\section{Introduction} Msc project Euler/Spider Diagram editor --- Euler/Spider Diagrams could be used to model failure modes in components. --- 2005 paper --- need for static analysis because of high reliability of modern safety critical systems. \section{Practical Experience: Safety Critical Product Approvals} FMEA performed on selected areas perceived as critical by test house. Blanket measures, RAM ROM checks, EMC, electrical and environmental stress testing \subsection{Practical limitations of testing for certification vs. rigorous approach} State explosion problem considering a failure mode of a given component against all other components in the system. Impossible to perform double simultaneous failure analysis (as demanded by EN298~\cite{en298}).