-> issue +2 steps: T_A = 33Timing Advance Command MAC CELCID 61, TAG Id 0, T_A = 33 -> (33-31) x 512 = 1024 T_c = +0.52 µs2N_TA 104 960 -> 105 984 T_capplied from the start of UL slot n+k+1PUSCH with the corrected timingarrival now 0.09 µs into the CP -- inside T_e3quiet UE, no correction neededTiming Advance Command MAC CE, T_A = 31no timing change at all -- sent purely to restart the timerthe CE does not arriveTiming Advance Command MAC CEPDSCH fails after the last HARQ attempt; MAC never sees ittimeAlignmentTimer expiry-> uplink out of synctimeAlignmentTimer restartedtimerexpiresNothing in this loop is RRC signalling -- it is all MAC, because the correction has to keep up with a moving UE. Note thata T_A = 31 command is not a no-op: it restarts timeAlignmentTimer, which is the only thing keeping the uplink alive.
Figure 5. A full maintenance cycle, a keep-alive, and a lapse. The gNB's correction threshold is not specified by 3GPP — the decision to send a CE at all is scheduler policy.

The adjustment is not instantaneous. If the CE arrives in downlink slot n, the new timing applies from the beginning of uplink slot n + k + 1, where k is derived from the UE's PDSCH decoding capability N_T,1, its PUSCH preparation capability N_T,2, the largest timing advance the cell supports, and a 0.5 ms margin TS 38.213 cl. 4.2. Practically this is a few slots; it matters because uplink transmissions already in flight or already prepared use the old N_TA, and a log that shows a PUSCH with stale timing immediately after a TA command is showing correct behaviour.

🧮
Worked Calculation

T_A = 33 applied to the N_TA of the earlier worked example, at 30 kHz:

adjustment = (33 − 31) × 16 × 64 / 2 = 2 × 512 = +1024 T_c

= +0.5209 µs round trip = +0.2604 µs one way

= the UE is now treated as 78 m further away

N_TA: 104 960 → 105 984 T_c (53.39 µs → 53.91 µs)

Full-scale limits of one CE at this numerology:

T_A = 63 → +32 steps = +16 384 T_c = +8.33 µs = +1.25 km of range

T_A = 0 → −31 steps = −15 872 T_c = −8.07 µs = −1.21 km of range

So a single CE can chase a UE moving at 1.25 km per correction interval. At a 100 ms cadence that is 45 000 km/h of radial speed — the range of one command has never been the binding constraint on terrestrial mobility.

⚠️
Common Pitfall

A Timing Advance Command MAC CE carrying T_A = 31 is not a no-op and is not a logging artefact. It changes nothing about the timing and everything about the timer: receiving it restarts timeAlignmentTimer for that TAG. Schedulers use it as a keep-alive for a UE that has nothing to send and is not drifting. Filtering "T_A = 31" out of a trace as noise removes exactly the evidence you need when investigating an unexplained timeAlignmentTimer expiry.

6.3 The absolute variant

Absolute Timing Advance Command MAC CE (Rel-16)Absolute Timing Advance Command MAC CE (Rel-16)TS 38.321 cl. 6.1.3; carried under an extended LCID (eLCID) on DL-SCHbit76543210Oct 1R R R RT_A bits 11..8Oct 2T_A bits 7..0 -- full 12-bit absolute value, 0 .. 3846The same 12-bit absolute quantity the RAR carries, but deliverable at any time in RRC_CONNECTED. Added for IAB,where an IAB-MT's timing must be set outright rather than nudged, and reused by NTN and by very large cells wherea 6-bit relative step cannot span the correction needed.
Figure 6. The Rel-16 Absolute Timing Advance Command MAC CE. Its existence is the clearest evidence that relative nudging is not always enough — an IAB-MT joining a multi-hop topology, or a UE handed a satellite's delay, needs its timing set, not adjusted.

The relative CE cannot express a correction larger than ±32 steps, so any situation where the correct N_TA is far from the current one needs either a Random Access procedure or the absolute CE. Rel-16 introduced the latter for IAB, where a mobile-termination function must be aligned to a parent node's timing outright; Rel-17 reuses it in non-terrestrial deployments. It is carried under an extended LCID on DL-SCH rather than one of the sixty-four single-octet LCID codepoints, because those were already exhausted.

7. N_TA_offset: the Constant the UE Also Subtracts

N_TA is not the whole advance. The UE also applies a fixed, band-dependent offset N_TA_offset that has nothing to do with propagation and everything to do with the UE's own radio hardware. On a TDD carrier the UE has to physically switch its front end from receive to transmit between a downlink symbol and an uplink symbol; the offset buys the time for that switch and keeps the NR uplink timing interoperable with LTE on shared bands.

ConfigurationN_TA_offset (T_c)In µsWhy it has that value
FR1, FDD (paired spectrum)00Transmit and receive are on different frequencies and run concurrently. No switching gap is needed, so no offset.
FR1, TDD, no LTE-NR coexistence2560013.02Buys the UE's RF switching time between downlink and uplink symbols on the same carrier.
FR1, TDD, LTE-NR coexistence on the band3993620.32Larger, so the NR uplink lines up with the LTE uplink timing already in use on that band and the two do not interfere at the boundary.
FR2 (all duplex modes)137927.01FR2 front ends switch faster and the symbols are much shorter, so a smaller absolute margin suffices.

Table 6. N_TA_offset per TS 38.133 cl. 7.1.2. The network can override the band default by signalling n-TimingAdvanceOffset in ServingCellConfigCommon, whose enumeration members n0, n25600 and n39936 are these same numbers.

🧮
Worked Calculation

Total advance for the 8 km UE, on an FR1 TDD carrier at 30 kHz:

N_TA = 104 960 T_c (53.39 µs — the propagation part)

N_TA_offset = 25 600 T_c (13.02 µs — the hardware part)

-------------------------------------------------------------

T_TA = 130 560 T_c = 66.41 µs

That is the number the UE's transmitter actually uses. Nearly 20 % of it has nothing to do with distance — which is why an attempt to back-calculate range from a total-advance figure printed by a PHY-layer log, rather than from N_TA itself, comes out roughly 2 km too far on this carrier.

