1130 updates.pdf
PDF 952 KB Posted
- Attached to
- Commercial Low Earth Orbit (LEO) Development Program Phase 2 Requirements and Safety Technical Interchange Meeting Federal contract opportunity
- Solicitation number
- 80JSC025REQ_SAFETY_TIM
About this file
This is a presentation file discussing updates and evaluations to safety requirements for NASA's Commercial LEO Development Program (CLDP), specifically focusing on RFI 3:1130 definitions and requirements. The presentation addresses key safety aspects including catastrophic hazard definitions, two-failure tolerance requirements, and loss of crew/mission approaches.
The document outlines several significant changes and clarifications: deleting duplicative catastrophic definitions, confirming CLDP-REQ-3102 will be released to partners in late CY24, maintaining single failure tolerance requirements for critical hazards, and not allowing corrective maintenance as a hazard control. It details the rationale for maintaining two-failure tolerance requirements for catastrophic hazards while providing flexibility through verified evacuation methods. The presentation also explains the approach to Loss of Crew and Loss of Mission requirements, noting that over 80% of ISS risk in both categories comes from MMOD (Micrometeoroid and Orbital Debris) and crew medical events. The document includes assumptions about legacy vehicles, ISS heritage payloads, and the expectation that partners will be at PDR+ level of maturity at contract award.
View the file
Other files for this federal contract opportunity
Show all 24
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
COMMERCIAL LEO
D E V E L O P M E N T P R O G R A M
Catastrophic definition
• Comment: Definition of catastrophic is inconsistent with catastrophic event
• Concur: Recommend deleting the definition of catastrophic.
Catastrophic event definition covers the content and having definitions for catastrophic and catastrophic event is unnecessarily duplicative
• RFI 3:1130 Definition
• Catastrophic: The loss of the vehicle, or a serious injury or fatality.
• Catastrophic Event: An event resulting in the death or permanent disability of a crewmember or an event resulting in the unplanned loss/destruction of a major element of the CLDS during the mission.
• Catastrophic Hazard: Any hazard that, when uncontrolled, results in a catastrophic event.
P R O G R A M
CLDP-REQ-3102 release date
• Comment: When will CLDP-REQ-3102 be released?
• Recommendation: Concur with observation. Released to
Partners last half of CY24
• RFI 3:1130 language: The CLDS shall be designed such that no two independent failures, or two Operator errors, or one Operator error in presence of a single failure can result in an exposure to a catastrophic hazard, except for select Design for Minimum Risk items defined and approved in accordance with CLDP-REQ-3102 (TBR) where applicability to Visiting Vehicles is only during Integrated Operations.
P R O G R A M
Two failure tolerance
• Comment: Request flexibility/relief from 2 failure tolerance to a catastrophic hazard requirement
• Comments requesting separating operator error from the 2 failure tolerance requirement / eliminating duplication of operator error requirements
• Comments requesting additional FT credit when Emergency systems are available
• Recommendations
• Multiple comments requesting flexibility/relief from 2 failure tolerance to a catastrophic hazard requirement
• Comments requesting additional FT credit when Emergency systems are available
• Update the definition of Catastrophic to remove loss of destination
• Add an exception to the Emergency Systems to address crew evacuation as a third control to a catastrophic hazard
• Comments requesting separating operator error from the 2 failure tolerance requirement / eliminating duplication of operator error requirements
• Accept. 1130 CR added requirements that resulted in duplication
P R O G R A M
Two failure tolerance (cont)
• RFI 3: 1130 language
• Definitions:
• Catastrophic Event: An event resulting in the death or permanent disability of a crewmember or an event resulting in the unplanned loss/destruction of a major element of the CLDS during the mission.
• Catastrophic Hazard: Any hazard that, when uncontrolled, results in a catastrophic event.
• The CLDS shall be designed such that no two independent failures, or two Operator errors, or one Operator error in presence of a single failure can result in an exposure to a catastrophic hazard, except for select Design for Minimum Risk items defined and approved in accordance with CLDP-REQ-3102 (TBR) where applicability to Visiting Vehicles is only during Integrated Operations.
• FAILURE TOLERANCE WITHOUT EMERGENCY SYSTEMS - The CLDS shall provide the appropriate failure tolerance without the use of emergency equipment and systems.
P R O G R A M
Two failure tolerance (cont)
• Updated 1130 language
• FAILURE TOLERANCE TO CATASTROPHIC EVENTS – The CLDS shall be two failure tolerant to a catastrophic hazard, except for Design for Minimum Risk items defined and approved in accordance with CLDP-REQ-3102 - CLDP Hazard Analysis and Safety Process Requirements, where applicability to Visiting Vehicles is only during Integrated Operations.
• FAILURE TOLERANCE WITHOUT EMERGENCY SYSTEMS – The CLDS shall provide the required level of failure tolerance for critical and catastrophic hazards without the use of emergency equipment and systems except for a verified evacuation method is acceptable as a third control to catastrophic hazards for the Destination.
