DELTA-SIERRAMARSEXPLORE · UNDERSTAND · SETTLE
Support my work
HomeMars colonization hub › How could humans really colonize Mars?

Pillar guide

How could humans really colonize Mars?

The route to a permanent settlement is not one heroic flight. It is a sequence of risk-reduction, cargo, infrastructure and institution-building missions.

  • Evidence-led
  • Original public guide
  • Updated 4 August 2026
Roadmap from robotic surveys and cargo missions to a permanent Mars settlement and city
Stage 0Robotic reconnaissance and site certification.
Stage 1Uncrewed cargo and power before people.
Stage 2A crewed base designed to survive failures.
Stage 3Repeated growth toward settlement and city.

How would a colony on Mars actually be built, step by step?

A durable settlement would begin by reducing dependencies in a deliberate sequence rather than by attempting mass migration. Robotic reconnaissance is followed by cargo, power and communications; water access and protected living volume are tested before the first crew relies on them. Population growth becomes rational only after maintenance, reserves, medical capability, recycling, agriculture and local replacement of critical parts have survived real operating cycles. In that sense, settlement size is an output of demonstrated capability rather than a target that can be declared in advance.

The decisive question is therefore not “how many people can a spacecraft carry?” but “how many people can the surface infrastructure keep alive when several failures occur at the same time?” The roadmap below follows that logic and separates demonstrated capabilities, illustrative sizing examples and still-prospective settlement architectures.

This guide separates documented engineering results from settlement scenarios. Institutional sources support measured or demonstrated claims, while future choices are presented explicitly as design hypotheses.

The central answer

Humans could colonize Mars only by building the destination before depending on it

A credible colonization sequence begins with a simple rule: the first crew should not be asked to create every life-critical capability after landing. Power, communications, navigation aids, spare habitats, surface mobility and at least part of the resource-processing chain should arrive first and prove that they work in the actual Martian environment. The first human landing would then connect, inspect and expand an existing robotic foothold rather than improvise a base from cargo scattered across an uncertain landing ellipse.

This approach sounds cautious because it is. Mars offers no rapid rescue. Depending on orbital geometry, a one-way message takes roughly three to twenty-two minutes, and superior conjunction can disrupt communications for extended periods. A failed valve, medical crisis or software fault cannot be handed to Earth in real time. The settlement must carry expertise, procedures, diagnostic tools and authority locally.

Important distinction. NASA currently develops an architecture for human exploration from the Moon toward Mars. SpaceX describes a transport system and the objective of a self-growing base or civilization. Neither organization has demonstrated the complete surface, life-support, industrial and political system required for permanent settlement.

Stage 0: choose the purpose before choosing the hardware

“Go to Mars” is not a mission requirement. A short scientific expedition, a repeatedly occupied base and a permanent settlement require different cargo, crew, risk limits and legal arrangements. A short-stay architecture can accept deep dependence on pre-positioned supplies. A settlement architecture must invest early in repair, resource extraction, storage and workforce continuity, even when those systems increase initial mass.

The purpose also determines ethical constraints. A landing site valuable for accessible ice may also be scientifically sensitive. Human activity introduces heat, chemicals and terrestrial microbes. Site selection must balance engineering access with planetary-protection rules and the preservation of uncontaminated regions for research.

Stage 1: map and certify candidate settlement zones

The best landing site is not simply the flattest plain. It must combine safe entry, descent and landing; manageable altitude; useful sunlight; tolerable seasonal temperatures; access to subsurface water ice; communications geometry; traversable terrain and distance from hazards. NASA’s Subsurface Water Ice Mapping work has identified regions where ice may lie within about a meter of the surface. That is a powerful lead, not a guarantee that a colony can immediately mine clean water at industrial scale.

Before humans depend on a site, robotic missions would need to drill, analyze the ice and soil, measure dust behavior, monitor weather over multiple seasons and test excavation equipment. They would also need to determine whether local material can be processed into shielding, landing pads, roads or construction feedstock. Site viability depends on deliverable water rather than mere detection: depth, purity, temperature, ground strength, extraction rate and energy cost determine whether a deposit can support daily operations.

Stage 2: land power, communications and shelter first

Early cargo missions should establish an energy island before the crew arrives. Solar power is mature and scalable, but Mars dust and seasonal light variation make storage and cleaning central design issues. Fission surface power offers continuous output independent of sunlight, yet it introduces reactor transport, deployment, exclusion-zone and maintenance challenges. A settlement architecture may ultimately use both: solar arrays for scalable daytime production and fission units for dependable baseload power.

Early Mars-base modules with logistics operations and a surface vehicle.
Conceptual early-deployment visualization: first habitats do not stand alone; they depend on power, cargo, mobility, maintenance and procedures that gradually expand local capability.

Habitats should be landed, checked for leakage and connected to independent emergency volumes. Communications relays and local navigation beacons should operate before crewed descent. Robotic movers should position cargo and build prepared surfaces so that later landings do not blast dust and debris into existing equipment. The first site must be designed as a growing campus, not a collection of unrelated spacecraft.

The first real milestone is a surface system that works before crew arrival

A settlement program should demonstrate power generation, storage, communications, thermal control and at least one critical resource-production chain while nobody is present to improvise. Reliability becomes credible only when the surface can detect faults, isolate them, recover or enter a safe degraded state without depending on a crew standing beside the hardware.

Pedagogical calculation: how many successful landings for 100 useful tonnes on the surface?

If an illustrative architecture assumes 20 tonnes of useful landed payload per successful cargo landing, 100 tonnes requires at least 100 ÷ 20 = 5 successful landings. Planning one equivalent cargo as margin raises planned landed capacity to 6 × 20 = 120 tonnes. This is a teaching scenario, not a NASA mission architecture; its purpose is to expose how landing capacity multiplies operational events and risk.

Build local industry in order of criticality

The first workshops should not chase every consumer product. They should attack the items that most threaten survival when supply is delayed: seals, hoses, filters, structural repairs, electrical conversion, pumps, valves, simple machining and inspection. Local industry becomes strategic when it removes a single-point dependency from a life-support or mobility chain.

Mars Direct: simplify the mission before enlarging it

Mars Direct begins with a critique of heavy interplanetary architectures: if every function requires another infrastructure layer in Earth, lunar or Mars orbit, mass and cost can grow rapidly. Zubrin and David Baker instead proposed pre-positioning the return vehicle, manufacturing part of its propellant locally, and sending the crew only after the return capability is prepared.

Details changed across versions, but the conceptual legacy is durable: pre-deployment, local resource use, a relatively direct logistics chain and skepticism toward adding steps merely because they are technologically attractive.

ISRU: where chemistry becomes strategy

In-situ resource utilization was not invented by Zubrin. His contribution was to place it at the center of an understandable mission architecture: if Mars provides atmospheric CO₂ and water or imported hydrogen is available, chemical processes can produce useful molecules, including propellants and oxygen.

Today that logic should be connected to real demonstrations such as MOXIE while keeping scale explicit. A rover instrument that makes oxygen does not demonstrate an autonomous plant producing hundreds of tonnes of return propellant.

