Skip to main content
Concept guide · ISO 26262-5 §8-9 · 10 chapters

FMEDA: Quantitative Hardware Safety Analysis

Master the quantitative engine of ISO 26262-5: turn per-mode failure rates in FIT, failure-mode distributions, and diagnostic coverage claims into the SPFM, LFM, and PMHF metrics that decide whether a hardware design meets its ASIL target.

Chapters
10
Chapters
Hardware Metrics
3
Hardware Metrics
Reliability Unit
FIT
Reliability Unit
Interactive Visuals
6
Interactive Visuals
Included inExpert
Why this course · ISO 26262, Part 5, Clause 8-9

Why it pays for itself

Compute the three hardware metrics

Roll per-mode failure rates up into SPFM, LFM and PMHF using the Annex C equations, demonstrated on a compact numeric example, and check the results against the ASIL B, C and D targets.

Classify every fault correctly

Apply the decision tree that sorts each failure mode into safe, single-point, residual or multiple-point fault - the classification step where most FMEDAs quietly go wrong and metrics become indefensible.

Defend diagnostic coverage claims

Match safety mechanisms such as range checks, watchdogs and lockstep to the low, medium and high coverage tiers, and back each claimed percentage with fault-injection evidence instead of data-sheet optimism.

After the course

What you’ll be able to do

Rate every failure mode in FIT

Pull justified base failure rates from approved handbooks and correct them for the vehicle mission profile.

Classify faults correctly

Apply the decision tree to separate safe, single-point, residual, and latent multiple-point faults against a defined safety goal.

Defend diagnostic coverage claims

Match safety mechanisms to coverage tiers and back each percentage with fault-injection evidence rather than assumption.

Compute the three hardware metrics

Aggregate FMEDA data into SPFM, LFM, and PMHF and check the results against the relevant ASIL targets.

Build and review an FMEDA spreadsheet

Lay out columns, run the analysis workflow, and audit a completed FMEDA for the common metric-invalidating errors.

The curriculum · 10 chapters

Chapter by chapter

  1. 01

    What FMEDA Is

    Positions Failure Modes, Effects and Diagnostic Analysis (FMEDA) as the quantitative, coverage-aware extension of FMEA that feeds the mandatory hardware metrics of ISO 26262-5.

    • FMEDA versus FMEA: qualitative ranking versus quantitative metric inputs
    • Inductive (bottom-up) analysis complementing deductive Fault Tree Analysis (FTA)
    • Living document refined from hardware concept through verification and maintenance
  2. 02

    Failure Rates and FIT

    Defines the FIT unit (one failure per 10^9 operating hours), the recognised reliability handbooks, mission-profile correction, and the split of total lambda into safe and dangerous fractions.

    • FIT to lambda conversion and the constant hazard rate assumption
    • Source handbooks: SN 29500, IEC TR 62380, FIDES, MIL-HDBK-217F, supplier data
    • Temperature and stress derating tied to the vehicle mission profile
  3. 03

    Failure-Mode Distribution

    Shows how a component lambda is apportioned across its individual failure modes by percentage, then each mode classified as safe or dangerous against the safety goal in scope.

    • Distribution percentages applied to a worked current-sense resistor example
    • Standard failure-mode libraries by component family
    • Handling shared hardware across multiple safety goals
  4. 04

    SPF, RF, and MPF Faults

    Classifies every failure mode as Safe, Single-Point Fault, Residual Fault, or Multiple-Point Fault using a decision tree, and explains the latent multiple-point case.

    • The four fault classes and a step-by-step classification decision tree
    • Single-Point Fault versus Residual Fault distinguished by safety mechanism presence
    • Latent multiple-point faults driving the Latent Fault Metric (LFM)
  5. 05

    Diagnostic Coverage

    Covers how a safety mechanism reduces the dangerous undetected failure rate, the low, medium, and high coverage tiers, and the evidence needed to defend a diagnostic coverage claim.

    • Diagnostic coverage defined as the detected fraction of a dangerous failure rate
    • Indicative coverage values for common mechanisms (range check, watchdog, lockstep)
    • Credible evidence: fault injection over optimistic data-sheet assertions
  6. 06

    Deriving SPFM, LFM, PMHF

    Rolls FMEDA data up into the three mandatory metrics using the Annex C equations, then demonstrates the aggregation on a compact three-component numeric example.

    • Single-Point Fault Metric and Latent Fault Metric from per-mode lambda sums
    • Probabilistic Metric for random Hardware Failures (PMHF) in FIT per hour
    • Metric targets keyed to ASIL B, C, and D
  7. 07

    Building the FMEDA

    Lays out the FMEDA spreadsheet column structure, the analysis workflow from bill of materials to frozen metrics, and an annotated table for an EPS phase-monitoring circuit.

    • Column structure from component and lambda through mode, class, and coverage
    • Annotated example table for an Electric Power Steering monitoring circuit
    • Build process: enumerate, rate, distribute, classify, claim, aggregate
  8. 08

    Worked Example

    Walks an end-to-end FMEDA for a small ADAS perception subsystem (microcontroller, sensor, power supply), computing the metrics against an ASIL B safety goal.

    • Roughly 260 FIT split across microcontroller, sensor, and power supply
    • SPFM near 96.8 percent and LFM near 97.3 percent against ASIL B and C targets
    • Observations on which modes dominate the residual fault budget
  9. 09

    Pitfalls and Review

    Catalogues the common errors that invalidate FMEDA results, from optimistic coverage claims to under-counted latent faults, and supplies a practical review checklist.