⚠️
Common Pitfall

Getting n-TimingAdvanceOffset wrong produces a constant timing bias affecting every UE in the cell equally — 13.02 µs of it on FR1 TDD, which is more than five cyclic prefixes at 30 kHz. The signature is unmistakable once you know to look for it: uniformly bad uplink for all UEs regardless of distance, RSRP or power headroom, with PRACH detection still working perfectly because the preamble format's cyclic prefix is far longer. Distance-independence is the tell — a propagation problem is never distance-independent.

8. How the gNB Measures the Error, and How Often It Corrects

Nothing in the specification tells the gNB how to measure the timing error or when to issue a correction. TS 38.133 constrains the UE side (it must apply the advance it is given to within T_e) and TS 38.213 defines the arithmetic, but the measurement and the correction policy are implementation. What the specification does provide is the set of uplink signals a gNB can measure against:

SignalWhen it is availableTiming qualityRole in the loop
PRACH preambleOnly during a Random Access procedureCoarse but unambiguous — the search window is the whole cellThe only source that can acquire N_TA from nothing. Sets the initial absolute value.
PUSCH DMRSWhenever the UE is scheduled in the uplinkGood, and free — no extra resource costThe workhorse for an active UE. Accuracy improves with allocation bandwidth.
PUCCH DMRSWhenever HARQ-ACK, SR or CSI is reportedNarrowband, so poorer time resolutionKeeps a UE with no data traffic trackable at low cost.
SRSPeriodic, semi-persistent or aperiodic per SRS-ConfigBest available — wideband and designed for soundingThe deliberate choice for a UE that must be tracked accurately while sending little data.

Table 7. What the gNB can measure timing from. Time resolution scales with occupied bandwidth, which is why a UE holding a 4-PRB PUCCH and nothing else is tracked far less precisely than one being scheduled 100 PRB of PUSCH.

Correction cadence in practice follows from the geometry rather than from any parameter. A gNB has two independent reasons to send a CE: the measured error has grown past some fraction of the CP, or timeAlignmentTimer is about to expire and the uplink must be kept alive. The first is traffic- and mobility-dependent; the second is periodic at roughly half the timer value. Both produce CEs, and only the value distinguishes them.

🧮
Worked Calculation

How fast does a UE actually drift?

A UE moving radially at 100 km/h covers 27.8 m/s. One TA step is:

15 kHz: 78.1 m -> a step every 2.81 s

30 kHz: 39.0 m -> a step every 1.40 s

120 kHz: 9.8 m -> a step every 0.35 s

At 350 km/h (high-speed rail, 97.2 m/s) and 30 kHz: a step every 0.40 s.

Two conclusions. Corrections a few hundred milliseconds apart are ample for terrestrial mobility even at high SCS — and tangential motion produces almost no drift at all, so a UE circling a site at 100 km/h may need no correction for minutes. A log showing long gaps between TA commands for a fast-moving UE is not necessarily a broken loop.

9. Timing Advance Groups: pTAG, sTAG and Carrier Aggregation

One N_TA per UE is enough only if every serving cell the UE uses is the same distance away. With carrier aggregation that stops being true: cells on different bands may be radiated from different physical sites, from remote radio heads at the end of different fibre runs, or through a repeater. A Timing Advance Group is a set of serving cells that share one N_TA and one timeAlignmentTimer because they share, to within a cyclic prefix, one propagation delay.

pTAG (primary)sTAG (secondary)
MembershipContains the SpCell — the PCell of the master cell group, or the PSCell of a secondary cell group. Always exists.Contains only SCells. Zero, one or more may be configured; up to four TAGs total per cell group (maxNrofTAGs = 4).
TAG Identity
Always 01 … 3, assigned by the network in TAG-Config
How timing is acquiredRandom Access on the SpCellRandom Access on one of the SCells in the group, ordered by the network via a PDCCH order (there is no other way — an SCell has no RRC connection of its own)
Reference for measurementThe SpCell's downlinkThe downlink of an activated SCell in that TAG
Effect of timer expiryWhole cell group loses uplink (§10)Only that TAG's SCells lose uplink; PCell keeps running
Where configuredMAC-CellGroupConfigtag-Configtag-ToAddModListSame; each serving cell's ServingCellConfig carries the tag-Id it belongs to

Table 8. pTAG and sTAG. The distinction is not about importance — it is about which cell the timing is referenced to, and therefore what is lost when it lapses.

⚠️
Common Pitfall

A single site can legitimately need two TAGs. An operator running a mid-band macro from a cabinet and an mmWave small cell 400 m down the street as an SCell has roughly 1.3 µs of differential one-way delay between them — more than two cyclic prefixes at 120 kHz. Grouping both into the pTAG because "it's the same site" produces an SCell whose uplink never works while the PCell is perfect. If SCell UL BLER is bad and PCell UL BLER is fine, check the TAG assignment before anything else.

10. timeAlignmentTimer and the Cost of Expiry

N_TA is a cached measurement, and the network's confidence in it decays. If a UE has not been told anything for several seconds it may have moved, changed dominant path, or been handed to a repeater. Rather than let it keep transmitting on stale timing — which would interfere with everyone else — NR gives every TAG a timeAlignmentTimer, restarted on every Timing Advance Command MAC CE and on every absolute command for that TAG, and treats expiry as loss of uplink synchronisation TS 38.321 cl. 5.2.

