Mean Time To Dangerous Failure
Is MTTFd the same as MTTF?
No. MTTF is mean time to any failure; MTTFd counts only dangerous failures.
Is MTTFd a rate or a time?
It is a time-based metric, usually expressed in years, and it is the reciprocal of the dangerous failure rate under functional safety assumptions.
How does MTTFd relate to ISO 13849-1?
ISO 13849-1 uses MTTFd as an input to estimate the reliability contribution of each channel in a safety-related control system, then combines it with diagnostic coverage and structure to derive PL.
Mean Time to Dangerous Failure (MTTFd) is a reliability metric estimating the average operating time until a safety-related component experiences a dangerous failure that can create a hazardous condition. It is a core input to ISO 13849-1 and IEC 62061 for determining Performance Level or Safety Integrity Level in machinery safety.
On the shop floor, MTTFd is used when selecting and validating safety devices like interlock switches, light curtains, safety relays, contactors, valves, and safety PLC inputs/outputs. Engineers use component MTTFd values, along with diagnostic coverage and architecture, to determine the Performance Level (PL) or Safety Integrity Level (SIL) a safety function can achieve. For example, a machine guarding circuit may need components with sufficiently high MTTFd so the complete safety-related control system meets the target PL from the machine risk assessment. In Canadian practice, MTTFd is relevant where companies design or verify machine safeguarding under CSA/ISO-aligned methods, providing engineering evidence that the safeguarding solution is robust for the hazard exposure.
Treating MTTFd as total reliability instead of dangerous-failure reliability, counting all failures and corrupting safety calculations.
Using catalog values without verifying operating conditions, as MTTFd depends on actual duty cycle, load, and operating frequency.
Ignoring MTTFd in the full safety chain, since a high MTTFd component alone does not ensure compliance; final PL/SIL depends on architecture, diagnostics, and validation of the whole system.