FIT and PMHF Budget Calculator (ISO 26262)

Free tool

FIT and PMHF Budget Calculator (ISO 26262)

Enter a failure rate, a safe-fault fraction and your diagnostic coverage. The calculator returns the single-point fault metric, the latent-fault metric and the probabilistic metric for random hardware failures, checked against the ISO 26262 targets for your ASIL — plus how much failure-rate budget you have left.

SPFM
target
LFM
target
PMHF
target
Failure-rate splitFITh−1
Safe faults λS
Safety-related λSR
Single-point + residual λSPF+RF
Multiple-point, latent λMPF,latent
Multiple-point, detected
Budget headroom. At this diagnostic coverage, the largest total failure rate that still meets the ASIL B PMHF target is — you are currently at of it.

Runs entirely in your browser. Nothing is uploaded, stored, or sent anywhere.

What these numbers are

FIT — failures in time — is one failure per 109 hours of operation. It is the unit component reliability data arrives in, so it is the unit an FMEDA is built in. 1000 FIT is a failure rate of 10−6 h−1.

ISO 26262 splits a part’s total failure rate into categories. Safe faults cannot violate the safety goal and are set aside. Of what remains, a single-point fault reaches the safety goal with no safety mechanism in the way; a residual fault is the part of a covered fault that the mechanism still misses. A multiple-point fault needs a second, independent fault before anything hazardous happens — and if nobody notices it in the meantime, it is latent.

The three published figures fall out of that split. SPFM measures how much of the safety-related failure rate is not single-point or residual. LFM measures how much of the rest is detected or perceived rather than sitting latent. PMHF is the residual probability, per hour, that random hardware failure violates the safety goal — the one number a reviewer will ask for first.

The ISO 26262 targets

MetricASIL AASIL BASIL CASIL D
SPFM≥ 90%≥ 97%≥ 99%
LFM≥ 60%≥ 80%≥ 90%
PMHF< 10−7 h−1< 10−7 h−1< 10−8 h−1

ASIL A carries no quantitative hardware-architectural-metric or PMHF target. That is not a licence to skip the analysis — the qualitative requirements still apply, and an ASIL A part in a system that later moves to ASIL B has nowhere to hide.

How the calculator works

λ_S = λ × safe  ·  λ_SR = λ × (1 − safe)
λ_SPF+RF = λ_SR × (1 − DC_SPF)
λ_MPF = λ_SR × DC_SPF  ·  λ_latent = λ_MPF × (1 − DC_LF)
SPFM = 1 − λ_SPF+RF / λ_SR
LFM = 1 − λ_latent / (λ_SR − λ_SPF+RF)
PMHF ≈ λ_SPF+RF + λ_latent² × T_life

The PMHF expression has two terms. The first is the single-point and residual rate, which dominates in practice. The second is the dual-point contribution: the probability that two independent latent faults coincide inside the operating lifetime. Because it is second order in λ, it is usually orders of magnitude below the first term — try it, and watch how little the lifetime field moves the answer. That is the correct intuition, and it is why diagnostic coverage on single-point faults buys far more than latent-fault coverage does.

A worked example

Take a 1000 FIT part, half its faults safe, 99% single-point coverage, 90% latent coverage, 10,000 hour life. The safety-related rate is 500 FIT; 1% of that — 5 FIT, or 5×10−9 h−1 — escapes as single-point or residual. SPFM lands at 99%, LFM at 90%, and PMHF at roughly 5×10−9 h−1: inside the ASIL D target of 10−8. The dual-point term contributes about 2×10−11 — three orders of magnitude down, and irrelevant to the verdict.

Now drop single-point coverage to 90%. The escaping rate becomes 50 FIT, PMHF becomes 5×10−8 h−1, and the part fails ASIL D on both SPFM and PMHF while still clearing ASIL B comfortably. One coverage figure moved the achievable integrity level by two grades. That sensitivity is the whole argument for doing the FMEDA before the architecture is frozen rather than after.

What this tool does not do

This is a budgeting aid, not an FMEDA. It will tell you whether a target is plausible and where your headroom is. It is not a submission, and no certification body will accept its output as evidence.
  • It works on a single lumped element. A real FMEDA is built per part, per failure mode, with a distribution across modes — and the rollup is where the arguments happen.
  • Diagnostic coverage is an input here. Earning a DC figure is most of the actual work: it has to be argued per failure mode against a claimed safety mechanism, not asserted.
  • The dual-point term assumes the two latent faults are independent and that the multiple-point fault detection interval is the full lifetime. A shorter, argued detection interval lowers it further — it is already negligible.
  • Base failure rates must come from a recognised source (IEC 62380, SN 29500, FIDES, or supplier data) with the environmental and mission profile stated. Those assumptions are challenged more often than the arithmetic.
  • Dependent-failure analysis, safety-mechanism latency, and the qualitative ISO 26262 requirements sit entirely outside this calculation.

Where this fits

FMEDA and FMEA review is one of our primary service lines, at board and silicon level. If the numbers above are not landing where you need them, the usual next step is a gap review: we read the analysis you already have and tell you what an auditor will find missing, before the certification body arrives. It runs one to two weeks and ends in a written report you keep.

Every block in our safety soft-IP catalog ships with its FMEDA and its published SPFM/LFM figures, so you can see what these numbers look like on real hardware rather than on a worked example.

More free tools

Each of these runs entirely in your browser. Nothing is uploaded, stored or sent anywhere, and none of them needs an email address.

See all 9 engineering tools →