• Catastrophic event – An event with the potential for loss of life or permanently disabling injury or an event that results in the loss of a crew return vehicle
• Verified Evacuation Method – A verified evacuation method demonstrates the ability of the destination systems to alert the crew to a potentially catastrophic event and allow for the crew involved in the worst case activity (e.g., sleeping, maintenance, exercise, payload ops) to safe their area, translate to the crew return vehicle, undock, departure, entry, descent, landing, recovery and handover of the NASA crew to NASA.
P R O G R A M
SFT to Critical Hazards
• Comments:
• Inclusion of Human error in the Critical Hazard requirements is duplicative of other human error requirements
• Reduce/change the critical hazard FT requirement from 1 FT to Critical hazard are controlled
• Recommendations:
• Remove operator error from critical hazard requirement
• Update the definition of a critical hazard to narrow the impact
• RFI 3: 1130 Language
• Critical hazard - A nondisabling personnel injury, severe occupational illness; loss of mission or the inability to support a crewed mission over the planned mission duration; loss of services (either power, data, or thermal) to more than 50% of the allocated payload locations.
• FAILURE TOLERANCE TO CRITICAL HAZARDS - The CLDS shall be designed such that no single failure or single operator error can result in a Critical Hazard, excluding launch vehicles.
• Updated 1130 language
• Critical hazard - A hazard with a potential for non-disabling personnel injury or severe occupational illness; loss of Destination, mission, or the ability to support a crewed mission over the planned mission duration.
• FAILURE TOLERANCE TO CRITICAL HAZARDS - The CLDS shall be single failure tolerant to Critical Hazards, where applicability to Visiting Vehicles is only during Integrated Operations.
P R O G R A M
Rationale for maintaining SFT to Critical Hazards
• Pro – Clear requirement on what is needed/expected to protect against the occurrence of critical hazards
• Pro – Provides emphasis on the importance of mission success
• Pro – Can still use financial incentives to encourage emphasis on mission success
• Pro – Most cases are enveloped as part of the control of catastrophic hazards
• Pro – Avoids de-crewing after a single failure
• Pro – Loss of payload risk can be mitigated through contract payment structure
• Con – Less flexibility than other options
• Con – Could result in additional mass/complexity to meet requirements
P R O G R A M
Corrective maintenance as a hazard control
• Comment: Request the use of corrective maintenance as a leg of failure tolerance
• Recommendation: Do not allow corrective maintenance as a hazard control.
Provide explanation to partners that maintenance is not a guaranteed timely restoration of a function. Maintenance can be used as part of variance rationale.
• Hardware can be DOA
• Dormant failures occur (although at a reduced rate)
• Induced failures occur
• No way to verify the functionality of a stowed spare without installing it
• Infant mortality occurs
• Functional failures are not always limited to ORUs or can propagate to non ORU components (hoses, QDs, wire harnesses, connectors)
• Troubleshooting can require significant crew time
• Restoration and maintenance can take significantly longer than forecast (stripped/ bound fasteners, as flown build doesn’t match ground documentation, locating and accessing spares and tools can take a significant amount of time (equipment not where it’s “supposed” to be, needed items stowed in difficult to access areas (under multiple stowage bags, area where multiple actions are required to access it)
P R O G R A M
2 FT versus a minimum of Single FT
• 2 failure tolerance
• Less mass, but higher LoM risk than a 2 failure tolerance without the exception for crew return.
• Able to de-emphasize LoC/LoM as an early design input
• 2 failure tolerance still required for loss of crew.
• Effectively single failure tolerance for Catastrophic hazards with a longer time to effect
• Less insight required to certify design with 2 failure tolerance
• Closer to the requirements levied on CD-ISS
• Avoids scenario where the second failure results in an immediate loss of crew
• Minimum of Single FT
• Language lacks clear requirements for when greater than SFT is required
• Late identification of a need for additional failure tolerance results in a cost bearing change and impacts to schedule
• Greater design flexibility
• Higher reliance on LoC/LoM Metrics
P R O G R A M
Loss of Crew/Loss of Mission Metrics in lieu of Failure tolerance
• Comment: LOC/LOM should be allowed as an alternative to 2 failure tolerance
• Recommendation: Continue to work with HQ on PRA expectations and use PRA metrics as an input to the acceptability of a failure tolerance variance
P R O G R A M
Loss of Crew Approach – Destination
• Loss of Crew is captured in the definition of a catastrophic hazard
• An event with the potential for loss of life or permanently disabling injury or an event that results in the loss of a crew return vehicle.
• Controls and mitigations to prevent Loss of Crew
• Two failure tolerance to Loss of crew in lieu of Human Rating’s “a minimum of Single Failure
Tolerance”
• A verified evacuation method is acceptable as a third control to hazards whose only catastrophic effect is loss of crew.