ISRU: when the atmosphere becomes a line in the cargo manifest

The most durable idea in Mars Direct may be the strategic use of ISRU — in-situ resource utilization. If part of the return propellant can be manufactured from Martian resources, less mass must leave Earth. A planetary fact — a carbon-dioxide-rich atmosphere — becomes a logistics parameter. Mars is no longer only the object of study; the architecture asks the planet to supply part of the mission.

NASA has since studied ISRU extensively and analyzed its architectural consequences. Agency work cites Mars Direct as an influential reference and examines propellant, water, oxygen and other local-resource pathways. [Z8][Z9] That legacy matters because one can reject details of the 1991 design while recognizing that the shift toward local production became central to human-Mars planning.

ISRU, however, is not a formula that “solves” Mars. A propellant plant must be landed, powered, commissioned, monitored, protected from dust, maintained, provided with spares and proven before the crew depends on it. Mass savings are purchased with local reliability requirements. That is precisely why Mars Direct is pedagogically valuable: it reveals where risk is moved rather than pretending risk disappears.

The minimum viable outpost: four people do not yet make a colony

Imagine four people landing on Mars with a habitat, stored supplies and a vehicle. It would be historic, but calling it a colony would be premature. If the group depends on precisely scheduled resupply, Earth-based medical expertise, irreplaceable components and a single return vehicle, it is still an expedition. The distinction is not the flag or the length of stay. It is whether the system continues when the nominal mission plan breaks.

The first practical objective is therefore a minimum viable outpost. It needs independent power paths, reserves of water and oxygen, an isolatable refuge, diagnostic capability, critical spares and procedures for operating without immediate Earth contact. Essential cargo should ideally arrive before the crew and be commissioned robotically. This changes the logic of the mission: the surface environment has to prove that a functional system can survive before human lives are made dependent on it.

A scientific base is the next threshold. It remains Earth-dependent but starts producing selected resources, maintaining hardware and accumulating local experience. An industrial base follows when workshops, recycling, quality control and manufacturing begin replacing imports. A city is another transition entirely: services and institutions can no longer be managed as if every resident were simply part of a spacecraft crew. Colonization is therefore a sequence of functional thresholds, not a single date.

A useful metric: how many Earth launch windows can the settlement miss?

Earth and Mars do not provide continuous low-energy transport. Favorable opportunities recur on a cycle of roughly twenty-six months. This gives a concrete measure of dependence. A base that cannot miss one window remains fragile. A base that can survive until the next opportunity with margin has real logistical resilience. Missing two or three windows implies that many vital supply chains have already been transformed.

This measure forces planners to separate consumables from durable equipment. Water can be recycled and perhaps extracted locally. Oxygen can be regenerated or produced. Some food may be grown, but not necessarily every nutrient or calorie. Filters, seals, sensors, medicines, electronics and lubricants all have different shelf lives and failure rates. For each family, the questions are the same: what is stocked, what can be repaired, what can be substituted and what can be manufactured locally?

The result is better represented as a dependency matrix than as one self-sufficiency percentage. Rows can represent air, water, food, power, thermal control, computing, medicine and mobility. Columns can represent stored inventory, recycling, local production, repair capability, replacement capability and maximum time without resupply. One function can be mostly local yet remain vulnerable to a single imported part.

A settlement crosses an important threshold when a missed launch opportunity no longer forces permanent survival mode. It crosses an even larger threshold when a failed local production chain can itself be rebuilt using local capability.

From twenty to one thousand residents: budgets become systems

At twenty people, many needs can still be estimated in kilograms per person per day. If a teaching example uses 0.82 kg of metabolic oxygen per person per day, the daily quantity for twenty people is 20 × 0.82 = 16.4 kg. Over thirty days, 16.4 × 30 = 492 kg. That is not the mass of an ECLSS; it is only an order of magnitude for oxygen consumed. Recycling losses, leakage, EVA use and emergency reserves must be treated separately.

At one hundred people, logistics becomes a permanent professional function. No single technician can know every machine. The settlement needs procedures, configuration records, system owners, training and organized stores. Agriculture may provide a meaningful fraction of food, but it also introduces crop disease, lighting failures, contamination and nutrient-management risk. The best system is not the one with the highest nominal yield; it is the one that continues after a bad week.

At one thousand people, basic industry becomes necessary. A metal part requires feedstock, energy, machine tools, cutting tools, metrology, drawings and quality control. Glass, polymers and electronics require other chains. Independence does not mean making everything. It means identifying which dependencies are strategically worth removing first.

Growth is therefore an ordering problem. The settlement should master the capabilities that most directly protect life and reduce imported mass before trying to reproduce every terrestrial industry. Highly complex supply chains may remain Earth-based for a long time if inventories and redundancy are designed around that fact.

Combined failures matter more than isolated failures

The most dangerous scenario is not always the most spectacular single fault. A reactor may be redundant, a pump may have a spare and a rover may be towable. Systemic risk emerges when several moderate problems reinforce one another. A dust event reduces solar generation, batteries cycle deeper, electrical heating demand rises, a maintenance task is deferred and agricultural output is affected later. No event is catastrophic alone, but the margin disappears.

Reserves therefore need definitions. “Three days of water” could mean three days with no recycling, or three days of drinking water only. Are reserves distributed between compartments? Can one leak contaminate all of them? Power needs the same discipline: which loads survive, which are shed, which have independent feeds and how does the network restart after a blackout?

Training begins before launch. Crews should rehearse lost communications, compartment isolation, ambiguous sensors, limited-power operations and medical cases without real-time help. But training cannot replace missing architecture. A brilliant procedure cannot compensate for a valve that was never installed, a spare that was never stocked or a refuge that is too small.

A credible settlement therefore publishes failure assumptions as carefully as nominal performance. How long without water production? How long without Earth contact? What is survival power? Which systems share a common cause? These questions turn a picture of a base into an architecture that can be examined.

Medicine, reproduction and psychology: biological autonomy is harder than mechanical autonomy

A broken pump can sometimes be replaced by another pump. A rare diagnosis is harder to substitute. Distance rules out rapid evacuation and limits real-time telemedicine. A settlement therefore needs appropriate medical expertise, medicines, imaging, procedures and possibly surgical capability for a small population. As the mission becomes permanent, healthcare changes from astronaut medicine to ordinary community medicine.

Human reproduction introduces even greater uncertainty. There are no long-duration human data for pregnancy, childhood and development at Martian gravity. A permanent population cannot avoid the question forever, yet it must approach it with exceptional ethical caution and clearly separate knowledge from microgravity, animal research and what remains unknown at 0.38 g.

Psychology is more than isolation. A small community combines intense professional dependence with limited privacy in an environment where the outdoors is lethal and Earth is not an immediate escape. Conflict, fatigue, grief, cultural differences and power relationships become operational variables. Technical competence can decline if the social system deteriorates.

At larger scale, mental and physical health therefore meet governance: work rhythms, private space, medical confidentiality, reproductive choices and the right to refuse risk. These are difficult precisely because no single equation solves them. They deserve the same seriousness as propulsion and EDL.

