Skip to content

Drawing No. EH–CA–012 // Engineering Case Study

Mars Climate Orbiter Unit Conversion Failure

A spacecraft that had operated nominally for nine months was lost at Mars because a ground-software interface supplied small-thruster impulse data in pound-force-seconds while the navigation process expected newton-seconds. The unit mismatch was simple; the mission failure was systemic. This interactive case study follows the interface error, the growing navigation discrepancy, the missed opportunities to detect it, and the engineering controls that should have stopped it.

Prepared by EngineerHub · NASA Mishap Investigation Board-based technical reconstruction · reviewed 11 August 2026

Launch: 11 Dec 1998Loss: 23 Sep 1999Required unit: N·sDelivered unit: lbf·sMismatch: ×4.45Corrected periapsis: ≈57 km

01 // Interactive mission failure replay

Select a stage or run the sequence.

Mars Climate Orbiter — navigation reconstructionMission milestones and periapsis values are documented; geometry and trajectory shapes are schematic and not to scale.
The Phase I board retained uncertainty about the final fate: MCO either was destroyed in the atmosphere or exited back into heliocentric space after atmospheric passage. AMD-event markers and all trajectory geometry are illustrative, not event counts or a scaled orbit reconstruction.
Mars Climate Orbiter approach and navigation failure replaySchematic Mars approach showing planned and corrected trajectories, atmosphere, trajectory correction milestones, repeated small-force events and spacecraft loss.MARSTCM-4 target first periapsis: 226 kmMCO minimum survivable periapsis: 80 kmpost-loss corrected estimate: 57 km
Navigation / mission state
Replay encoding
Planned / target geometry
Navigation solution / modeled path
Corrected post-loss trajectory
Small-force / AMD events

Key mishap-board facts

Launch mass629 kg
MOI main-engine burnplanned 16 min
TCM-4 target periapsis226 km
MCO minimum survivable80 km
Corrected periapsis57 km
Unit factor1 lbf·s = 4.45 N·s

Mission event console — latest stage first

02 // Unit-interface failure explorer

See exactly what the 4.45× mismatch means.

1.0 lbf·s
20 events
Physically equivalent impulse
Value navigation consumes
Modeled fraction of impulse
Scalar aggregate mismatch*
Interface check
Magnitude error
SOFTWARE / DATA INTERFACE — EDUCATIONAL RECONSTRUCTIONLMA SM_FORCESthruster impulseAMD FILESIS requiresN·sJPL NAVassumes N·sINTERFACE CONTRACT1 lbf·s = 4.44822 N·s
Model boundary. This tool demonstrates unit semantics only. The event-count slider is illustrative: the board reported that AMD events occurred 10–14 times more often than the operations navigation team expected, but it did not publish a single historical count here. The scalar aggregate mismatch is not a spacecraft Δv or a trajectory calculation.

03 // Why small forces became a large navigation error

The problem accumulated through repeated, under-modeled momentum-desaturation events.

01 / ASYMMETRIC SPACECRAFTMCO's single solar array created a solar-pressure torque unlike Mars Global Surveyor's more symmetric configuration.
02 / MORE AMD EVENTSReaction-wheel desaturation events occurred 10–14 times more often than the operations navigation team had expected.[1]
03 / WRONG UNIT AT INTERFACESM_FORCES output entered the AMD file in lbf·s even though the interface documentation required N·s.
04 / ΔV MISMODELEDNavigation consumed the numbers as metric, under-modeling each small impulse by about a factor of 4.45.
05 / DISCREPANCY NOT CLOSEDDoppler residuals and different orbit-determination solutions indicated a problem, but the mismatch was not resolved before Mars arrival.

04 // Navigation figures

Documented milestones only — no invented continuous trajectory.

