A NASA small business R&D contract pulls fault management logic into the same digital systems engineering model that defines a spacecraft, with NASA's HelioSwarm solar wind probe as the first test bed.
When a spacecraft is millions of miles from Earth, a round-trip radio signal can take twenty minutes. Waiting for a human in mission control to diagnose a fault is not an option at that distance. NASA is preparing for that constraint by building spacecraft whose failure-response logic is generated from the same engineering model that defines the hardware, rather than patched on after the design is done.
Today's fault management has historically been bolted on after the nominal system is designed, which NASA itself calls a "bandage fix". The Science Mission Directorate is integrating Model-Based Systems Engineering (MBSE) with fault management so that a failure modes and effects analysis and the fault trees that drive recovery are pulled directly out of the systems model during design and verification.
A Phase II Small Business Innovation Research contract with Qualtech Systems Inc. is where the work is landing in software. Qualtech, whose TEAMS toolset is itself the product of earlier agency SBIR funding, has integrated its fault-management toolchain with the MBSE pipeline so the two share data instead of exchanging flat files. NASA demonstrated the pipeline on the HelioSwarm heliophysics mission, a planned swarm probe for studying solar-wind turbulence. Engineers fed HelioSwarm's early design information in and let the model generate a complete failure modes analysis and fault trees, instead of writing them by hand after the design froze.
A traditionally bolted-on fault tree is a separate document the flight software has to consume as input. A model-generated one is structurally the same object as the rest of the system description, so a change to the hardware model ripples into the recovery logic, and the verification campaign runs against the same source of truth. That keeps recovery logic current as the design evolves, and tightens the loop between the people who design the spacecraft and the people who plan for what happens when something breaks.
NASA is hardening the same autonomy stack in parallel for crewed deep-space work. The Orion program has built a SysML model and digital twin of the crew vehicle for Artemis I. Gateway, the lunar-orbit outpost for Artemis crews, has a Vehicle Systems Manager demonstrated for data-driven fault recovery, planning, diagnosis, and execution, per follow-on NTRS work on data-driven recovery and NTRS reporting on planning, diagnosis, and execution. The science-mission MBSE-plus-fault-management effort is the heliophysics-and-planetary counterpart to those crew-vehicle programs; together they push the same playbook of designing failure response the same way the system is designed across NASA's deep-space portfolio.
HelioSwarm is pre-launch; the demonstration ran on early design data, not flight hardware. The Qualtech Systems TEAMS toolset is commercially available, but how broadly the approach rolls out beyond that one SBIR contract is not yet shown. Federal MBSE adoption is in early stages agency-wide, which puts the science-mission work near the front of the curve rather than at the back.
The next concrete checkpoint is whether model-generated fault trees move from demonstration to a primary flow on a flying mission. The team's published next step is to start that handoff once HelioSwarm's design is firm enough to lock the recovery logic against the verified model.