Martian society is critical infrastructure

Early authority can be mission-based: commander, system leads and emergency procedures. A permanent settlement eventually has to separate technical emergency authority from political authority. Who can isolate a network? Who allocates a scarce resource? Who decides whether a scientific activity can contaminate a site? Who owns equipment produced with community resources?

These are safety questions as well as legal ones. If no one knows who can shut down a failing system, an emergency slows. If residents cannot legally modify imported hardware, technical autonomy may be limited by governance. If resource rules are perceived as unfair, cooperation can fail exactly when it is most necessary.

Institutions should therefore be designed like systems: functions, interfaces, responsibilities, degraded modes and recovery mechanisms. A perfect constitution written on Earth is probably less useful than a framework able to evolve with population and experience.

Mars may also reward a distinctive culture of maintenance and transparency. Accurate inventories, traceable decisions and the ability to report errors without hiding them become survival values. A society that punishes every reported mistake can create invisible technical debt. On Mars, that debt can become physical.

Delta-Sierra calculators and data

The calculators make hidden assumptions inspectable: readers can follow each operation, change the inputs and see how the result responds before using it in a settlement argument.

Campaign engineering · logistics · proof before crew

Design the campaign backwards from a safe crew

The most reliable way to plan early colonization is to start from the conditions a first crew must find on arrival and work backwards. The crew needs a landing zone that has already been mapped, communications that have already carried operational traffic, power that has already survived faults and seasonal variation, shelter whose pressure and thermal behavior are known, reserves whose location is verified, and surface machines that have already demonstrated useful work. This “architect from the right” logic resembles NASA’s current Moon to Mars method: define the desired end capability first, then identify the functions and elements required to achieve it.

Working backwards prevents a seductive but dangerous sequence in which a launch vehicle is chosen first and every other part of the settlement is forced to fit its payload bay. Transport matters enormously, but a high delivered mass is not equivalent to a functioning base. The cargo must arrive in the correct order, connect through standardized interfaces, be commissioned by robots or a small crew, survive dust and thermal cycles, and still be maintainable when the manufacturer is tens of millions of kilometres away.

Launch windows turn logistics into a two-year discipline

Earth and Mars offer favorable transfer geometry roughly every 26 months. That rhythm means settlement logistics must be planned in campaigns rather than continuous resupply. A terrestrial hospital can order an unexpected component and receive it in days. A Mars base may discover a design flaw after the launch window has closed and live with the consequence until the next campaign can be prepared, launched and transferred.

This creates a useful design question: how many launch opportunities can the settlement miss? A first outpost may be safe only if the next window succeeds. A more mature base should be able to miss one campaign. A durable settlement should survive more complex events: one vehicle lost during launch, another delayed, and a local production system simultaneously degraded. The objective is not to stock everything forever. It is to make the time available for diagnosis, repair, substitution and rationing longer than the time required to recover.

Campaign gates before the first crew
GateWhat must be demonstratedWhat does not count as proof
SiteTerrain, hazards, resources, communications geometry and operational routes mapped at useful resolution.A scientifically interesting location with no engineering certification.
LandingRepeated delivery into a manageable logistics radius with known dispersion and surface effects.One small robotic landing at a very different mass scale.
PowerGeneration, storage/distribution, black start and load shedding demonstrated through faults.Nameplate power under ideal conditions.
HabitationPressure, thermal control, leakage monitoring and safe-haven logic exercised.An unopened habitat that has only survived transport.
LogisticsRobots can locate, move, connect and inventory critical cargo.Cargo merely present somewhere on the surface.
ReturnReturn/ascent chain and its critical consumables protected from a single pre-crew failure.A future promise that propellant or hardware will be produced after crew arrival.

The first 100 sols should be designed before launch

The first crew should not arrive with a vague objective to “build the base.” Their early sols should already have a hierarchy. The first hours prioritize crew health, habitat pressure, power, communications and the return chain. The next days verify stores, environmental-control performance, emergency refuge, fire detection, medical capability and robotic assets. Only after the settlement demonstrates stability should it expand construction, science and resource production.

A useful rule is that every high-risk activity should have an abort path that returns the crew to a known safe state. An EVA to repair a power cable needs enough suit margin and an alternate energy path so the habitat remains safe if the repair fails. Commissioning a water extractor should not contaminate the potable reserve. Connecting a new habitat should not require placing the entire settlement on one pressure boundary. Early operations are therefore slower than popular imagery suggests: inspect, measure, isolate, test, document, then proceed.

A sample 100-sol priority sequence

PeriodPriorityGo/no-go evidence
Sols 0–3Human stabilization, habitat, power, communications, emergency inventoryNo unexplained pressure loss; stable atmosphere; emergency power tested.
Sols 4–15Inspect predeployed assets, verify routes, commission secondary loopsCritical equipment status reconciled with digital inventory; independent backups exercised.
Sols 16–40Begin local water/oxygen demonstrations and scheduled maintenanceMeasured throughput, purity, energy and maintenance burden logged.
Sols 41–70Expand protected storage, workshop and scientific operationsRepair/requalification process proven on non-critical equipment.
Sols 71–100Stress tests and degraded-mode rehearsalBase can shed loads, isolate a compartment and continue life support without Earth-side real-time direction.

Landing reliability compounds across a cargo campaign

A settlement assembled from many landings faces cumulative reliability. Even when each landing has a high individual probability of success, a long sequence makes it increasingly likely that at least one vehicle will fail. The engineering response is not to demand impossible perfection; it is to make the manifest tolerant to loss. No single early cargo flight should carry all of one indispensable function if losing that flight would make the crew mission unsafe.

Calculation: the probability that every landing succeeds

Illustrative model Suppose, purely as a mathematical example, that each landing has a 95% independent probability of success. For n landings, the probability that all succeed is 0.95n.

5 landings: 0.955 ≈ 0.774, or 77.4%.
10 landings: 0.9510 ≈ 0.599, or 59.9%.
20 landings: 0.9520 ≈ 0.358, or 35.8%.

This does not estimate any current vehicle. Independence is also a simplifying assumption. The lesson is architectural: a twenty-flight campaign should expect that something may be lost and distribute power, communications, spares and life-critical capacity accordingly.

Cargo should arrive as capabilities, not as a warehouse

A manifest can be optimized by mass and still be operationally poor. Ten tonnes of spare parts are not useful if the parts cannot be identified, moved, protected from dust, connected to the installed configuration or matched to the failure that actually occurs. Cargo must arrive with data: serial number, compatible equipment, storage conditions, shelf life, tools, software version, inspection state and exact location. The settlement needs warehouse discipline before it needs a large warehouse.

Some cargo should be designed to create new capability rather than merely extend consumption. A machine tool can repair future hardware. A metrology bench lets residents verify dimensions and electrical characteristics. A clean enclosure enables electronics and medical work. A standardized pump family reduces the number of unique spares. A modular power converter can support several loads. These “capability multipliers” are often more important than a highly optimized single-purpose device.