First-periapsis knowledge before and after loss

Target / plannedNavigation estimateCorrected post-loss estimate
View milestone data
MilestonePeriapsisBasis
TCM-4 target226 kmComputed 8 Sep; TCM-4 executed 15 Sep
Week before MOI150–170 kmOperations navigation processing
~1 hour before MOIas low as 110 kmMore accurate tracking data
Post-loss corrected estimate57 kmCorrected small-forces values and all data through loss of signal
Minimum considered survivable80 kmMishap-board threshold
The 150–170 km value is a documented range, not a single point. The chart therefore renders it as a range bar rather than inventing an intermediate estimate.

Unit mismatch magnitude

Physical impulse equivalentNumerical value if passed through unchanged
View conversion
InputCorrect metric valueFaulty consumed valueModeled fraction
1.000 lbf·s4.448 N·s1.000 N·s22.48%
The Phase I report rounded the force conversion to 1 lbf = 4.45 N. The calculator uses the standard conversion 4.44822 for the educational arithmetic.

05 // What actually failed?

This was not an onboard spacecraft software unit mix-up. The mishap board identified a ground-software/interface failure.[1] Lockheed Martin's ground SM_FORCES application reported the impulse-bit data placed in the AMD file in pound-force-seconds, while the Software Interface Specification required newton-seconds. The downstream JPL navigation processing treated the AMD data as though the specified metric units had been supplied.

The unit error was the root cause, not the whole story

The Phase I board listed eight contributing causes:[1] undetected mismodeling of spacecraft velocity changes; navigation-team unfamiliarity with the spacecraft; TCM-5 not being performed; inadequate systems engineering during the transition from development to operations; inadequate communications; insufficient operations-navigation staffing; inadequate training; and verification/validation that did not adequately address ground software.

There were warning signals

During spring and summer 1999, working-level concerns existed about differences between navigation solutions.[1] Doppler residuals associated with the more frequent AMD events were noted but only informally reported. During Mars approach, Doppler-only solutions consistently indicated a closer flight path than combined solutions. The discrepancies were not resolved.

TCM-5 was a missed contingency opportunity

TCM-5 was a contingency option,[4] but NASA's lessons-learned record states that it was not included in the baseline mission-operations timeline, had not been tested for flight-sequence compatibility or mission safety, and was not included in operational readiness testing. With no compelling evidence judged sufficient to accept that late-maneuver risk, the project did not execute TCM-5. The Phase I board listed “TCM-5 not performed” as a contributing cause.

Final fate remains technically uncertain in the Phase I report

After correcting the small-forces data, the board estimated a 57 km initial periapsis, below the 80 km minimum considered survivable.[1] The Phase I report states that MCO either was destroyed in the atmosphere or re-entered heliocentric space after atmospheric passage. Later NASA summaries commonly describe the spacecraft as destroyed, but this page preserves the board's more cautious wording.

07 // The interface that failed

The specification was metric; implementation and verification did not enforce it.

Required interface behavior

SM_FORCESproducerAMD FILEN·sNAVIGATIONconsumerproducer output validated against interface specification
Specified unitN·s
Checkunit-aware
Resultconsistent

Observed failure path

SM_FORCESlbf·sAMD FILEnumber, wrong unitNAVIGATIONassumes N·snumeric compatibility without semantic compatibility
Delivered unitlbf·s
Magnitude error×4.45
Detectionfailed

08 // Eight contributing causes identified by the Phase I board

The unit mismatch was the root cause. Mission loss required multiple engineering and organizational barriers to fail around it.

1 / Velocity mismodeling not detectedSmall spacecraft velocity changes were modeled incorrectly and the discrepancy persisted.
2 / Navigation team unfamiliar with spacecraftThe team underestimated how the spacecraft's asymmetric solar-array configuration drove more frequent AMD events.
3 / TCM-5 not performedThe contingency TCM-5 maneuver was not executed before orbit insertion.
4 / Development-to-operations systems engineeringThe transition did not receive adequate systems-engineering attention.
5 / Inadequate communicationProject elements did not communicate discrepancies and interface assumptions effectively.
6 / Operations navigation staffingThe board identified inadequate staffing as a contributing cause.
7 / TrainingTraining was not sufficient for the operational and software-review demands of the mission.
8 / Ground-software verification & validationV&V did not adequately cover the software path that generated and consumed the small-forces data.