Uplink time alignment state machine per TAGUplink Time Alignment as a State MachinePer TAG, not per UE -- a UE with two TAGs runs two copies of thisNO VALID N_TAuplink cannotbe used at allACQUIRINGpreamble sent,awaiting RAR / MSGBUL IN SYNCtimeAlignmentTimerrunning for this TAGCORRECTINGTA Command MAC CEin flightUL OUT OF SYNCtimer expired,N_TA no longer trustedRA triggeredRAR / MSGB:absolute 12-bit T_AgNB measures error,sends T_A != 31N_TA updated,timer restartedtimeAlignmentTimerexpiryN_TA released; RA to re-acquire,or RLF and re-establishmentThe only edge that creates timing information out of nothing is the RAR. Everything else is a nudge, a keep-alive, or a loss --so a UE that cannot complete Random Access can never reach the green state, no matter how good its downlink looks.
Figure 7. Uplink alignment as a per-TAG state machine. A UE aggregating three carriers across two TAGs runs two independent copies, and they can be in different states.
Consequences of timeAlignmentTimer expiryWhat timeAlignmentTimer Expiry Actually CostsTS 38.321 cl. 5.2timeAlignment-Timer forTAG x expiresIs TAG xthe pTAG?Every serving cell in the cell group:flush all HARQ buffersrelease PUCCH and SRS configclear configured DL assignmentsand configured UL grantsall TAGs considered out of syncThe SCells in TAG x only:flush their HARQ buffersrelease their PUCCH and SRSclear their configured grantsPCell and pTAG keep transmittingUplink unusableon the SpCell.Random Accessto re-acquire,or RLFSCell uplinkunusable. RA ona cell of thatTAG, or releasethe SCellyesnoThe asymmetry is the thing worth remembering: an sTAG lapse is a capacity event, a pTAG lapse is a service event.Both look identical in a MAC log until you resolve the TAG Id.
Figure 8. The two expiry paths. Everything in the red box is mandated behaviour, not vendor choice — which is why an unexplained pTAG expiry looks, from above, exactly like a radio link failure.
On expiry the UE …pTAGsTAGWhy
Flushes all HARQ buffersFor every serving cell in the cell groupFor the SCells in that TAG onlyA retransmission on stale timing is worse than no retransmission: it cannot be decoded and it raises interference.
Releases PUCCH and SRS configurationAll serving cells in the groupThe SCells in that TAGPUCCH and SRS are periodic and unscheduled — without valid timing they would transmit blind, indefinitely.
Clears configured DL assignments and configured UL grantsAll of them (SPS and Type 1 / Type 2 configured grants)Those on the affected SCellsSame reason: a configured grant fires without a DCI, so nothing would stop it. See the companion 08 Scheduling document.
Considers the TAG uplink out of syncAll TAGs are considered out of sync, not just the pTAGOnly that TAGThe sTAGs' timing is referenced through the same UE; if the pTAG is untrusted, nothing is trusted.
Next stepRandom Access on the SpCell to re-acquire an absolute N_TA — or, if that fails, RLF and RRC re-establishmentRandom Access on a cell of that TAG following a PDCCH order, or the network simply releases the SCellOnly Random Access can create timing from nothing (§5).

Table 9. timeAlignmentTimer expiry, action by action, TS 38.321 cl. 5.2. The asymmetry in the last two rows is the operationally important part.

💡
Key Point

timeAlignmentTimer expiry on the pTAG is one of the Random Access triggers listed in the companion 03 Random Access document, and it is the one most often misdiagnosed. The UE's radio conditions may be excellent throughout; what failed is a downlink MAC CE that never arrived, or a scheduler that never sent one. In a log this appears as a sudden RACH from a UE that was in RRC_CONNECTED with good measurements — which looks like a beam or coverage failure and is not.

11. Worked Arithmetic, End to End

Putting §§3–7 together for one UE, from Random Access to a maintained steady state. FR1 TDD band, 30 kHz uplink (µ = 1), UE 8.0 km from the gNB, normal cyclic prefix.

StepQuantityArithmeticResult
1True round-trip delay2 × 8000 m / 299 792 458 m/s53.37 µs
2gNB quantises to a 12-bit T_A53.37 µs / 0.2604 µs per step = 204.96 → nearest integerT_A = 205
3UE computes N_TA from the RAR205 × 16 × 64 / 2^1104 960 T_c
4N_TA in time104 960 × 0.508626 ns53.39 µs
5Quantisation error left behind53.39 − 53.37+0.02 µs — 0.9 % of the 2.34 µs CP
6N_TA_offset for FR1 TDDfrom TS 38.13325 600 T_c = 13.02 µs
7Total advance the UE applies(104 960 + 25 600) × T_c130 560 T_c = 66.41 µs
8UE drives 600 m further out2 × 600 / c = 4.00 µs → 4.00 / 0.260415.4 steps needed
9gNB issues one relative CET_A = 31 + 15 = 46 → (46 − 31) × 512+7680 T_c = +3.90 µs
10New N_TA104 960 + 7680112 640 T_c = 57.29 µs ≈ 8.59 km
11Residual after the correctiontrue 57.37 µs − applied 57.29 µs0.08 µs — 3 % of the CP, fine

Table 10. One UE, eleven lines, from preamble to a maintained steady state. Note step 5: the initial quantisation error is far smaller than the CP, which is exactly the design intent — the step size was chosen relative to the 15 kHz CP and every higher numerology shrinks both together.

It is worth noticing what step 9 does not need. The gNB never tells the UE its new absolute timing, never re-runs Random Access, and never involves RRC. One octet of MAC control element, plus its one-octet subheader, moved a UE 600 m and cost two bytes of downlink.

12. Non-Terrestrial Networks: When 12 Bits Are Not Enough

Every number in §4 assumes the transmitter is on the ground. A low-Earth-orbit satellite at 600 km has a one-way delay of about 2 ms at zenith and more at low elevation; a geostationary satellite is 35 786 km away, giving roughly 119 ms one way and about 239 ms of round trip on the service link alone, before the gateway feeder link is counted. The largest N_TA the 12-bit field can express at 15 kHz is 2.003 ms of round trip. It is short by two orders of magnitude, and no amount of relative nudging closes that gap.

Rel-17 solves it by splitting the total advance into components and moving most of the work to the UE, which in NTN is required to have GNSS. The network broadcasts the parts only it knows; the UE computes the part only it knows.

ComponentWho supplies itSignalled asWhat it covers
N_TA (closed loop)gNBThe ordinary 12-bit RAR command and 6-bit MAC CE, unchangedResidual error after everything else — the fine correction, exactly as in a terrestrial cell.
Common TANetwork, broadcastta-Common-r17, with ta-CommonDrift-r17 and ta-CommonDriftVariation-r17The delay component shared by all UEs in the beam: the feeder link and the reference-point-to-satellite leg, plus its first and second derivatives so the UE can extrapolate between updates.
UE-specific TAUE, self-computedNot signalled — derived from ephemerisInfo-r17 plus the UE's own GNSS positionThe UE-to-satellite leg. This is the large, fast-changing term, and only the UE can compute it in time.
N_TA_offsetBand configurationn-TimingAdvanceOffset as usualRF switching margin, unchanged.