Local resources should be introduced in layers

ISRU is frequently discussed as though “using local resources” were one technology. It is a production chain. Water extraction requires locating ice, excavating material, handling dust, moving feedstock, heating or otherwise separating water, removing contaminants, storing the product and dealing with residue. Atmospheric oxygen requires gas intake, compression, electrochemical processing, thermal control, purification and storage. Construction feedstocks require mineral characterization, beneficiation, forming, joining and quality assurance.

The first useful local process is therefore not necessarily the one with the largest theoretical mass saving. It may be the one whose product is easy to verify and whose failure does not endanger the crew. A prudent campaign can use early resource plants as industrial learning systems: measure throughput, energy per kilogram, maintenance hours, contamination, rejected product and degradation over seasons. Only when the data exist should the crew’s survival or return depend on the plant.

Return capability must be protected from settlement ambition

Early crews should not consume or repurpose hardware needed for safe return simply because settlement growth creates pressure for more equipment. The ascent/return chain belongs to a protected configuration with known propellant, power, thermal state and maintenance requirements. If local propellant production is part of the architecture, the required inventory should be completed and verified with margin before crew departure from Earth whenever the design permits.

This separation creates a healthy asymmetry: exploration and construction can be aggressive only after the return system is conservative. A crew may accept that a greenhouse experiment fails; it should not accept that the only route home depends on an uncommissioned compressor. As the settlement matures, the return chain can itself become redundant, but the principle remains: growth assets and emergency assets should not silently become the same inventory.

A settlement becomes real when maintenance becomes routine

The emotional image of colonization is arrival. The engineering signature of colonization is recurring maintenance. Filters are changed, seals inspected, software rolled back, bearings lubricated, inventories reconciled, calibration standards checked and repairs documented. The community stops treating every fault as a mission anomaly and starts treating reliability as an everyday civic function.

Maintenance data should feed the next launch campaign. If a valve type wears twice as fast as predicted, the settlement needs more than replacement valves: it needs root-cause analysis, perhaps a design change, different material, better dust exclusion or a local manufacturing path. Every failure becomes information. The best campaign architecture therefore gets more robust with time because it converts operational history into design changes and more accurate inventories.

Campaign engineering · proof before dependence

Design the first settlement around proof gates, not dates

A calendar is useful for coordinating work, but it is a poor definition of readiness. A launch date can be announced years in advance; a settlement becomes ready only when specific capabilities have been demonstrated under the conditions in which the crew will depend on them. The practical roadmap therefore needs gates: conditions that must be met before the next level of dependency is accepted. This is stricter than asking whether a technology exists. A water processor can exist without being maintainable on Mars. A power source can exist without a local black-start strategy. A habitat can hold pressure without proving that a damaged compartment can be isolated while the rest remains habitable.

NASA’s 2026 Mars architecture trade space is still deliberately open in several areas. It treats transport, entry/descent/landing, crew systems, surface systems and ascent as coupled decisions, and it has already narrowed some options, including selecting nuclear fission as the primary surface-power technology for initial human Mars missions. That is an important distinction: a current NASA architecture decision is evidence about an exploration campaign, not evidence that a self-sufficient city architecture has been selected. A settlement roadmap must inherit the demonstrated pieces while keeping its own assumptions explicit.

Example proof gates for a first crew-dependent surface campaign
GateQuestion that must be answeredEvidence required before crew dependency
PowerCan essential loads survive loss of the largest source or bus?Black-start test, load-shedding sequence, independent emergency storage, physically separated distribution where practical.
WaterCan potable water still be produced after a processor fault?Stored reserve, second treatment path, contamination detection, replacement media, verified cleaning procedure.
AtmosphereCan oxygen and carbon-dioxide control continue through a major fault?Buffer gas, independent sensors, emergency scrubbers, leak isolation and repair tools.
HabitatCan one volume be lost without losing the settlement?Pressure-compartment test, fire isolation, safe haven, local breathing protection and evacuation route.
CommunicationsCan the crew operate when Earth is delayed or unavailable?Local procedures, cached technical data, autonomous planning, time-critical decision authority and degraded-mode navigation.
ReturnIs the crew’s route home protected from a single surface failure?Ascent readiness, propellant margin, independent checkout, compatible rendezvous/navigation chain and abort logic.

A missed launch window is an engineering test, not only a schedule problem

Efficient Earth-to-Mars launch opportunities recur at roughly 26-month intervals because of the relative orbital motion of Earth and Mars. That does not mean cargo can be sent only once every 26 months; it means that the energetically attractive windows that dominate conventional Mars planning are separated by about that interval. For a settlement, this orbital fact becomes a resilience test. If a critical spare part is discovered missing two weeks after the main cargo opportunity, “send another one next month” may not be a realistic assumption.

A useful settlement metric is therefore the number of missed resupply windows that essential functions can tolerate. The value is not a magic threshold. It forces the designer to name what is stocked, what is repairable, what can be substituted and what remains a hard dependency on Earth. A four-person expedition might carry an exceptionally deep stock of a few critical spares. A hundred-person settlement cannot simply multiply every spare by twenty-five; it needs local manufacturing, standardized components, inspection, configuration control and a rational inventory system.

Pedagogical calculation: landing reliability across a campaign

Suppose a notional cargo architecture needs 12 successful landings before the first crew depends on the surface system. Assume, only for this example, that each landing has an independent probability of success of 95%. Let p mean the probability that one landing succeeds, and let n mean the number of landings that all need to succeed. If the events were truly independent, the probability that every one of the 12 succeeds would be:

P(all succeed) = pn = 0.9512 ≈ 0.540

The symbol P means probability; p = 0.95 means a 95% success probability for one landing; n = 12 is the number of required successes. The exponent does not mean that landing twelve is intrinsically harder: it represents multiplying the same assumed success probability twelve times. Under these deliberately simplified assumptions, the chance that all twelve work would be only about 54%.

This does not predict a real Mars program. Independence is a strong assumption, vehicle reliability changes with experience, failures can be correlated, and a good campaign should not require every cargo event to succeed. The point of the calculation is architectural: if the settlement plan collapses because one of twelve cargo flights is lost, the plan has converted a moderately reliable vehicle into a fragile campaign. The remedy is not a nicer probability figure; it is spare capacity, duplicated functions, replaceable cargo manifests and the ability to re-plan after loss.

Cargo should deliver capabilities, not a sequence of irreplaceable boxes

Early cargo manifests are often described by mass: tonnes of power equipment, tonnes of habitat, tonnes of food. Mass is necessary but insufficient. A robust manifest is organized by capability. If cargo lander A is lost, which minimum set of functions still exists? Can a reactor delivered by B energize a habitat delivered by C? Are connectors, voltages, data protocols, lifting fixtures and software versions compatible? Is the spare pump for one water system interchangeable with another? Interoperability turns cargo loss from a mission-ending event into a configuration problem.

