What you will learn
By the end of this topic, you should be able to distinguish reliability, durability and environmental robustness; define a defensible service-life profile; identify degradation mechanisms; write measurable requirements; plan representative and accelerated tests; justify samples and confidence; connect failures to risk; preserve critical design features in production; and use field evidence to maintain the reliability case.
Reliability, durability and robustness answer different questions
Reliability
What is the likelihood that the device performs its required functions, under stated conditions, for a stated period or number of demands?
Durability
Can the device withstand accumulated use, wear, cleaning, maintenance and repeated loading for its intended life?
Environmental robustness
Does the device remain safe and effective after foreseeable temperature, humidity, shock, vibration, contamination, transport and storage exposure?
Safety relationship
Which failures or degradations could lead to hazardous situations, loss of essential performance or misleading output?
The three concepts overlap, but they are not interchangeable. A mechanism may survive a vibration test yet wear out too early; a device may meet average life but fail unpredictably in a humid environment; a protective function may operate reliably while a non-safety feature degrades more often.
State the required function, conditions and life before selecting a test. Reliability evidence is meaningful only when it represents the device, stresses and usage being claimed.
Define intended life as an engineering model
“Expected lifetime” is not a marketing phrase to be decided after testing. It is a set of assumptions about calendar time, operating hours, cycles, procedures, patients, actuations, charging, cleaning, transport, maintenance and permitted replacement.
- Define shelf life, transport and storage duration separately from service life.
- Describe daily, weekly and lifetime duty cycles, including peak and unusual demand.
- State whether the device is single-use, reusable, repairable, refurbished or subject to replaceable parts.
- Identify cleaning, disinfection, sterilisation and maintenance cycles.
- Define installation, movement, drops, impacts, cable handling and connector mating.
- Account for battery ageing, consumables, calibration and sensor drift.
- State the conditions that mark end of life and how users recognise them.
Build these assumptions from MTL-102 — Intended Purpose, Users and Use Environments and translate them into measurable design inputs through MTL-103 — User Needs and Design Inputs.
Build one environmental profile from manufacture to disposal
The most severe condition is not always one extreme value. Damage can arise from combinations, transitions and sequences: a cold product moved into humid air, vibration followed by impact, cleaning fluid entering a worn seal, or heat accelerating a chemical process before mechanical loading.
Record normal ranges, foreseeable excursions, frequency, duration, rate of change and combined exposure. Product-specific, collateral and transport standards can supply methods, but the manufacturer must justify the severities against the real environment.
Test failure mechanisms—not just finished products
Reliability work begins by asking how performance could degrade. Use risk analysis, design reviews, supplier knowledge, similar-product history, service records and focused experiments to identify plausible mechanisms.
Mechanical
Fatigue, creep, wear, fretting, fracture, loosening, deformation, abrasion, seal damage and loss of alignment.
Electrical
Thermal cycling, solder fatigue, connector wear, insulation ageing, corrosion, component drift and power stress.
Materials
Hydrolysis, oxidation, swelling, embrittlement, stress cracking, UV damage, chemical attack and coating loss.
Energy storage
Capacity fade, internal resistance, leakage, swelling, charging stress and protection degradation.
Sensing and measurement
Drift, contamination, fouling, loss of calibration, hysteresis, noise and reference instability.
Human and service interaction
Repeated cleaning, excessive force, incorrect assembly, dropped equipment, missed maintenance and unsuitable replacement parts.
A generic test list can miss the dominant mechanism. A failure-mechanism review should identify the stress that drives each mechanism, the observable response and the design or process characteristics that control it.
Write requirements that expose the reliability claim
A useful requirement states the function, performance limit, environmental and operating conditions, life or number of demands, allowable degradation and required confidence where a statistical claim is intended.
Connect safety-significant limits to MTL-113 — Essential Performance and Safety Concepts and evaluate failure consequences through MTL-105 — Medical-device Risk Management.
Design for margin, tolerance and graceful degradation
Reliable products result from design choices that reduce stress, tolerate variation and make degradation visible before it becomes unacceptable. Testing should confirm those choices, not substitute for them.
- Reduce loads and stress concentrations before increasing material or component ratings.
- Use derating, tolerance analysis and worst-case analysis where they represent the mechanism.
- Separate wear items from life-limiting permanent assemblies where practical.
- Provide sealing, drainage, ventilation and contamination control appropriate to the environment.
- Design connectors, cables, hinges, latches and controls for foreseeable handling and misuse.
- Detect drift, partial failure and depleted life where loss could otherwise remain hidden.
- Define maintenance, calibration and replacement intervals from evidence.
