Abstract: Spoofing attacks against civilian GNSS receivers have grown more common, especially near conflict zones where they now disrupt civil aviation, maritime operations, and critical infrastructure on a daily basis. Spoofing is possible because legacy civil GNSS signals are largely predictable in both their navigation data and ranging codes, allowing an attacker to forge a signal that imposes a false position and time on an unsuspecting receiver. Cryptographic authentication schemes such as Galileo's Open Service Navigation Message Authentication (OSNMA) mitigate this threat by verifying the authenticity of the navigation data. The ranging code itself, however, remains unprotected. To close this gap, Galileo is introducing a Signal Authentication Service (SAS) in the E6-C signal, which directly authenticates ranging measurements. SAS is currently transmitted by only two satellites in an elliptical orbital plane, of which at most one is visible at a time, meaning a full position solution is not yet possible; however, a georeferenced receiver can still obtain an authenticated time solution. This paper presents, to the authors' knowledge, for the first time, a timing solution computed from an authenticated civil GNSS signal. We develop a snapshot software receiver implementing a simplified version of the Galileo SAS protocol to compute the receiver clock bias from an authenticated pseudorange, using radio-frequency data recorded with an engineering prototype software-defined radio receiver from Septentrio. We evaluate the resulting timing solution using recordings from both SAS-capable satellites collected at different locations, demonstrating the feasibility of authenticated timing ahead of full SAS operational deployment.