Table 11. The Rel-17 NTN timing decomposition. The design principle is that a quantity changing at tens of microseconds per second cannot be tracked by a downlink control element — it has to be predicted, and only the UE has the position to predict it with.

ParameterRangeGranularityNotes
ta-Common-r17
0 … 66 485 757≈ 4.072 × 10⁻³ µsFull scale is about 270.7 ms — chosen to cover a GEO round trip including the feeder link.
ta-CommonDrift-r17
−257 303 … 257 303≈ 0.2 × 10⁻³ µs/sFirst derivative. Full scale ≈ ±51 µs/s, which is LEO territory.
ta-CommonDriftVariation-r17
0 … 28 949≈ 0.2 × 10⁻⁴ µs/s²Second derivative, so the UE's extrapolation stays accurate between SIB19 updates.
cellSpecificKoffset-r17
0 … 1023 slotsone slotNot a timing advance: it pushes every scheduling relationship (K0, K1, K2, RAR window) far enough into the future that the round trip fits.
ntn-UlSyncValidityDuration-r17
seconds, s5 … s900How long the broadcast ephemeris and TA parameters may be used. On expiry the UE must stop transmitting in the uplink.

Table 12. Rel-17 NTN timing parameters, from NTN-Config in SIB19 and ServingCellConfigCommon. Granularities are the units the specification defines the integers in; treat the decimal approximations here as approximate.

🔄
Release Delta

Two Rel-17 NTN additions change how a trace reads even before any satellite is involved. ta-Report lets the network ask the UE to report the timing advance it applied, turning N_TA into an explicitly reported ranging measurement rather than something inferred. And downlink HARQ feedback can be disabled per HARQ process, because a 270 ms round trip makes stop-and-wait pointless — see the companion 05 HARQ document. Neither has a terrestrial equivalent in earlier releases, so their presence in a log is itself a strong hint about the deployment.

13. Parameter Reference: ASN.1, Ranges and Effects

ASN.1 nameWhereRange / valuesTypicalEffect
timeAlignmentTimer
TAG inside MAC-CellGroupConfigtag-Configms500, ms750, ms1280, ms1920, ms2560, ms5120, ms10240, infinityms1920 or ms2560How long a TAG's N_TA stays valid without a refresh. Shorter means more keep-alive CEs; longer means more time transmitting on possibly stale timing.
tag-Id
TAG; also in each ServingCellConfig0 … 30Which TAG a serving cell belongs to. 0 is the pTAG by definition.
n-TimingAdvanceOffset
ServingCellConfigCommon
n0, n25600, n39936band-dependentOverrides the TS 38.133 default N_TA_offset for the band. Wrong value = constant cell-wide uplink timing bias (§7).
srs-ConfigSRS-ResourceresourceType
BWP-UplinkDedicated
periodic / semiPersistent / aperiodicperiodicDetermines whether the gNB has a guaranteed timing reference for an otherwise idle UE.
ta-Report-r17
NTN-Config / UE reporting configenabled (optional)absentMakes the UE report the TA it applied. Turns N_TA into a usable ranging observable.
ta-Common-r17
NTN-Config in SIB190 … 66 485 757n/aBeam-common delay component (§12).
cellSpecificKoffset-r17
ServingCellConfigCommon
0 … 1023 slotsn/aShifts every scheduling timing relationship to accommodate the NTN round trip.
ephemerisInfo-r17
NTN-Config in SIB19state vector (position/velocity) or orbital elementsn/aLets the UE compute its own UE-specific TA component.

Table 13. Configuration that determines timing-advance behaviour. Only the first three exist in Rel-15; everything below srs-Config is Rel-17 NTN.

14. Timers and Counters

TimerScopeStarted / restarted byOn expiry
timeAlignmentTimer
Per TAGAny Timing Advance Command MAC CE, Absolute Timing Advance Command MAC CE, or Random Access Response for that TAGTAG considered uplink out of sync; HARQ flush, PUCCH/SRS release, configured grants cleared (§10)
ntn-UlSyncValidityDuration-r17
Per serving cell (NTN)Receiving a fresh NTN-Config — the epoch is epochTime-r17UE stops uplink transmission on that cell until it reacquires valid ephemeris and TA parameters
ra-ResponseWindow
Per Random Access attemptEnd of the PRACH preamble transmissionNo RAR, so no absolute TA; the attempt fails and RACH retries. NTN extends the enumeration because the round trip alone can exceed the terrestrial maximum.
T304
Per handoverApplying reconfigurationWithSyncHandover failure. Relevant here because the target cell's TA is acquired inside T304 and a target with a badly wrong n-TimingAdvanceOffset fails every inbound handover.

Table 14. Timers that gate uplink timing. timeAlignmentTimer is the only one whose sole job is timing advance; the others bound procedures that happen to acquire or depend on it.

Notice what is not in that table: there is no retransmission counter and no failure counter anywhere in the timing-advance mechanism. A Timing Advance Command MAC CE is protected only by the HARQ process carrying its PDSCH, and if that PDSCH is finally undecodable the CE is simply gone — MAC never learns and the gNB never finds out, because MAC control elements are not acknowledged above HARQ. The whole safety net is timeAlignmentTimer, and its granularity is hundreds of milliseconds.