• Crew survivability methods/actions/procedures are required for hazardous substance release
(gas, liquid, particulate), depress, fire, Loss of Attitude Control (LOAC), and medical emergency (emergencies)
• CLDP-REQ-1130 requirements for MMOD PNP and collision avoidance (PDAM)
• Quantitative assessment of medical risk
• Failure tolerance variances are NASA approved and include a NASA risk assessment (PRA where applicable)
• Post certification mission to mission risk monitoring
• Hazard analysis and CoFR address mission unique operations and deltas from the certified design
Note: Greater than 80% of ISS Loss of Crew risk is accounted for by MMOD and Crew medical events
P R O G R A M
Rationale for Destination Loss of Crew approach
• Approach selected to provide clear requirements on minimum levels of failure tolerance for Loss of Crew
• Not dependent on engineering judgement or PRA to determine where additional failure tolerance is required
• Accounts for providers being at PDR+ level of maturity at contract award
• NASA PRA not in the critical path for failure tolerance decisions
• Avoids having to prove a design is not safe enough to drive additional failure tolerance
• Places emphasis on early identification of key Failure Tolerance trades
• Allows design flexibility for hazards with long time to effects
• Avoids being zero failure tolerant to an immediately catastrophic failure after the first failure
• Approach not impacted by commercial provider unique services
• Key contributors to loss of crew (MMOD and Crew Medical Event) still monitored to understand how risk is evolving
• Provides additional robustness for a destination with multi-year, continuous operations without the ability to return for refurbishment
• Limited hardware and systems available with run time in a CLD application
• Reliance on reliability predictions instead of demonstrated reliability
• Insufficient time to validate reliability prediction prior to the planned start of services
• Limited time for integrated system test prior to launch
P R O G R A M
Loss of Mission Approach – Destination
• Loss of Mission is captured in the definition of a critical hazard
• A hazard with a potential for non-disabling personnel injury or severe occupational illness; loss of Destination, mission, or the ability to support a crewed mission over the planned mission duration
• Controls and mitigations to prevent Loss of Mission
• Single failure tolerance to critical hazard in lieu of a quantitative requirement
• CLDP-REQ-1130 requirements for MMOD PNP and collision avoidance (PDAM)
• Quantitative assessment of medical risk
• Failure tolerance variances are NASA approved and include a NASA risk assessment (PRA where applicable)
• Leverage contract payment structure to incentivize meeting NASA requirements (time on orbit, facility up time, crew time available for utilization)
• Similar to Cargo Resupply Services Contract approach
• Post certification mission to mission risk monitoring
• Hazard analysis and CoFR address mission unique operations and deltas from the certified design
Greater than 80% of ISS Loss of Mission risk is accounted for by MMOD and Crew medical events NOTE: Loss of destination is not considered catastrophic in this approach which is different than ISSP concentrating requirements on crew safety.
P R O G R A M
Rationale for Destination Loss of Mission approach
• Approach provides a failure tolerance requirement for Loss of Mission
• Not dependent on engineering judgement or PRA to determine where failure tolerance is required
• Accounts for the fact that providers are expected to be a PDR+ level of maturity at contract award
• NASA PRA not in the critical path for failure tolerance decisions
• Less likely to identify requirements for additional failure tolerance and associated cost and schedule impacts post contract award
• Providers are not penalized for larger crew sizes (Loss of mission due to crew medical event is directly related to crew size)
• Approach not impacted by commercial provider unique services
• Proposed contract payment structure to reimburse based on mission metrics provides incentives to reduce likelihood of Mission impacts (time on orbit, facility up time, crew time available for utilization)
• Key contributors to loss of mission still monitored to understand how risk is evolving (MMOD and Crew Medical Event)
• Provides for additional robustness for a destination with multi-year, continuous operations
• Limited hardware and systems available with run time in a CLD application
• Reliance on reliability predictions instead of demonstrated reliability
• Insufficient time to validate reliability prediction prior to the planned start of services
• Limited time for integrated system test prior to launch
P R O G R A M
• Legacy visiting vehicles (crew and cargo) will be used early in CLD operations
• Minimize delta certification efforts for CLDS
• Avoid administrative changes that drive rework of existing certification products
• ISS heritage payloads expected as a part of NASA Utilization
• Avoid NASA driven changes to certification
• Provider base has multiple ISS heritage Partners
• Aligning with ISS processes where practical will facilitate onboarding Partners and maintaining clear expectations
• CD-ISS has existing requirements for certification
• Minimizing the significant deltas (not related to Human Rating or CLD utilization) between the CERD and overall CLD approach improves competitiveness for Phase 2
• NASA has an influence opportunity through the SAA’s
• Partners will be PDR+ at CLD Contract award
• NASA is one of many customers
• NASA will not own or operate any of the systems (Cargo, Destinations, or Crew Vehicles)
Assumptions and Considerations
| Slide Number 1 |
| Catastrophic definition |
| CLDP-REQ-3102 release date |
| Two failure tolerance |
| Two failure tolerance (cont) |
| Two failure tolerance (cont) |
| SFT to Critical Hazards |
| Rationale for maintaining SFT to Critical Hazards |
| Required controls for catastrophic hazards |
| Corrective maintenance as a hazard control |
| 2 FT versus a minimum of Single FT |
| Loss of Crew/Loss of Mission Metrics in lieu of Failure tolerance |
| Loss of Crew Approach – Destination |
| Rationale for Destination Loss of Crew approach |
| Loss of Mission Approach – Destination |
| Rationale for Destination Loss of Mission approach |
| Slide Number 17 |
| Assumptions and Considerations |
File details come from the government source that posted it. Updated .