Every pitfall below has been watched happening on real programmes; the guards are correspondingly practical.
| Pitfall | What it looks like | The guard |
|---|---|---|
| Selling the number as a field forecast | "The prediction says 48,600 h, so the fleet will see it" | Quote predictions as comparative estimates; track field MTBF separately |
| Unit mix-ups | FIT and f/10⁶ h blended in one roll-up — a factor of 1,000 | Declare units at the top; convert at the boundary, once |
| One environment for a multi-phase life | A missile electronics box predicted entirely in GF | Segment the mission; time-weight per-phase results |
| Extrapolating the models | Stress ratios above 1.0, temperatures past the tables | Treat out-of-table parts as derating findings, not inputs |
| Forgetting the unglamorous contributors | No PCB, solder-joint, or connector terms in the roll-up | Follow the handbook's roll-up procedure to the letter |
| Optimistic quality claims | Commercial parts carried at military πQ "because the vendor is good" | Evidence for the claimed screening, or the honest factor |
| Ignoring duty cycle and dormancy | Calendar hours fed into operating-hour models | Define operating time explicitly; profile on/off phases |
| Quoting MTBF without its clock | Operating-hour prediction argued against calendar-hour field data | State the clock with every MTBF; publish both views when duty cycle < 100% |
| Wear-out items left in the λ sum | A life-limited item carried at a constant rate with no replacement plan | Screen against mean life; pull flagged items into conditional-reliability treatment |
| One-shot items on the hourly clock | A squib or cartridge carrying a per-hour failure rate | Per-demand probability, combined at the demand point — never in the λ sum |
| Silent zero from an unsupported environment | A model asked for an environment it does not define returns a perfect part | Treat any zero rate as a defect in the analysis until proven deliberate |
| Double-counting field evidence | Field-based specified rates further "corrected" by field-data methods or factors | One evidentiary basis per rate, recorded with the rate |
| Chasing the number, not the design | Assumptions tuned until the target is met | The handbook's own warning: those who treat the prediction as a number to exceed will find a way — without improving anything |
| Frozen-handbook blindness | 1995 models applied to parts that did not exist in 1995 | Say so in the assumptions; consider newer model sets or field data for modern parts |
Most of these are process failures, not mathematics failures, and the last two deserve a sentence each. The gaming problem is old enough that the handbook warns about it explicitly — a prediction whose assumptions were tuned to clear a threshold has spent its credibility for one review meeting. And the frozen-handbook problem is structural: MIL-HDBK-217F Notice 2 predates three decades of component evolution, which is precisely why the serious modern practice is to treat handbook predictions as one pedigree among several — blended with field data where it exists, cross-checked against newer model sets where it matters, and always documented with their assumptions attached.