15. Failure Modes and What Each One Means

FailureDetected byWhat the UE doesDiagnostic pointer
timeAlignmentTimer expiry on the pTAGUE MACFlush all HARQ, release PUCCH/SRS, clear configured grants, consider every TAG out of sync, trigger Random Access on the SpCellUsually a downlink problem, not an uplink one: the keep-alive CE never arrived. Check DL BLER and whether the scheduler sends keep-alives at all for idle UEs.
timeAlignmentTimer expiry on an sTAGUE MACSame actions, scoped to that TAG's SCells. PCell keeps working.Often the SCell was deactivated or was never given an SRS resource, so the gNB had nothing to measure. Look for an sTAG with no configured uplink reference signal.
N_TA correct but N_TA_offset wrongNobody — it is silentNothing; the UE is behaving correctlyUniformly poor uplink for all UEs, independent of distance and RSRP, while PRACH still succeeds. Compare n-TimingAdvanceOffset against the band's duplex mode (§7).
UE beyond the range the 12-bit field can expressgNBNothing — it never sees a RAR, because its preamble arrived outside the detection windowOnly distant UEs affected. Bounded by the PRACH format's CP first, then by the T_A ceiling in §4. Check the format before the field width.
TA command for a TAG the UE has not configuredUE MACDiscards the MAC CEConfiguration mismatch after a reconfiguration that changed tag-Config. Watch for CEs addressed to TAG 2 or 3 in a single-carrier UE.
Correction issued from a stale or wrong measurementgNBApplies it faithfully — the UE has no way to sanity-checkA TA value that jumps by hundreds of steps and then comes back is measurement noise, typically a narrowband PUCCH DMRS estimate or a multipath-dominated arrival. Correlate against allocation bandwidth.
Repeater or RF-over-fibre delay in the pathNobodyApplies a correct-looking N_TA that includes the equipment delayTA implies a distance far larger than RSRP or the cell's geometry allows, consistently, for every UE in a sector. Rel-18 network-controlled repeaters make this explicit; older passive repeaters do not.
NTN: ntn-UlSyncValidityDuration expiryUE MAC / RRCStops uplink transmission until fresh ephemeris and TA parameters are readSIB19 acquisition failure, not a radio failure. Check SI scheduling and the epochTime the UE was working from.

Table 15. Timing-advance failure modes. Note how many are silent — the mechanism has almost no self-diagnosis, which is why the checklist in §19 leans on cross-checks rather than on error indications.

💡
Key Point

Two of these are worth internalising because they invert the usual instinct. A pTAG timer expiry is a downlink failure — the UE stopped hearing corrections. And a constant N_TA_offset error is not a radio problem at all, which is why it survives every optimisation attempt aimed at coverage or power. In both cases the thing that broke is not the thing that is complaining.

16. ASN.1 Extracts

Timing-advance configuration is small and lives in three places: the TAG definitions in the MAC cell-group configuration, the offset in the common serving-cell configuration, and — for NTN — the timing block in SIB19. Abridged from TS 38.331; ... marks omitted fields and extension markers.

MAC-CellGroupConfig ::= SEQUENCE {
    drx-Config                     SetupRelease { DRX-Config } OPTIONAL,
    schedulingRequestConfig        SchedulingRequestConfig     OPTIONAL,
    bsr-Config                     BSR-Config                  OPTIONAL,
    tag-Config                     TAG-Config                  OPTIONAL,
    phr-Config                     SetupRelease { PHR-Config }  OPTIONAL,
    skipUplinkTxDynamic            BOOLEAN,
    ...
}

TAG-Config ::= SEQUENCE {
    tag-ToReleaseList  SEQUENCE (SIZE (1..maxNrofTAGs)) OF TAG-Id  OPTIONAL,
    tag-ToAddModList   SEQUENCE (SIZE (1..maxNrofTAGs)) OF TAG     OPTIONAL
}

TAG ::= SEQUENCE {
    tag-Id                 TAG-Id,
    timeAlignmentTimer     TimeAlignmentTimer,
    ...
}

TAG-Id ::= INTEGER (0..maxNrofTAGs-1)          -- maxNrofTAGs = 4

TimeAlignmentTimer ::= ENUMERATED {
    ms500, ms750, ms1280, ms1920, ms2560, ms5120, ms10240, infinity }

ServingCellConfigCommon ::= SEQUENCE {
    physCellId                  PhysCellId                     OPTIONAL,
    downlinkConfigCommon        DownlinkConfigCommon           OPTIONAL,
    uplinkConfigCommon          UplinkConfigCommon             OPTIONAL,
    n-TimingAdvanceOffset       ENUMERATED { n0, n25600, n39936 } OPTIONAL,
    ssb-PositionsInBurst        ...                            OPTIONAL,
    tdd-UL-DL-ConfigurationCommon TDD-UL-DL-ConfigCommon       OPTIONAL,
    ss-PBCH-BlockPower          INTEGER (-60..50),
    ...,
    [[ cellSpecificKoffset-r17  INTEGER (1..1023)              OPTIONAL ]]
}

Listing 1. TAG configuration and the offset. Note that timeAlignmentTimer is a field of TAG, not of the cell group — every TAG can have a different value, and often should.

NTN-Config-r17 ::= SEQUENCE {
    epochTime-r17                    EpochTime-r17              OPTIONAL,
    ntn-UlSyncValidityDuration-r17   ENUMERATED { s5, s10, s15, s20,
                                        s25, s30, s35, s40, s45, s50,
                                        s55, s60, s120, s180, s240,
                                        s900 }                  OPTIONAL,
    cellSpecificKoffset-r17          INTEGER (1..1023)          OPTIONAL,
    kmac-r17                         INTEGER (1..512)           OPTIONAL,
    ta-Info-r17                      TA-Info-r17                OPTIONAL,
    ntn-PolarizationDL-r17           ENUMERATED { rhcp, lhcp, linear } OPTIONAL,
    ntn-PolarizationUL-r17           ENUMERATED { rhcp, lhcp, linear } OPTIONAL,
    ephemerisInfo-r17                EphemerisInfo-r17          OPTIONAL,
    ta-Report-r17                    ENUMERATED { enabled }     OPTIONAL,
    ...
}

TA-Info-r17 ::= SEQUENCE {
    ta-Common-r17               INTEGER (0..66485757),
    ta-CommonDrift-r17          INTEGER (-257303..257303)       OPTIONAL,
    ta-CommonDriftVariation-r17 INTEGER (0..28949)              OPTIONAL
}

EphemerisInfo-r17 ::= CHOICE {
    positionVelocity-r17   PositionVelocity-r17,   -- ECEF state vector
    orbitalParameters-r17  Orbital-r17             -- Keplerian elements
}

Listing 2. NTN-Config, broadcast in SIB19 and reachable in dedicated signalling. The three ta-* fields are a value and its first two derivatives, so the UE can extrapolate the common component between broadcasts instead of needing one every few milliseconds.