This is why “standardization” is not bureaucratic decoration. On Mars, a connector standard can be survival infrastructure. Every unique fastener, pressure fitting, voltage, software protocol and filter cartridge creates another item that must be stocked, manufactured or adapted. The settlement becomes more independent not merely when it manufactures more kilograms locally, but when it reduces the number of unique imported things whose absence can stop a vital function.

ISRU should be layered by consequence

ISRU, in-situ resource utilization, means using resources found at the destination rather than importing every product from Earth. Mars offers atmospheric carbon dioxide and, in many regions, accessible water ice or hydrated materials. Yet “use local resources” hides a chain of machinery: prospecting, excavation, transport, crushing or melting, purification, chemical conversion, storage, quality assurance, power and repair.

The safest sequence is therefore to introduce ISRU by consequence. A demonstration may first produce a useful product while imported reserves remain available. The next stage may use local production for routine consumption while Earth-supplied reserve covers outages. Only after reliability, maintenance and storage have been demonstrated should the crew’s return or survival depend on continuous local production. NASA’s MOXIE experiment is a useful example of the distinction: it demonstrated oxygen production from Martian atmospheric carbon dioxide and ultimately produced 122 grams of oxygen in total, reaching 12 grams per hour at best and at least 98% purity. That is a genuine technology demonstration; it is not an industrial oxygen plant for a crew or ascent vehicle.

Protect the return chain before expanding the settlement

A one-way settlement narrative can make return capability sound philosophically optional. Early human missions cannot responsibly treat it that way. NASA’s Mars trade-space work explicitly treats ascent from the Martian surface as a major unresolved architectural choice: ascent propellant may be imported or produced in situ, and the ascent vehicle may be integrated with or separate from the lander. From the settlement perspective, the key principle is simpler: do not allow routine expansion to consume the margins that protect the crew’s exit path.

That means separating “city growth” inventory from return-critical inventory, protecting ascent checkout from unrelated software changes, reserving power and maintenance time for the departure chain and defining clear authority over any resource that is shared between survival and return. The more attractive local production becomes, the more tempting it is to use the same tanks, pumps, electrical buses and operators for everything. That efficiency can also create common-cause failure.

The first hundred sols should look more like commissioning than colonization

A sol is a Martian solar day, about 24 hours and 39 minutes. During the first hundred sols of a crew-dependent site, the most valuable work is likely to be unglamorous: verify sensor calibration, map actual power demand, sample water quality, inspect seals, establish dust-cleaning frequencies, measure spare consumption, rehearse fire and depressurization procedures, validate software rollback, inventory tools and record the actual hours required for maintenance. These numbers replace assumptions with operating history.

Every procedure that moves from “we think this will take two hours” to “three different crews performed it safely in 95 minutes with these tools” increases settlement knowledge. Every component that fails earlier than predicted changes stocking. Every filter that lasts longer than expected reduces imported mass. Colonization advances when uncertainty is converted into measured operating data.

Primary references used in this module

After giant architectures, the radical move is subtraction

In the late 1980s American plans for renewed lunar exploration and eventual human missions to Mars generated large studies and large architectures. In that setting Robert Zubrin and colleagues at Martin Marietta developed Mars Direct. NASA explicitly records the architecture in histories of human-Mars planning and later Mars reference missions. [Z3][Z4] The key intellectual move was not a magical new technology; it was to ask what could be removed if Mars itself supplied part of the return resources.

That instinct runs against the natural growth of a large program. Difficult missions tend to accumulate vehicles, assembly steps, depots and infrastructure. Mars Direct instead pre-deploys the return vehicle, produces return propellant on Mars, verifies that capability, and only then sends the crew. The Mars Society still presents this sequence as the core of the concept. [Z5] NASA Ames has publicly described Mars Direct as a 1990s architecture using conventional rockets and Martian in-situ resources. [Z2]

Settlement operations · from landing site to maintainable town

The roadmap after landing: turn a site into an operable place

Landing cargo is only the beginning of construction. A settlement site must be surveyed, zoned, connected, inspected and made maintainable. The first physical map should therefore be more than a list of habitat coordinates. It should identify landing hazard zones, blast/plume zones, clean scientific areas, water prospecting zones, power corridors, buried or protected utility routes, vehicle roads, emergency refuges, medical access, dust transition zones and future expansion reservations. If these functions are allowed to grow randomly, later generations inherit expensive conflicts that may be difficult to correct under pressure.

A useful principle is separate what can fail together. Landing pads should not threaten the only power plant. Oxygen production should not share every electrical and software dependency with carbon-dioxide removal. Medical oxygen should not exist only in the same storage manifold used for routine industrial oxygen. Data archives should not depend on one server room. Habitats should be connected enough for rescue but compartmented enough to survive a fire or pressure loss.

Site certification is a campaign, not a photograph

Orbital imagery can identify terrain, slopes, rock abundance and some indicators of subsurface ice, but a crew-dependent site needs local measurements. Robots can verify bearing strength, dust behavior, subsurface conditions, radiation environment, communications geometry and access routes. A promising water-ice signature still needs extraction tests because “ice exists” and “water can be produced reliably at useful energy cost” are different statements.

The site-selection dossier should preserve negative results. If a drill jams, a radar interpretation proves wrong or a slope becomes unsafe under loaded vehicle operations, that information is part of the architecture. A good site is not the location with the most attractive single resource; it is the location where the total system closes with tolerable risk.

Surface logistics needs traffic rules before traffic exists

Rovers, cranes, cargo pallets, pressurized vehicles and people in EVA suits create a logistics network. Even with a tiny population, routes need priorities and exclusion zones. A vehicle carrying emergency oxygen should not be trapped behind excavation spoil. A rover should not cross a contamination-sensitive scientific area because the shortest route happens to pass through it. A heavy transport route should not repeatedly cross fragile buried pipes or communications lines.

This sounds like city planning because it is city planning under survival constraints. The “road” is also an emergency corridor, dust source, maintenance surface and navigation reference. Standard pallet sizes, lifting interfaces and vehicle attachment points can reduce the number of unique tools and adapters. Early standardization creates compound benefits decades later.

Food autonomy should be measured in nutrients and failure tolerance, not greenhouse area

A large greenhouse is visually persuasive but does not prove food autonomy. A settlement diet needs calories, protein, fats, micronutrients, acceptable texture and variety. Crops also need lighting or sunlight management, water, nutrient chemistry, carbon dioxide, temperature control, pollination strategies where relevant, disease control and labor. Some foods may remain more efficient to import in dry, compact form for a long time.

A practical roadmap can separate four levels: fresh-food supplementation; partial calorie production; nutritionally complete local diet with imported inputs; and a genuinely regenerative food system in which seeds, fertilizers or nutrient sources, equipment and biological controls can be sustained locally. Each level should state what is still imported. “We grow vegetables” is not the same statement as “we can feed the settlement.”

Medical autonomy grows by response time

For a low-Earth-orbit crew, terrestrial expertise and evacuation options remain relatively close. Mars removes that assumption. Communication delay means that a time-critical emergency cannot wait for a specialist on Earth to conduct the procedure step by step. Evacuation to Earth may take months and can be impossible during parts of a mission. Medical planning therefore asks what conditions must be diagnosed and treated locally, which drugs and sterile supplies age in storage, what imaging is available, how blood products or substitutes are managed, and which crew skills need redundancy.