- Avoid common-cause weaknesses in redundant or protective architectures.
Keep system boundaries and allocations aligned with MTL-112 — Systems Engineering, Architecture and Interfaces.
Reliability is a multidisciplinary design responsibility
Mechanical and materials
Loads, fatigue, wear, creep, joints, seals, finishes, chemicals, dimensional stability and maintenance access.
Electronics and power
Derating, thermal management, component life, connectors, batteries, drift, insulation and manufacturing variation.
Software and control
Fault detection, diagnostics, safe states, watchdogs, data integrity, recovery and accumulated-resource limits.
Systems and risk
Life profile, failure allocation, common causes, safety consequences, acceptance criteria and evidence integration.
Manufacturing and suppliers
Critical characteristics, process capability, workmanship, storage, traceability and controlled alternatives.
Service and post-market
Maintenance effectiveness, returned-product analysis, exposure history, trend detection and corrective action.
Use MTL-114 — Electrical and Electronic Design and MTL-115 — Mechanical Design and Materials for discipline-specific design foundations.
Use a layered reliability and environmental test programme
No single test answers every question. A credible programme combines analysis, component evidence, engineering exploration and controlled verification.
Characterise
Measure loads, temperatures, motion, user forces, duty cycles and environmental exposure.
Purpose: replace assumptions with representative input data.Explore
Use prototypes and focused stress tests to reveal weaknesses, interactions and design margin.
Purpose: learn while architecture and materials can still change.Verify
Test controlled representative samples against approved requirements and predetermined criteria.
Purpose: produce objective evidence for the released design.Confirm after exposure
Assess physical damage and repeat relevant functional, safety and performance measurements.
Purpose: demonstrate that exposure did not create hidden degradation.Apply the protocol, sample, configuration and reporting principles in MTL-106 — Verification and Validation.
Accelerate the mechanism—not merely the test clock
Accelerated testing increases a stress or duty rate to produce the same relevant degradation sooner. It is valid only when the acceleration does not introduce an unrealistic failure mechanism, suppress an important recovery effect or change how loads interact.
- State the physical or chemical mechanism being accelerated.
- Justify the relationship between test stress and real-use stress.
- Respect rate limits such as heating, cooling, fluid movement, battery recovery and material relaxation.
- Account for dwell time, sequence and combined stresses.
- Use intermediate inspections to understand the progression of degradation.
- Compare accelerated failures with real or representative-use failures where possible.
- Do not claim a life beyond what the model and evidence support.
Highly accelerated limit testing can expose margins and weaknesses, but it is normally an engineering-development method rather than direct proof of a stated lifetime. Accelerated ageing, fatigue and cycle testing each need a mechanism-specific rationale.
Match samples and statistics to the decision
A small number of successful samples may show that a design can work, but it may provide little evidence about the reliability of a production population. The sample rationale should reflect the claim, variability, failure opportunity, risk and decision being made.
- Identify whether the test demonstrates feasibility, verifies a requirement or estimates a population characteristic.
- Represent production materials, processes, suppliers, tooling, variants and software configurations.
- Select worst cases using documented engineering reasoning rather than convenience.
- Define the statistical model, confidence and reliability target before testing when making a quantitative claim.
- Treat every unit, cycle and demand consistently when counting exposure and failures.
- Do not replace failed samples without preserving and investigating the result.
- Separate censored, interrupted, invalid and completed tests in the analysis.
Where evidence is limited, state the uncertainty honestly and combine test results with analysis, supplier evidence and post-market monitoring rather than implying unjustified precision.
Every failure and anomaly is evidence
A device that reaches the final cycle but shows cracking, drift, looseness, corrosion, intermittent behaviour or unusual noise has not necessarily passed. Acceptance criteria should address functional performance, safety, physical condition and latent degradation.
Assess each anomaly against the risk file, essential-performance definition and test validity. Record deviations transparently; retrospective acceptance criteria weaken the credibility of the whole programme.
Transfer reliability-critical characteristics into production
Development tests usually examine few samples. Production controls must preserve the characteristics on which reliability depends across normal process and supplier variation.
- Identify life-limiting materials, components, joints, seals, coatings and processes.
- Control supplier, grade, formulation, geometry and conditions of acceptability.
- Define process parameters and inspections for reliability-critical workmanship.
- Monitor dimensions, forces, leakage, alignment, torque, thermal interfaces and electrical margins where relevant.
- Use incoming and production tests that can detect meaningful drift without damaging the product.
- Retain traceability needed to investigate field failures and lot-specific trends.
- Assess substitutions, tooling, process, firmware and supplier changes against the established mechanisms and margins.
