---
title: "Qualification path"
url: https://docs.mru.space/concepts/qualification/
description: "What exists for Mru against NPR 7150.2, NASA-STD-8739.8, ECSS-E-ST-40C and ECSS-Q-ST-80C, and what has not started. No compliance claim."
---

[Docs](https://docs.mru.space/) / [Concepts](https://docs.mru.space/concepts/shrinking-quorum/) / Qualification path

# Qualification path

What exists today, and the NASA and ECSS software standards it relates to. No qualification evidence exists yet. Mru makes no compliance claim.

## Standards

This page maps Mru to four software standards, two from NASA and two from ECSS:

| Number | Title |
| --- | --- |
| NPR 7150.2 | NASA Software Engineering Requirements |
| NASA-STD-8739.8 | Software Assurance and Software Safety Standard |
| ECSS-E-ST-40C | Space engineering: Software |
| ECSS-Q-ST-80C | Space product assurance: Software product assurance |

The tables below map by topic, not by clause. No clause of any standard has been checked against Mru.

## What exists

These activities run today. They are engineering evidence, not qualification evidence: none was planned, reviewed or recorded under a standard.

| Activity | What exists | Related standards |
| --- | --- | --- |
| Unit tests | Unit tests of the core and the C interface, run in CI on every change. See [the quorum crate](https://docs.mru.space/core/quorum-crate/). | NPR 7150.2, ECSS-E-ST-40C |
| Formal proofs | Nine Kani proofs, four on the core and five on the C interface, run in CI on every change. Each has a stated scope. See [Kani proofs](https://docs.mru.space/core/quorum-crate/#proofs). | NPR 7150.2, NASA-STD-8739.8, ECSS-E-ST-40C, ECSS-Q-ST-80C |
| Continuous integration | Build and test on Linux x86\_64, Linux ARM64 and macOS, plus static ARM Linux binaries tested under emulation and a bare-metal ARM Cortex-M build. | NPR 7150.2, ECSS-E-ST-40C |
| Scenario tests | `scripts/scenarios.sh` runs the demo program and checks its output: faults, limits, resets and the comparison with fixed TMR. | NPR 7150.2, ECSS-E-ST-40C |
| Bench | 300 runs per host with injected faults on three general-purpose processors. Not radiation testing, not target hardware. See [Bench](https://docs.mru.space/core/bench/). | NPR 7150.2, ECSS-E-ST-40C |
| F´ unit tests and system test | 37 unit tests of the F´ components, and a 60-case system test against the demo's counts. Not run on flight hardware. See [F´ components](https://docs.mru.space/core/fprime/#tests). | NPR 7150.2, ECSS-E-ST-40C |

## Not started

| Activity | Status | Related standards |
| --- | --- | --- |
| Software classification and criticality | Not started | NPR 7150.2, NASA-STD-8739.8, ECSS-Q-ST-80C |
| Requirements traceability | Not started | NPR 7150.2, ECSS-E-ST-40C |
| Independent verification and validation | Not started | NPR 7150.2, NASA-STD-8739.8, ECSS-E-ST-40C |
| Tool qualification (compiler, Kani, test tools) | Not started | NPR 7150.2, ECSS-Q-ST-80C |
| Rust toolchain qualification plan: TODO | Not started | NPR 7150.2, ECSS-Q-ST-80C |
| Coding standard compliance | Not started | NPR 7150.2, ECSS-Q-ST-80C |
| MC/DC structural coverage | Not started | NPR 7150.2, ECSS-E-ST-40C |
| Software development and assurance plans | Not started | NPR 7150.2, NASA-STD-8739.8, ECSS-E-ST-40C, ECSS-Q-ST-80C |

Status as of 11 Oct 2026, flight v0.2.0. The F´ components and the C interface have numbered requirements, each with a verification method, but no trace to mission or standard requirements.

## Related

-   [Architecture status](https://docs.mru.space/concepts/architecture/): what is built, layer by layer
-   [Shrinking quorum](https://docs.mru.space/concepts/shrinking-quorum/#guarantees): what is proved and what is tested

Updated 11 Oct 2026 · [Edit on GitHub](https://github.com/mruspace/docs/edit/main/src/pages/concepts/qualification.astro) · [Questions? Get in touch](https://mru.space/contact/)
