View Video Presentation: https://doi.org/10.2514/6.2022-4368.vid Space systems are often new designs that lack the required mission reliability. The usual approach is to improve reliability by adding redundancy, either by using parallel online systems or by providing spares. NASA has often required designs to be two fault tolerant, meaning that the system can operate satisfactorily after experiencing two failures. At the subsystem level, two fault tolerance requires providing triple redundancy, three sets of subsystems. The two fault tolerance approach often does not achieve the required reliability at the minimum cost. There are several reasons for this. It is often assumed that redundancy can be implemented without introducing new failure mechanisms. The process of failure detection and redundant subsystem switching may fail. In addition to the expected random failure modes, the redundant subsystems may have Common Cause Failures (CCFs) which defeat redundancy. System level failures, environmental challenges, and operator errors can cause intrinsically reliable systems to fail. Instead of increasing fault tolerance by using redundancy to improve reliability, systems should be designed by calculating their failure probability. Although it is well known that two fault tolerance is too simple, and it has been criticized and corrected in some NASA engineering, it is still sometimes used as NASA’s standard approach.