The settlement should build medical depth before population growth creates demand. One clinician cannot be a single point of failure. Training must include non-medical crew for stabilization and procedures. Equipment should favor multipurpose tools where that does not compromise safety. Medical records and decision support must remain locally available during communications outages.

Crew size is an operations trade, not only a seat count

Adding people increases food, water, habitat and transport demand, but it also adds expertise and labor. NASA human-factors work published in 2026 highlights exactly this trade for Mars: tasks that mission control performs for low-Earth-orbit missions may shift to the crew because of delay and blackouts. Modeling cited by NASA found that, under one set of assumptions, more than six crew members could be needed to provide work hours comparable to a four-person ISS mission once additional Mars-transit tasks are transferred locally. That result is not a universal minimum crew size; it demonstrates why crew complement must be derived from workload and expertise rather than selected by tradition.

For a settlement, the trade becomes broader. Population creates redundancy in skills, but only if training and shift schedules make those skills available during emergencies. Two surgeons who always work the same shift do not provide full temporal redundancy. Three electrical technicians trained on three incompatible equipment families may not substitute for one another. Crew planning and hardware standardization are linked.

The spare-parts problem eventually becomes a manufacturing problem

No inventory is infinite. At first, Earth can supply pumps, electronics, seals, motors and medical consumables. With time, the number of unique parts becomes too large to protect by simple overstocking. The settlement then needs a hierarchy of local manufacturing. Simple brackets, ducts, housings and tools may come first. Later capabilities include machining precise metal parts, polymer processing, glass and ceramics, cable manufacture, motors, sensors and eventually electronics. Each step requires its own feedstock, energy, metrology and quality assurance.

Metrology means measurement science: knowing dimensions, pressure, temperature, electrical values and material properties accurately enough to prove that a locally made part is fit for use. A machine shop without calibration standards can produce objects that look correct but fail at the interface. Manufacturing autonomy therefore depends on measurement autonomy.

Data is a supply chain too

A settlement imports more than physical cargo. It imports software updates, scientific databases, medical knowledge, manufacturing drawings, standards and educational material. Local copies are essential because Earth links can be delayed or disrupted. The site needs versioned repositories, offline documentation, backups in physically separate locations and a process for deciding which Earth updates are safe to install.

A dangerous failure mode is knowledge divergence: a technician follows a drawing that no longer matches modified hardware, or a software update assumes a sensor version not installed on Mars. Configuration management keeps the digital model synchronized with the physical settlement. It should record modifications as carefully as a hospital records medication or an aircraft operator records maintenance.

From outpost to settlement: a practical sequence of increasing independence

  1. Pre-position and verify. Land power, communications, habitat, water reserves, spares and robotic construction capability before crew dependence.
  2. Commission locally. Convert design assumptions into measured operating data; prove faults, repairs and degraded modes.
  3. Close vital loops gradually. Increase water recovery, oxygen production and waste recycling while maintaining protected reserve paths.
  4. Build maintenance depth. Standardize parts, train multiple people, create metrology and repair workshops.
  5. Localize bulk materials. Water, shielding, construction aggregates and selected chemical products reduce imported mass.
  6. Localize complex production selectively. Manufacture the parts whose logistics risk justifies the industrial investment.
  7. Grow social infrastructure. Medicine, education, governance, records, conflict resolution and public spaces become survival infrastructure.
  8. Prove missed-resupply resilience. Demonstrate survival through a deliberately assumed lost cargo window before claiming meaningful independence.

The sequence does not prescribe dates. Each stage should begin when the previous stage has produced enough evidence and reserve to make the new dependency acceptable. That is slower than a promotional roadmap and much more useful to a real engineering program.

Additional primary references

Operational roadmap · what the first five years would actually prove

The first five years should be measured by declining dependence, not rising population

Population is a seductive progress indicator because it is easy to count. It is also incomplete. A base can double its population while becoming more fragile if every new resident adds imported food, unique hardware and maintenance demand faster than local capability grows. A better early-settlement metric is dependency per person: how many kilograms, unique parts, specialist interventions and Earth-controlled decisions are still required per resident and per year?

Year one of a hypothetical settlement should mainly establish reliable operations: characterize real resource consumption, learn failure rates, validate dust procedures, measure maintenance hours and prove emergency drills. Year two can reduce repeated imports that are bulky or simple to localize, such as shielding material, some water and basic fabricated parts. Years three to five can deepen repair, food production, chemical processing, storage, medical capability and technical training. This sequence is a scenario, not a forecast; its purpose is to show that autonomy is a vector of many dependencies, not one percentage.

A dependency ledger can make progress visible

Example annual dependency ledger for a growing settlement
DependencyEarly phaseDirection of progressEvidence required
Potable waterLarge reserve plus recycling; local extraction experimental.Routine local extraction with reserve and second treatment path.Measured rate, energy, purity, downtime and seasonal variability.
OxygenStored oxygen plus regenerative life support.Local production covers routine demand with protected reserve.Production rate, storage, purity, maintenance and fault recovery.
FoodMostly imported shelf-stable food plus fresh crops.Increasing local calories and nutrients without reducing reserve.Yield over multiple crop cycles, disease events, labor and nutrient inputs.
Spare partsEarth inventory dominates.Local manufacture of high-use/simple parts, then selected precision parts.Dimensional/material verification and successful service history.
Expert decisionsEarth specialists consulted for many anomalies.Local crews diagnose and authorize more time-critical actions.Training, drills, incident review and safe outcomes under delay.

Do not optimize independence faster than safety

A settlement can become “more local” and less safe if it replaces a proven imported component with an immature local substitute too early. The goal is not to minimize imports at any cost. The goal is to eliminate dependencies in the order that improves resilience. Some imported items may remain rational for decades because they are light, reliable and difficult to manufacture. Other products, especially bulk water, shielding or simple structural material, may justify local production much earlier.

The final criterion is therefore not ideological self-sufficiency. It is the ability to keep vital functions within safe limits despite transport delay, equipment failure and communication disruption, while progressively increasing the fraction of repair and production that can be performed locally.

Readiness metrics · replace “soon” with measurable conditions

Five metrics are more useful than a promised arrival year

A practical colonization roadmap should publish the state of five quantities: pre-positioned survival duration, fraction of vital functions with an independent backup path, maintenance workload per resident, critical imported dependencies, and number of resupply opportunities the site can miss without loss of life. None of these is a universal threshold, but all force hidden assumptions into the open.

For example, “180 days of survival without scheduled cargo” must specify the scenario: population, rationing, failed equipment, available local water and whether return capability is counted separately. “80% of critical functions have redundancy” must explain whether the backups share power, software, cooling or location. “Ten imported critical parts remain” must identify their service life and whether a substitute can be made locally. A metric without its boundary is only a marketing number.

