Simulators and operations rehearsal
Spacecraft simulators and structured rehearsal campaigns are how a national operations team proves competence before commanding real hardware. This page covers simulator fidelity tiers, contingency drill design and the evidence a programme needs to justify first-command authority.
The simulator is not a luxury; it is the only safe place to be wrong
Every spacecraft anomaly that destroys a mission has a precursor: an operator who encountered that failure mode for the first time on the live vehicle. Simulators exist to make that encounter cheap. The principle is not new. NASA's Apollo programme ran thousands of hours of crew simulation before any lunar mission, and the discipline transferred directly into robotic spacecraft operations. What has changed is cost: a high-fidelity software simulator that would have required dedicated mainframes in the 1980s now runs on a rack of commodity servers.
For a national programme standing up its first operations team, the simulator is the primary training environment for at least the first eighteen months. It is also the evidence base. When a government programme director asks whether the team is ready to command the satellite, the answer cannot be 'we think so.' It must be a logbook of completed drill scenarios, pass/fail records and anomaly response times, signed off by a qualified flight director. Simulation is how you manufacture that evidence.
Fidelity tiers: what you actually need to build
Simulator fidelity is not binary. Programmes typically deploy three tiers, each serving a different purpose. A functional simulator models the spacecraft's command and telemetry interface faithfully but approximates internal physics: it is fast to build, sufficient for procedure verification and console familiarisation, and cheap to maintain. A high-fidelity engineering simulator adds accurate subsystem models, including power budgets, thermal behaviour, attitude dynamics and failure injection. This tier is where contingency training happens. A hardware-in-the-loop (HIL) simulator inserts real flight-spare electronics into the simulation chain, providing the highest confidence that software and procedures will behave identically on orbit.
Most national programmes at the small-satellite scale operate well with a functional simulator for routine training and a high-fidelity software simulator for contingency drills. HIL rigs are justified when the mission carries a novel payload or when the programme cannot afford a second satellite to absorb a procedural error. The cost difference between tiers is significant: a functional simulator may be built in weeks from the same software stack used to generate ground support software, while a full HIL rig requires flight-spare procurement, which can extend lead time by six to twelve months and add materially to programme cost.
Designing a rehearsal campaign that actually transfers to flight
A rehearsal campaign is a structured sequence of simulation sessions with defined objectives, not a series of ad hoc practice runs. The campaign typically opens with procedure walk-throughs: operators follow nominal timelines step by step, with the simulator providing realistic telemetry responses. Once nominal procedures are internalised, the campaign introduces off-nominal scenarios. These are injected by a simulation supervisor, sometimes called the SimSup role, who introduces failures without warning the console team. Common injection categories include attitude control anomalies, battery state-of-charge exceedances, payload thermal limits, uplink dropouts and safe-mode transitions.
The campaign structure should mirror the actual mission phases. Launch and early orbit operations (LEEO) demand the most intensive rehearsal because the timeline is compressed, the spacecraft is in an unfamiliar configuration and there is no margin for hesitation. A credible LEEO rehearsal campaign runs the full acquisition-of-signal sequence, including the scenario where signal is not acquired on the first pass, at least a dozen times before launch day. Station-keeping manoeuvre rehearsals, payload commissioning sequences and end-of-life disposal procedures each warrant their own campaign blocks. The total rehearsal hours required to reach first-command authority vary by mission complexity, but published ESA and NASA operations standards consistently point to a minimum of several hundred hours of simulator time for a three-to-five person operations team on a first mission.
Where simulators fail you: honest limits
A simulator is only as good as its models, and spacecraft models are always incomplete. Thermal models, in particular, are notoriously difficult to validate before launch: the on-orbit thermal environment differs from ground testing in ways that are hard to anticipate, and a simulator calibrated on pre-launch data may not reproduce the actual thermal telemetry the team sees on day one. Operators trained exclusively on a well-behaved simulator can develop a false pattern-recognition instinct: they learn to expect telemetry that looks like the model, and anomalies that fall outside the model's assumptions can be misread.
Latency is another gap. A simulator running on a local server responds to commands in milliseconds. Real operations involve ground station uplink delays, spacecraft on-board processing time and downlink scheduling constraints. If the simulator does not accurately reproduce the timing of the command-acknowledge-telemetry cycle, operators will develop procedures that are subtly mis-timed. This matters most during time-critical contingency responses. The fix is to inject realistic latency into the simulation chain from the start of training, not as a refinement added later.
Finally, no simulator reproduces the psychological pressure of a real anomaly. Organisations that treat simulation as purely technical miss this. Rehearsal campaigns should include deliberate stress elements: time limits, communication constraints, injected distractions and formal post-drill debriefs that examine decision quality, not just procedural correctness.
Evidencing readiness: what a flight readiness review actually needs
A flight readiness review (FRR) is the formal gate before a national team assumes command authority. The simulation and rehearsal record is the primary evidence package. A credible package includes: a completed training matrix showing each operator's qualification status against each procedure category; drill completion records with pass/fail criteria and remediation notes; anomaly response time statistics from contingency scenarios; and a signed assessment from the flight director or equivalent authority.
The FRR is also where gaps become visible. If the rehearsal campaign has not covered a particular failure mode, the FRR is the last opportunity to add it before launch. Programmes that skip or compress the rehearsal campaign to meet a launch date consistently pay for it: the first real anomaly becomes the de facto training event, and the cost of learning on the live spacecraft, in terms of lost mission time or permanent hardware damage, almost always exceeds the cost of the simulation sessions that were cut.
Engineering parameters
| Functional simulator build time | 4 to 12 weeks from spacecraft interface definition document |
| High-fidelity software simulator build time | 3 to 9 months, depending on subsystem model complexity |
| Hardware-in-the-loop rig lead time | 6 to 18 months, gated by flight-spare procurement |
| Minimum rehearsal hours to first-command authority (small satellite, 3-5 person team) | 200 to 500 hours; varies with mission complexity and team prior experience |
| LEEO rehearsal campaign minimum runs | 10 to 20 full acquisition-of-signal sequences before launch |
| Typical contingency scenario library size | 40 to 120 distinct failure injection scenarios for a well-characterised small satellite |
| Simulator update cycle after on-orbit calibration | Model refresh within 90 days of first telemetry, then as anomalies warrant |
| Command latency injection accuracy | Realistic simulation requires latency modelling to ±50 ms of actual ground-station round-trip |
One contract, one accountable engineer
Commissioned as one programme, not a stack of contracts: spacecraft, launch, ground segment, mission control, training and handover are priced together. Source-access terms and audit rights are agreed in writing before signature. Review our rehearsal campaign framework.