17. Illustrative Message Traces

🔍
About These Traces

Illustrative trace. Field names and encodings follow 3GPP; the values are constructed for this document and are not a capture from any deployed or lab network.

17.1 Configuration the UE is working from

[RRC-DL-DCCH] RRCReconfiguration -- TAG and offset configuration
RRCReconfiguration
 cellGroupConfig  (masterCellGroup)
  mac-CellGroupConfig
   tag-Config
    tag-ToAddModList
      TAG [0]
        tag-Id .................... 0            -- pTAG, contains PCell
        timeAlignmentTimer ........ ms1920
      TAG [1]
        tag-Id .................... 1            -- sTAG, mmWave SCell
        timeAlignmentTimer ........ ms1280       -- shorter: faster drift
   phr-Config ................... setup
  spCellConfig
   reconfigurationWithSync
    spCellConfigCommon
     physCellId .................. 214
     n-TimingAdvanceOffset ....... n25600        -- FR1 TDD, 13.02 us
     subcarrierSpacing ........... kHz30
  sCellToAddModList
   SCellConfig [1]
    sCellIndex ................... 1
    sCellConfigDedicated
     tag-Id ...................... 1             -- this SCell is in sTAG 1
     uplinkConfig
      initialUplinkBWP
       srs-Config
        srs-ResourceToAddModList
         SRS-Resource [0]
          resourceType ........... periodic
           periodicityAndOffset .. sl40          -- every 40 slots
          usage .................. codebook

Listing 3. Two TAGs, two timers, and an SRS resource on the SCell so the gNB has something to measure sTAG 1 against. An sTAG with no uplink reference signal is a timer expiry waiting to happen.

17.2 Acquiring the initial value, then maintaining it

[MAC/PHY] initial TA and one maintenance cycle
09:41:02.118  [MAC-DL] RAR MAC PDU, RA-RNTI 1391, RAPID 23 matched
                MAC RAR
                  Timing Advance Command ..... 205
              -- mu=1 (30 kHz): N_TA = 205 x 16 x 64 / 2 = 104960 T_c
              --                             = 53.39 us round trip
              --                             ~ 8.00 km one-way path
              -- N_TA_offset = 25600 T_c (13.02 us, FR1 TDD)
              -- T_TA = 130560 T_c = 66.41 us of total advance
09:41:02.118  [MAC]    timeAlignmentTimer(TAG 0) started, ms1920
09:41:02.122  [MAC-UL] MSG3 on PUSCH, TC-RNTI 0x4601, advance applied

09:41:02.640  [PHY-UL] PUSCH DMRS arrival  +0.11 us vs expected  (32 PRB)
              -- 0.4 steps; below the correction threshold, no CE sent

09:41:03.900  [PHY-UL] SRS arrival        +0.61 us vs expected
              -- 2.3 steps at 30 kHz; past threshold -> correct by +2
09:41:03.902  [MAC-DL] Timing Advance Command MAC CE
                LCID ....................... 61
                TAG Identity ............... 0
                Timing Advance Command ..... 33
              -- (33 - 31) x 512 = +1024 T_c = +0.52 us = +78 m of range
              -- N_TA 104960 -> 105984 T_c   (53.39 -> 53.91 us)
09:41:03.902  [MAC]    timeAlignmentTimer(TAG 0) restarted, ms1920
09:41:03.906  [MAC]    adjustment effective from UL slot n+k+1
09:41:03.908  [MAC-UL] PUSCH still using old N_TA (prepared before n+k+1)
09:41:03.910  [MAC-UL] PUSCH using N_TA 105984
09:41:04.130  [PHY-UL] PUSCH DMRS arrival  +0.09 us vs expected  -- inside T_e

09:41:04.820  [MAC-DL] Timing Advance Command MAC CE  TAG 0  T_A = 31
              -- keep-alive: no timing change, timer restarted only

Listing 4. Absolute acquisition, one real correction, and one keep-alive. The two PUSCH lines at 09:41:03.908/.910 show the n + k + 1 application delay — the first uses the old value and is correct to do so.

17.3 An sTAG lapses while the pTAG keeps running

[MAC] sTAG timeAlignmentTimer expiry and recovery
09:52:10.004  [MAC]    SCell 1 (sTAG 1) deactivated by SCell Activation/
                       Deactivation MAC CE
              -- no UL transmissions on SCell 1 from here; SRS suspended
09:52:10.004  [MAC]    timeAlignmentTimer(TAG 1) continues to run, ms1280
09:52:11.284  [MAC]    timeAlignmentTimer(TAG 1) EXPIRED
09:52:11.284  [MAC]    TAG 1 -> uplink out of sync
                       flush HARQ buffers ........ SCell 1 only
                       release PUCCH config ...... SCell 1 (none present)
                       release SRS config ........ SCell 1
                       clear configured grants ... SCell 1
09:52:11.284  [MAC]    TAG 0 (pTAG) unaffected, timer running, 1.42 s left
09:52:11.284  [MAC-UL] PCell uplink continues normally

09:52:19.700  [MAC-DL] SCell Activation/Deactivation MAC CE -- SCell 1 on
09:52:19.700  [MAC]    TAG 1 has no valid N_TA -> SCell 1 UL unusable
09:52:19.740  [PHY-DL] PDCCH order: DCI 1_0, C-RNTI 0x4601,
                       ra-PreambleIndex 47, SSB index 3, on SCell 1
09:52:19.760  [MAC-UL] CFRA preamble 47 on SCell 1 PRACH
09:52:19.770  [MAC-DL] RAR, Timing Advance Command 218  -- absolute, TAG 1
              -- N_TA(TAG 1) = 218 x 512 = 111616 T_c = 56.77 us
              -- ~8.51 km: 510 m further than the PCell's TAG. Two TAGs
              --   were the right call.
09:52:19.770  [MAC]    timeAlignmentTimer(TAG 1) started, ms1280

Listing 5. An sTAG expiry costs one SCell and is recovered by a network-ordered contention-free Random Access on that SCell. Nothing about the PCell changes — compare the next trace.