Defense in depth: controls that should stop this class of failure

InterfaceMachine-checkable unit contracts

Carry units as explicit metadata or types. Reject a lbf·s value at an N·s interface rather than accepting an untyped number.

VerificationEnd-to-end interface tests

Test producer → file → consumer chains with known values and independently computed conversions.

NavigationIndependent solution reconciliation

Define thresholds that force closure when Doppler-only, range-only and combined orbit solutions diverge materially.

OperationsClosed-loop anomaly reporting

Informal residual concerns should become tracked anomalies with owners, disposition criteria and documented closure.

ContingencyTCM-5 readiness

Late correction maneuvers must have validated procedures and decision gates before the mission reaches the critical window.

OrganizationSystems engineering across interfaces

Maintain enough staffing, training and mission-systems ownership to bridge contractor, navigation, software and operations teams.

09 // Historical chronology

Date / timeEvent
1995Mars Climate Orbiter and Mars Polar Lander identified for the 1998/1999 launch opportunity.
11 Dec 1998MCO launches from Cape Canaveral on a Delta II.
Spring–summer 1999Working-level concerns arise over differences between navigation solutions and Doppler residuals associated with AMD events.
8 Sep 1999TCM-4 computed to target a 226 km first periapsis after MOI.
15 SepTCM-4 executed as planned.
Week before MOINavigation processing indicates first periapsis has fallen to roughly 150–170 km.
~1 h before MOIMore accurate tracking solution indicates first periapsis as low as 110 km.
23 Sep, 09:00:46 UTCMars Orbit Insertion main-engine burn begins.
09:04:52 UTCCarrier signal disappears at Mars occultation, 49 seconds earlier than predicted.
After expected 21 min occultationSignal is not reacquired; search continues through 25 September.
27 SepOperations navigation consults spacecraft engineers about ΔV modeling discrepancies.
29 SepUnit mismatch discovered: AMD impulse data delivered in lbf·s instead of required N·s.
15 OctNASA establishes the Mishap Investigation Board.
10 Nov 1999Phase I report identifies root cause and eight contributing causes.
13 Mar 2000Phase II project-management report expands the lessons to systems engineering, communication, mission assurance and risk management.

11 // Engineering lessons learned

Mars Climate Orbiter is a systems-engineering case study disguised as a unit-conversion mistake.

Units are part of the data typeA bare number at an interface is incomplete. Quantity, unit, sign convention, reference frame, coordinate system and epoch may all be part of its engineering meaning.
Interface documents must be executable in practiceWriting “N·s” in a specification is not enough if producer, tests and consumer do not verify the requirement end to end.
Small repeated errors can dominateEach AMD event imparted a small impulse, but systematic under-modeling accumulated over a nine-month cruise.
Disagreement between independent solutions is informationPersistent Doppler/range residuals should trigger reconciliation, not normalization of deviance.
Ground software can be mission criticalThe spacecraft performed nominally. Mission loss came through the ground navigation/software chain, demonstrating that criticality follows function, not physical location.
Contingencies must be executable, not theoreticalA maneuver that exists in the mission plan but lacks completed analysis, test, procedures and decision authority may not be usable when the window arrives.
Transition to operations needs systems ownershipInterfaces that were acceptable during development can become mission risks when teams, tools and responsibilities change at handover.
Simple errors require strong organizational barriersThe board's lesson was not that engineers must never make mistakes; it was that projects need processes capable of detecting ordinary mistakes before they become catastrophic.

12 // Frequently asked questions

Common misconceptions and practical lessons.