The released evidence should connect through MTL-104 — Design Controls and Technical Documentation, not remain as isolated laboratory reports.
Use post-market data to test development assumptions
Field evidence reveals real duty cycles, environments, user behaviour, maintenance quality and production variation. Complaint counts alone are not enough: exposure and installed population affect the meaning of a trend.
- Capture time in service, use count, environment, configuration, maintenance and failure symptoms where possible.
- Distinguish no-fault-found returns, misuse, wear-out, random failures and systematic weaknesses.
- Examine replaced parts and preserve evidence before repair.
- Trend by age, lot, supplier, variant, geography, environment and usage intensity.
- Compare observed failures with risk estimates and life-test mechanisms.
- Feed credible signals into CAPA, design change, maintenance, labelling and future verification.
- Reconsider claimed life and replacement intervals when assumptions are not supported.
Reliability work across the lifecycle
Define use and life
Translate intended use, environments, duty cycles, cleaning, maintenance, transport and storage into a quantitative life profile.
Typical evidence: Life specification, environmental profile, use-cycle model, user assumptions and boundary conditions.Identify degradation
Ask how materials, components, joints, seals, batteries, sensors, mechanisms and software-supported functions can deteriorate.
Typical evidence: Risk analysis, failure-mechanism review, historical data, supplier evidence and engineering analyses.Design for margin
Select architectures, materials, components and protective features that tolerate variation, ageing, wear and foreseeable stress.
Typical evidence: Calculations, derating, tolerance analysis, simulations, design reviews and prototype investigations.Verify progressively
Use focused engineering tests early, then controlled durability and environmental verification on representative configurations.
Typical evidence: Protocols, sample rationale, test records, raw data, anomalies, reports and traceable conclusions.Control production
Protect reliability-critical characteristics through suppliers, processes, inspection, configuration control and change assessment.
Typical evidence: Critical-characteristic list, process controls, acceptance criteria, supplier records and production monitoring.Learn from the field
Compare real use, failures, maintenance and environmental exposure with the assumptions used during development.
Typical evidence: Complaint trends, service data, reliability metrics, investigations, CAPA and updated risk conclusions.Common misconceptions
“A long cycle test proves reliability.”
Only if the cycles, loads, environments, samples, criteria and failure mechanisms represent the stated claim.
“Passing once proves the full product family.”
Variants and production ranges require a documented coverage rationale and may need different worst cases.
“Accelerated testing is simply faster normal use.”
Higher stress or rate can create different mechanisms; acceleration needs a physical justification.
“No functional failure means the sample passed.”
Cracking, drift, wear, corrosion and other latent damage may already invalidate safety or remaining life.
“Reliability belongs to the test team.”
Architecture, materials, components, software behaviour, suppliers, production and service all shape reliability.
“A standard test level defines our environment.”
Standards provide methods and sometimes severities; the manufacturer still justifies applicability to the device and use.
Practical review checklist
- Are shelf life, service life, duty cycles, maintenance and end-of-life conditions defined?
- Does the environmental profile cover manufacture, distribution, storage, operation, cleaning and service?
- Have plausible mechanical, electrical, material, battery, sensing and human-interaction degradation mechanisms been identified?
- Are reliability and durability requirements measurable and linked to risk?
- Does the architecture provide appropriate margin, tolerance and degradation detection?
- Are product variants, suppliers, processes and worst-case configurations represented?
- Does each accelerated test preserve the relevant failure mechanism?
- Are sample size, statistical assumptions and uncertainty appropriate to the claim?
- Are inspections performed before, during and after environmental or life exposure?
- Are all failures, anomalies and deviations investigated and retained?
- Have reliability-critical characteristics been transferred into production controls?
- Are field data compared with development assumptions and used to maintain the evidence?
Authoritative references
- ISO 14971:2019 — Medical devices: application of risk management to medical devices
- IEC 60068-1:2013 — Environmental testing: general and guidance
- IEC 60601-1:2005+A1:2012+A2:2020 — Medical electrical equipment: basic safety and essential performance
- IEC 60601-1-11:2015+A1:2020 — Medical electrical equipment used in the home healthcare environment
- FDA — Recommended Content and Format of Non-Clinical Bench Performance Testing Information in Premarket Submissions
- Regulation (EU) 2017/745 — Medical Device Regulation
Applicable methods and severities depend on device technology, intended environments and markets. Confirm current editions, amendments, national adoptions, regulatory recognition and product-specific standards before defining the verification programme.
Reliability is a maintained argument about function, stress, time and evidence
Define the life and environment, understand the degradation mechanisms, design for margin, test representative products, control production variation and use field data to challenge every assumption.