Readiness should improve monotonically in the important dimensions even if the launch date moves. If a delay allows more surface runtime, more spares, better training and a second recovery path, the architecture can become safer while the calendar becomes later. A roadmap that treats schedule as the only progress variable will repeatedly hide technical debt behind dates.

Martian methane as an example of a broader architectural logic

One of the best-known elements of Mars Direct is the use of Martian atmospheric CO₂ in a chemical chain producing propellant. Exact reactants and mass flows vary between versions, but the architectural logic is powerful: a resource available at the destination can replace imported mass if the plant, power, catalysts, storage and reliability needed to use it are themselves a better trade than transporting the final resource.

That “if” is essential. ISRU is never free mass. It trades cargo for hardware, power, time, risk and maintenance. Zubrin’s lasting contribution was to force architects to make that trade explicitly instead of treating Mars only as an inert destination.

The realistic formula

Humans could colonize Mars by sending robots first, landing infrastructure before crews, building redundant power and shelter, producing water and oxygen locally without immediate dependence, selecting cross-trained teams, expanding repair and manufacturing capacity, and creating institutions able to govern a community separated from Earth. Every step is individually conceivable. The challenge is making all of them work together for decades.

Explore the books behind the broader Mars project

This guide is the engineering doorway: it organizes the physical steps required to establish a human foothold and points outward to specialist monographs when a subsystem needs deeper treatment. The long-form books explore the broader human and institutional consequences separately.

I Walked on Mars — Book 1

Explore Book 1

I Walked on Mars — Complete Series

Explore the series

Frequently asked questions

How long would it take to colonize Mars?

There is no reliable date. The decisive timeline is set by capability demonstrations, launch economics and political continuity rather than one announced target year.

What should be sent to Mars before humans?

Power systems, communications relays, navigation aids, habitats, emergency stores, surface mobility, robotic cargo handling and pilot-scale water and oxygen equipment should operate before a crew depends on them.

Could the first settlers survive without Earth?

Not completely. Early settlers would require Earth-made electronics, medicines, specialized tools and replacement equipment. Their goal would be increasing resilience, not instant independence.

What is the biggest obstacle to colonizing Mars?

There is no single obstacle. The central difficulty is systems integration: transport, power, landing, radiation protection, life support, maintenance, human health and governance must all remain functional together.

Before the first crew: make human arrival almost routine

A cautious settlement campaign would try to make the first human stay as unheroic as possible. Functions that can be demonstrated without a crew should be operated before people depend on them: power, communications, localization, weather monitoring, water production or storage, dormant-habitat operation, thermal control, leak monitoring and remote diagnostics. The purpose is not to remove all risk — Mars makes that impossible — but to avoid turning the crew into the first test technicians for life-critical systems that have never run in the real environment.

NASA's historical Exploration Zone concept is useful because it forces several needs into one geography. Scientific regions of interest, resource prospects, mobility corridors, landing areas and habitation must coexist within operational reach. A rich deposit behind terrain that the available vehicles cannot traverse is not an operational resource. A scientifically outstanding site with poor landing safety, difficult power conditions or unacceptable dust behavior imposes real tradeoffs. Site selection is therefore a multi-criteria systems problem before it is a choice of scenery.

A credible campaign can be organized around maturity gates. Gate 1: the region is mapped and environmental variability is characterized. Gate 2: multiple cargo elements reach the zone and exchange data. Gate 3: primary power survives a representative interval. Gate 4: the habitat holds pressure and temperature without crew intervention. Gate 5: a critical local inventory — water, oxygen or energy — is produced or secured. Gate 6: robotic systems can inspect, isolate or bypass a fault. Only after such demonstrations does the crew become an extension of the system instead of its only recovery mechanism.

Maturity sequence before the first durable human presence on Mars
A robust settlement campaign proves site, delivery, power, habitat, inventory and recovery capability before people become dependent on them.

A credible start depends less on one heroic first crew than on a sequence of campaigns in which each arrival increases the margin of the next. Pre-deployed stores, communications, power, spares and surface equipment can turn isolated missions into a cumulative architecture. A cargo failure should not automatically turn the next crewed window into an emergency.

As population grows, the objective changes from surviving until return to maintaining continuous services despite wear and faults. Shared infrastructure, distributed skills and local production then matter more than the peak performance of one vehicle or habitat.

NASA Mars trade-space status

NASA’s March 2026 architecture material explicitly keeps many Mars mission choices open. The settlement sequences here are consequently comparison architectures, not a claim that NASA has selected this exact campaign.

A cargo campaign should be designed to lose something without losing the mission

Assume, only to expose the logic, that a pre-crew settlement needs 600 tonnes of useful surface cargo and one successful vehicle delivers 100 tonnes. Six successes are mathematically sufficient, but a six-flight manifest has zero margin: one lost cargo makes the target impossible. With eight attempts, the campaign can absorb two losses and still reach 600 tonnes. More mass is launched, but the architecture gains a new property — tolerance to loss.

If the teaching assumption assigns each flight a 90% independent probability of success, the expected number of successes in eight attempts is 7.2. An expectation is not a guarantee. It simply shows that campaign planning must work with distributions rather than a deterministic manifest. Critical functions can be spread across flights, while large but less critical equipment can accept more concentration.

Minimum useful cargo: 600 t; cargo per successful landing: 100 t.

Six successes are required. Eight attempts can tolerate two losses while remaining above 600 t.

Independent failures are a teaching assumption; real common-cause defects can correlate several flights.

Common cause is therefore the deeper concern. Eight identical vehicles can share the same software, engine or procedural weakness. Diversity does not necessarily require eight different launch systems. It can mean learning between flights, separating component lots, testing configuration changes, and refusing to place every critical function in the campaign before early flights have generated evidence.

Return logistics begins with the first deployment

Even if early residents do not return every object to Earth, the architecture needs reverse flows: hazardous waste, scientific samples, failed parts for expert analysis, data products, recyclables and equipment requiring maintenance beyond local capability. A base designed only around Earth-to-Mars flow can accumulate orphaned chemicals, unknown hardware and items for which no disposition path exists.

Return also applies to people. An expedition with mandatory return has different inventory, redundancy and medical criteria from a settlement with no rapid evacuation. That mission contract has to be defined before hardware. Settlement architecture begins with what the program promises the crew when a serious failure, illness or schedule delay occurs.

Go further in the books

Stage 3: prove resource production without betting lives on it

MOXIE demonstrated that oxygen can be extracted from the carbon dioxide in the Martian atmosphere. That is a landmark result, but MOXIE was a small technology demonstration. A settlement needs industrial flow rates, compression, filtration, thermal management, storage and maintenance over years. Oxygen for breathing is only part of the demand; oxidizer for ascent vehicles can dominate the required mass.

Water extraction faces a similar scale gap. Excavating icy regolith, moving it into a sealed processor, heating it, separating contaminants and preventing refreezing are all power- and maintenance-intensive operations. For this reason, the first crews should carry strategic reserves and use local production to build margin progressively. “Living off the land” should begin as risk reduction, not as a single point of failure.