17.4 The pTAG lapses

[MAC/RRC] pTAG timeAlignmentTimer expiry
10:07:44.512  [MAC-DL] Timing Advance Command MAC CE  TAG 0  T_A = 34
10:07:44.512  [MAC]    timeAlignmentTimer(TAG 0) restarted, ms1920
              -- UE has no UL data; next CE will be a keep-alive

10:07:45.300  [PHY-DL] PDSCH  HARQ pid 5  attempt 1  CRC fail
10:07:45.312  [PHY-DL] PDSCH  HARQ pid 5  attempt 2  CRC fail
10:07:45.324  [PHY-DL] PDSCH  HARQ pid 5  attempt 3  CRC fail  -- gave up
              -- this PDSCH carried the keep-alive TA CE. It is now lost,
              --   and MAC will never be told.

10:07:46.432  [MAC]    timeAlignmentTimer(TAG 0) EXPIRED
10:07:46.432  [MAC]    pTAG out of sync -> ALL TAGs out of sync
                       flush HARQ buffers ........ all serving cells
                       release PUCCH config ...... all serving cells
                       release SRS config ........ all serving cells
                       clear SPS assignments ..... all
                       clear configured UL grants  all
                       N_TA released for TAG 0 and TAG 1
10:07:46.432  [MAC]    UL out of sync on SpCell -> initiate Random Access
                       trigger ................... timeAlignmentTimer expiry
                       ra-Type ................... 4-step (CBRA)
10:07:46.436  [MAC-UL] preamble 12, PRACH SFN 812 slot 19
10:07:46.446  [MAC-DL] RAR, RAPID 12, Timing Advance Command 206
              -- 206 x 512 = 105472 T_c = 53.65 us ~ 8.04 km
              -- essentially unchanged from 12 minutes ago: the UE never
              --   moved. The failure was downlink, not timing.
10:07:46.452  [MAC-UL] MSG3: C-RNTI MAC CE (0x4601) + BSR
10:07:46.462  [MAC-DL] PDCCH to C-RNTI 0x4601 -> contention resolved
10:07:46.462  [MAC]    timeAlignmentTimer(TAG 0) started, ms1920
10:07:46.462  [RRC]    no RLF: RA succeeded, connection intact

Listing 6. The most instructive failure in this document. A stationary UE in good coverage performed a full Random Access procedure because three downlink HARQ attempts failed on the PDSCH that happened to carry a keep-alive control element. The new TA value is the proof: 206 against 205 twelve minutes earlier.

🔍
What You See In Logs

The trace above is what makes timeAlignmentTimer worth understanding. Every visible symptom points at the uplink — RACH, HARQ flush, PUCCH release — and the cause is a lost downlink PDSCH carrying two bytes. If you see RACH from RRC_CONNECTED UEs with healthy measurements, check the downlink BLER on the PDSCHs carrying MAC control elements, and check whether the scheduler is sending keep-alives at less than half timeAlignmentTimer.

18. Release Deltas: Rel-15 to Rel-18

ReleaseChangeWhy it matters when reading timing advance
Rel-1512-bit absolute command in the RAR; 6-bit relative Timing Advance Command MAC CE; up to four TAGs per cell group; timeAlignmentTimer per TAG; n-TimingAdvanceOffsetThe baseline. Everything in §§3–11 is Rel-15 and has not changed.
Rel-16`Absolute Timing Advance Command` MAC CE, introduced for IAB-MT alignmentA 12-bit absolute value can now arrive outside Random Access. A large N_TA change with no preceding preamble is no longer impossible.
Rel-162-step Random Access: successRAR and fallbackRAR both carry a 12-bit TA commandThe initial absolute value can come from MSGB rather than MSG2. Note that MSGA's payload was sent before it.
Rel-16NR-U: uplink transmission also gated by listen-before-talkAn uplink that does not happen is no longer evidence of a timing problem.
Rel-17NTN: ta-Common, ta-CommonDrift, ta-CommonDriftVariation, ephemerisInfo, cellSpecificKoffset, kmac, ntn-UlSyncValidityDuration, UE pre-compensation from GNSSN_TA is now one term of four. The 12-bit field alone no longer describes the total advance (§12).
Rel-17ta-Report — the UE reports the timing advance it appliedTA becomes an explicitly reported observable instead of something inferred from the network side only.
Rel-17FR2-2: 480 and 960 kHz numerologies (µ = 5, 6)Step size drops to 32 and 16 T_c; maximum expressible range drops to 9.4 and 4.7 km. The table in §4 gains two rows that change the answer.
Rel-17RedCap; small data transmission from RRC_INACTIVEA UE can transmit uplink data in a procedure that does not end in RRC_CONNECTED, so a valid N_TA is no longer synonymous with a connected UE.
Rel-18Network-controlled repeaters, with explicit signalling to the repeaterRepeater delay becomes visible to the network rather than being silently folded into every served UE's N_TA.
Rel-18NTN refinements, including support at higher frequencies and improved mobilityMore deployments where the terrestrial intuitions in §4 do not apply at all.

Table 16. Timing-advance changes by release. Confirm feature presence against the UE capability exchange — see the companion 26 UE Capability document — before assuming a field exists.

19. Reading Timing Advance in Logs: A Checklist

1. Identify the numerology first. A T_A of 205 is 53.4 µs at 30 kHz and 106.8 µs at 15 kHz. Nothing else in this checklist is meaningful until you know µ for the uplink the command applies to (§4).

2. Establish whether the value is absolute or relative. A 12-bit field in a RAR, a successRAR, or an Absolute Timing Advance Command MAC CE is absolute. A 6-bit field in a Timing Advance Command MAC CE is a delta around 31. Vendor logs often print both as "TA" (§5).

3. Convert the absolute value to a distance and sanity-check it against RSRP, the cell's known geometry and any other UE in the same sector. A TA-implied distance that is consistently wrong for every UE in a sector points at feeder or repeater delay, not at mobility (§4).