    • Optimistic diagnostic coverage and incomplete failure-mode enumeration
    • Wrong distributions, under-counted latent faults, double-counted coverage
    • Reviewer checklist for auditing a completed FMEDA
  10. 10

    Data Sources and Tools

    Surveys the reliability prediction handbooks, automotive mission-profile standards, FMEDA tooling, and how the per-mode failure rates feed quantitative Fault Tree Analysis.

    • Reliability handbooks and mission-profile definitions for passenger cars
    • Dedicated FMEDA tools versus spreadsheet-based analysis
    • Per-mode FIT values supplying cut-set probabilities for quantitative FTA
Diagrams and Visuals

Not just text: the visual toolkit

FIT Rate Explorer

Interactive view of how temperature, stress, and mission profile move a component failure rate across its useful-life region.

Failure-Mode Distribution Pie

Splits a single component lambda across its failure modes and shades the safe versus dangerous fractions.

Fault Classification Decision Tree

Branching flow that sorts each failure mode into Safe, Single-Point, Residual, or Multiple-Point fault.

Diagnostic Coverage Visualizer

Shows a safety mechanism carving the detected portion out of a dangerous failure rate at low, medium, and high tiers.

Metrics Roll-up Calculator

Aggregates per-mode rates into Single-Point Fault Metric, Latent Fault Metric, and PMHF against ASIL targets.

PMHF Budget Timeline

Tracks how single-point and latent contributions accumulate into the probabilistic hardware failure budget over operating life.

Worked Example

ADAS Perception Subsystem FMEDA

A complete FMEDA for a small automatic emergency braking perception subsystem (microcontroller, sensor, power supply) evaluated against an ASIL B safety goal, carried from per-component rates through to final metrics.

  • Total dangerous-relevant rate of roughly 260 FIT distributed across the three elements
  • Each component lambda split into failure modes and classified as safe, single-point, residual, or latent
  • Diagnostic coverage claimed per mechanism (range checks, watchdog, lockstep) and applied to dangerous modes
  • Single-Point Fault Metric computed near 96.8 percent against the ASIL B target
  • Latent Fault Metric computed near 97.3 percent with the ASIL C target as reference
  • PMHF rolled up in FIT per hour and compared to the safety goal budget
Subsystem Metric Summary
SPFM = 96.77 percent (meets ASIL B)

Unlock the full FMEDA table and PMHF rollup

Built for

Who this guide is for

  • Hardware safety engineers building their first FMEDA from a bill of materials
  • Reliability engineers moving from qualitative FMEA into quantitative ISO 26262-5 analysis
  • Reviewers auditing a supplier FMEDA for optimistic coverage or under-counted latent faults
  • Engineers whose SPFM or PMHF misses its ASIL target and who need to find out why

Frequently Asked Questions

Common questions about FMEDA: Quantitative Hardware Safety Analysis

FMEDA (Failure Modes, Effects and Diagnostic Analysis) is the quantitative hardware safety analysis that feeds the mandatory metrics of ISO 26262-5. It extends classical FMEA with two quantitative dimensions: a failure rate in FIT for every component, apportioned across its failure modes, and a diagnostic coverage claim for every safety mechanism that detects those modes. Each failure mode is classified as safe, single-point, residual or multiple-point against the safety goal in scope, and the results roll up into the Single-Point Fault Metric (SPFM), the Latent Fault Metric (LFM) and the PMHF, which decide whether the hardware design meets its ASIL target.
FMEA is qualitative: it ranks failure modes by severity, occurrence and detection to prioritize design improvements, and it stops at ranking. FMEDA is quantitative and coverage-aware: it assigns each failure mode a real failure rate in FIT from reliability handbooks, splits the rate into safe and dangerous fractions, credits each safety mechanism with a diagnostic coverage percentage, and aggregates everything into SPFM, LFM and PMHF. An FMEA tells you where to worry; an FMEDA tells you whether the design numerically meets the ISO 26262-5 targets for its ASIL - and it is a living document, refined from hardware concept through verification.
ISO 26262-5 sets the Single-Point Fault Metric targets at 90 percent for ASIL B, 97 percent for ASIL C and 99 percent for ASIL D, and the Latent Fault Metric targets at 60, 80 and 90 percent respectively. The PMHF (probabilistic metric for random hardware failures) target is below 100 FIT for ASIL B and C and below 10 FIT for ASIL D. ASIL A has no required metric evaluation. The guide works a full ADAS perception subsystem example, computing SPFM near 96.8 percent against an ASIL B goal so you see exactly how the equations behave on real numbers.
One FIT is one failure per 10^9 device operating hours - the base unit for every rate in an FMEDA. Base failure rates come from recognised reliability handbooks such as SN 29500, IEC TR 62380, FIDES and MIL-HDBK-217F, or from supplier data, and must then be corrected for the vehicle mission profile: temperature, stress and derating change the number substantially. The component rate is then apportioned across its individual failure modes by percentage using standard failure-mode distributions, and each mode is classified as safe or dangerous against the safety goal being analyzed.
The guide has 10 chapters, from FIT rates and failure-mode distributions through fault classification, diagnostic coverage and the metric equations, to building and reviewing the FMEDA spreadsheet itself. Six interactive visuals accompany the chapters, and an end-to-end worked example carries an ADAS perception subsystem - microcontroller, sensor and power supply, roughly 260 FIT - from per-component rates to final SPFM, LFM and PMHF results. A free account starts you off, and the Pro and Expert plans unlock more of the library.

Start the course today

A free account unlocks one full concept guide, 3 work product templates, 1 guided process, the Markov simulator, and 5 practice exams per month. The Pro and Expert plans unlock more of the 78-guide library. No credit card required.