Stage 4: send the first crew as operators of a whole system

The first residents would need overlapping expertise rather than a set of narrow specialists. A physician who cannot assist with maintenance, or a power engineer who cannot support emergency care, creates brittle staffing. The crew must be able to isolate leaks, repair electrical systems, operate excavation equipment, grow food, conduct science, manage software and resolve conflict. No individual can master all of this, so documentation and cross-training become infrastructure.

Their operational tempo should be conservative. Early missions would spend far more time inspecting seals, cleaning filters, checking inventories and rehearsing emergencies than popular imagery suggests. Surface exploration matters, but the first achievement is a boring one: months in which every critical system remains understood and repairable.

Stage 5: survive the first missing shipment

A base is not permanent merely because its crew intends to stay. Permanence begins when the settlement can absorb a launch failure or a cargo delay without immediate evacuation. This requires distributed stores of food, water and oxygen; replacement components for pumps, valves and electronics; locally repairable structures; multiple power sources and protected seed and microbial stocks.

The correct metric is not complete self-sufficiency, which would be unrealistic for a small community. It is the length and severity of interruption the settlement can survive. At first that may be one missed delivery of non-critical goods. Later it should include loss of a major cargo vehicle, a greenhouse, a power unit or an entire habitat zone.

Stage 6: convert expedition infrastructure into settlement infrastructure

Repeated missions should not merely add beds. They should add capabilities. A machine shop reduces dependence on finished parts. A chemical plant turns local carbon dioxide and water into useful gases and feedstocks. A materials laboratory learns which bricks, glass, ceramics or metals can be produced economically. A larger medical suite increases the range of treatable conditions. Education and apprenticeship convert experience into durable local competence.

At this stage, the settlement’s geometry changes. No single pressure hull should contain all life-critical functions. Habitats, workshops, farms and stores are separated by fire and pressure barriers but connected by protected routes. Landing zones move farther away. Waste heat and water become resources in an integrated industrial ecology.

Stage 7: cross the threshold from base to city

A city appears when the community contains more than mission roles. Children are not required for the first definition of permanence, but long-term demographic continuity eventually becomes unavoidable. Schools, archives, courts, public spaces, cultural institutions and independent economic activity emerge. People arrive not only because a space agency assigned them, but because the settlement has work, relationships and a future of its own.

Political autonomy would probably develop gradually. Earth-based sponsors would retain contractual power as long as they provide essential transport and equipment. Yet communication delay and local risk already require operational autonomy. Over time, the people who bear the consequences of decisions will demand a larger role in making them.

Why Mars plans repeatedly look closer than they are

Human Mars plans have been proposed for more than seventy years. Von Braun produced technically detailed expedition concepts in the mid-twentieth century. Later strategies reduced crew size, used local propellant concepts or relied on reusable heavy launch vehicles. Each generation solved some previous constraints while revealing others. Transport mass is crucial, but it is not the only missing variable. Long-duration human health, dust toxicity, closed-loop reliability, landing very large payloads, surface power, medical autonomy and industrial maintenance remain coupled problems.

Schedules also depend on budgets, politics, test outcomes and launch-system maturity. Therefore, this guide deliberately avoids promising a date. A serious roadmap is defined by capability gates: demonstrate cargo landing, prove power, certify ice extraction, sustain life support, validate crew autonomy and only then increase dependence on local systems.

Delta-Sierra calculation: thirty sols of energy show why storage is not a primary source

Assume a small surface infrastructure with a 100 kW average electrical load. A Martian sol is about 24 hours 39 minutes, roughly 24.66 hours. Supplying that load for thirty sols represents 100 kW × 24.66 h/sol × 30 sols ≈ 73,980 kWh, or about 74 MWh. This calculation does not select solar, fission or any other technology. It simply exposes the inventory that would be required if someone tried to cover an entire month with stored energy alone.

E = P × t, where E is energy, P is average power and t is elapsed time.

E = 100 kW × (24.66 × 30) h ≈ 73,980 kWh.

As the settlement grows, the relevant question becomes: which primary generation remains available in degraded mode, and how much storage is needed to bridge transitions rather than replace generation?

The same logic applies to water and oxygen. Inventory is not autonomy; inventory buys time. An architecture must say what that time is for: repair a failed train, reduce load, switch to another process line, isolate a compartment or wait for a delivery. Stock with no recovery path merely postpones the terminal failure.

Settlement growth is therefore better described as a sequence of verified states than as a calendar of dramatic milestones. A phase is not complete when hardware has landed. It is complete when the hardware has operated for a representative duration, consumables and losses are understood, alarms have meaning, degraded modes have been exercised and the next response to a failure is known. That discipline is less cinematic than a first footprint, but it is much closer to the difference between a visit and the beginning of durable presence.

The first strategically important cargo may be the one carrying no people

A cautious campaign assigns enormous value to payloads that can operate alone. A cargo element that delivers power, relay communications, weather sensing, navigation beacons and robotic inspection can reduce the risk of every later landing. A second may deliver habitat, inventory and commissioning hardware. The key is for each arrival to increase observability before the crew is committed. The better the site can measure its own temperature, dust environment, available power and equipment state, the less likely the first crew is to arrive inside an opaque system.

This logic also separates functions that must work together from assets that should not share the same physical vulnerability. Two power sources side by side can be redundant against an internal fault yet vulnerable to the same landing plume or local event. Two water stores inside the same compartment can be counted twice while remaining exposed to one leak. Settlement geography therefore becomes part of common-cause engineering: distance, barriers, connectors and alternate routes matter.

The first crew then becomes the user of an instrumented infrastructure rather than the improviser of an unfinished base. Their job is to expand capability: recover equipment, commission a second line, validate a resource, qualify a repair, and document the differences between Earth assumptions and Martian reality. That is a less heroic beginning, but a much stronger beginning for durable presence.

Official sources and live resources

The references below lead to primary institutional material and, where a programme’s own objectives matter, to official programme sources. A source documenting an objective does not by itself demonstrate that the objective has been achieved.

Official corporate pages describe the organization’s own plans and announced schedules. Public social-media feeds are dynamic and may include unverified third-party content.

NASA NTRS — Human Mars Landing Site and Impacts on Mars Surface Operations

NASA — Mars Architecture Trade Space

NASA — Moon to Mars Architecture Definition Documents

Primary and institutional sources

  1. NASA — Moon to Mars Architecture
  2. NASA — Moon to Mars Strategy and Objectives (updated 2026)
  3. NASA Science — Mars facts
  4. NASA/JPL — MOXIE completed its Mars mission
  5. NASA/JPL — Subsurface Water Ice Mapping
  6. NASA — Human factors and Mars communication delay
  7. NASA Science — Radiation exposure comparison for a Mars trip
  8. SpaceX — Mission: Mars
  9. Smithsonian National Air and Space Museum — von Braun’s Mars Project
Governance of a Mars colony: vision, rules, organization, transparency and adaptation.

Deep-dive dossier

MDRS: what analog missions actually test

Additional primary reference: NASA NTRS — Human Mars EDL architecture and heavy payload classes