4. Check `n-TimingAdvanceOffset` against the band's duplex mode. This is the cheapest check in the list and it catches the failure mode with the largest blast radius: distance-independent uplink degradation across the whole cell (§7).

5. Resolve the TAG Identity on every command. In a carrier-aggregated UE, corrections addressed to the wrong TAG, or a TAG with no uplink reference signal configured, explain single-carrier uplink problems that otherwise look inexplicable (§9).

6. Do not filter out T_A = 31. Those are keep-alives and they are the record of timeAlignmentTimer being maintained. Their absence over a period longer than the timer is the finding (§6.2).

7. When you see a `timeAlignmentTimer` expiry, look at the downlink. Check PDSCH BLER around the expiry and whether a MAC CE was in flight. The expiry is a symptom; a lost downlink control element is usually the cause (§17.4).

8. Distinguish a pTAG expiry from an sTAG expiry immediately. They cost completely different things — a service outage and a Random Access versus one SCell — and they look identical in a raw MAC log until you read the TAG Id (§10).

9. Correlate correction magnitude against allocation bandwidth. Large, oscillating corrections on a UE that only ever transmits narrowband PUCCH are measurement noise, not movement (§8).

10. For NTN, add up all four components before believing any of them. N_TA is the small residual; ta-Common and the UE's own ephemeris-based term carry almost all of the delay, and neither appears in a MAC CE (§12).

20. Glossary

TermExpansionMeaning in this document
TATiming AdvanceThe mechanism as a whole; loosely, also the command value. Prefer N_TA or T_A when precision matters.
N_TAThe UE's current uplink transmit-timing offset, in units of T_c, maintained per TAG. Not a field on the wire.
T_AThe integer carried in a command: 12 bits absolute (0…3846) in a RAR or absolute MAC CE, 6 bits relative (0…63, 31 = no change) in the ordinary MAC CE.
N_TA_offsetA fixed band- and duplex-dependent constant added to N_TA before transmission; 0 on FR1 FDD, 25600 T_c on FR1 TDD, 13792 T_c on FR2 (§7).
T_cBasic NR time unit1 / (480 000 × 4096) s ≈ 0.509 ns. Every timing-advance quantity in the specification is expressed in it.
T_eUE transmit timing error limitHow accurately the UE must apply the advance it was given TS 38.133 cl. 7.1.2. A fraction of the cyclic prefix, not the whole of it.
TAGTiming Advance GroupA set of serving cells sharing one N_TA and one timeAlignmentTimer because they share one propagation delay.
pTAG / sTAGPrimary / Secondary Timing Advance GroupThe TAG containing the SpCell, and any TAG containing only SCells. TAG Id 0 is always the pTAG.
CPCyclic PrefixThe guard copy prepended to each OFDM symbol; in the uplink it is the entire timing-error budget (§2).
SRSSounding Reference SignalA wideband uplink reference signal the gNB can measure arrival timing from without needing the UE to have data to send.
SpCellSpecial CellThe PCell of a master cell group or the PSCell of a secondary cell group; always in the pTAG.
ta-CommonRel-17 NTN: the delay component common to every UE in a beam, broadcast with its first two time derivatives (§12).

21. References

  • 3GPP TS 38.213Physical layer procedures for control. Clause 4.2 (uplink transmission timing: the N_TA formula, the relative MAC CE arithmetic, and the n + k + 1 application rule), clause 4.1 (timing reference), clause 8 (random access, where the initial command originates).
  • 3GPP TS 38.211Physical channels and modulation. Clause 4.1 (T_c and κ), clause 4.3.1 (uplink frame timing: T_TA = (N_TA + N_TA_offset)·T_c, and N_TA = 0 for PRACH), clause 4.2 (numerologies and cyclic prefix lengths).
  • 3GPP TS 38.321MAC protocol specification. Clause 5.2 (maintenance of uplink time alignment, timeAlignmentTimer and the expiry actions), clause 6.1.2 (R/LCID subheader for fixed-size control elements), clause 6.1.3.4 (Timing Advance Command MAC CE), clause 6.1.3 (Absolute Timing Advance Command MAC CE), clause 6.2.3 / 6.2.3a (MAC RAR and the MSGB RAR variants), Table 6.2.1-1 (DL-SCH LCID values).
  • 3GPP TS 38.133Requirements for support of radio resource management. Clause 7.1.2 (UE transmit timing: the T_e requirement and the N_TA_offset table), clause 7.1.1 (timing advance adjustment accuracy).
  • 3GPP TS 38.331RRC protocol specification. TAG-Config, TAG, TAG-Id, TimeAlignmentTimer, MAC-CellGroupConfig, ServingCellConfigCommon (n-TimingAdvanceOffset, cellSpecificKoffset), NTN-Config and TA-Info (Rel-17), EphemerisInfo.
  • 3GPP TS 38.300NR overall description. Clause 9.2.6 and clause 16 (carrier aggregation and the role of timing advance groups in it).
  • 3GPP TR 38.821Solutions for NR to support non-terrestrial networks. The study behind the Rel-17 timing decomposition in §12.

Companion documents in this set

  • 02 Radio Frame Structure — T_c, κ, numerology and the cyclic prefix arithmetic that §§2–4 build on.
  • 03 Random Access — where the initial absolute command comes from, and the one trigger list that includes timeAlignmentTimer expiry.
  • 05 HARQ — the buffers that a timer expiry flushes, and the Rel-17 disabled-feedback mechanism that NTN needs for the same reason NTN needs ta-Common.
  • 07 MAC PDU and Control Elements — the general subheader and LCID rules that §6.1 specialises.
  • 08 Scheduling — SPS and configured grants, which a timer expiry clears, and the SRS configuration the measurement loop depends on.
  • 11 DRX — a sleeping UE receives no corrections, which is why DRX and timeAlignmentTimer have to be sized against each other.
  • 16 RLM and RLF — where a failed post-expiry Random Access on the SpCell ends up.
  • 22–25 Handover documents — the target cell's absolute TA is acquired inside T304, on the target's n-TimingAdvanceOffset.
  • 26 UE Capability — how to confirm that the Rel-16 and Rel-17 features in §18 are actually supported by the UE in front of you.