The Purpose of the Diagram — Not a Presentation Tool
Every pharma OT project produces a network diagram. Most produce one too early, in a visually polished but technically shallow form that looks good in a design review presentation but fails to serve its actual function: as a controlled engineering document that the IQ team uses on-site to verify the as-built network matches the approved design.
The IQ team's job with the network diagram is simple: look at the diagram, look at the system, confirm they match. For that comparison to be possible, every element on the diagram must correspond to a real device with a real tag number, IP address, and physical location. A box labelled "SCADA Server" with no IP address, no tag number, and no indication of which rack it sits in cannot be verified. A box labelled "SRV-SCADA-01 — 192.168.20.10 — MCP-01 Rack A U8" can be walked over to, identified, and confirmed against the HDS component register in under thirty seconds.
The IQ-SYS-001 input documents table references "DWG-HDS-002 — Network Architecture Diagram (As-Built)" as a prerequisite document. This means the diagram must exist, must be at as-built revision before IQ execution begins, and must be formally controlled with a document number and revision. A hand-drawn sketch or an unsaved Visio file does not qualify. The diagram is a GMP document — it has a document number, a revision history, and it is approved under the same document control process as the HDS itself.
What the Diagram Must Show — The Mandatory Elements
The network architecture diagram for a pharma IQ must include the following elements. Every one of these is something an IQ team will look at and expect to find:
- Every network device with its equipment tag — switch tag (SW-OT-01), firewall tag (FW-OT-01), server tags (SRV-SCADA-01, SRV-HIST-01), HMI station tags, PLC CPU tag, engineering workstation tag
- IP address of every device — shown adjacent to the device symbol, as a label. Not in a separate table that the IQ team has to cross-reference separately.
- Zone boundaries clearly marked — OT Control Zone, OT Supervision Zone, DMZ, Corporate IT Zone — with clearly visible boundary lines or shaded regions
- VLAN IDs labelled on each zone — e.g. OT-SUP = VLAN 20, OT-CTRL = VLAN 10, MGMT = VLAN 30
- Every firewall symbol with its tag — outer firewall (FW-DMZ-01) and inner firewall (FW-OT-01) both visible, with the zone they separate shown on each side
- Every connection line labelled with protocol — OPC-UA, PROFINET, Ethernet, S7 TCP/IP — and connection direction where relevant (arrow showing data flow direction)
- Physical medium for key links — copper Cat6, fibre, etc., at minimum for any link that the IQ team will physically inspect during the cabling verification
- Legend / key — explaining zone shading, line types, and symbol meanings
- Title block — document number (DWG-HDS-002), revision, approval date, system name, site
What the Diagram Must Not Be
Understanding the failures is as useful as the specification. These are the most common reasons IQ teams reject or flag a network diagram as insufficient:
Generic device labels without tag numbers. "SCADA Server" is not an IQ-verifiable label. "SRV-SCADA-01" cross-references to the component register and can be physically located in the server rack.
IP addresses missing from the diagram. If IP addresses are only in a separate table in the HDS body, the IQ team must flip between two documents to verify a single device. Put the IP address on the diagram, adjacent to the device. The IQ team should be able to verify a device's identity, location, and network address from the diagram alone.
No zone boundaries or VLAN labels. A diagram that shows all devices on a flat topology without zone delineation cannot be used to verify that the segmentation architecture was implemented. The zones and VLANs are the compliance-critical part of the architecture — they must be visible.
No title block or document control. A network diagram without a document number, revision, and approval cannot be referenced as a controlled document in the IQ input documents list. It is not an approved engineering document.
Design-phase version used at IQ without as-built update. A diagram showing planned IP addresses that differ from the as-installed addresses generates a nonconformance at IQ. The diagram must reflect the as-built state before the IQ team walks on-site. This is the same as-built update requirement that applies to the full network IQ documentation package.
Tooling and Format — What Works
The diagram does not need to be produced with specialist network diagramming software. Microsoft Visio, draw.io (free, browser-based), or even PowerPoint with proper engineering discipline all produce acceptable output. What matters is the content and the document control — not the tool.
The format requirement from the IQ perspective is that the diagram is printed or rendered at a size where the device labels and IP addresses are readable. A diagram produced at A3 or A4 landscape with text sized at 7-8pt minimum is readable when printed. A diagram exported from a large canvas at low resolution, with 5pt text, is not. If the diagram is too complex to show all zones and devices at readable scale on a single page, split it — a logical topology overview diagram plus a detailed OT zone diagram is better than one illegible diagram that tries to show everything.
The diagram is referenced in the IQ as "DWG-HDS-002 — Network Architecture Diagram (As-Built) Rev A" — this means it needs a document number, a revision letter, and to be formally controlled in the project document management system alongside the HDS, IQ, and other GMP deliverables. It is signed off as part of the HDS package, not as a standalone document.
HDS-SYS-001 Appendix B provides the network architecture diagram template with zones pre-defined, colour-coded by zone type (OT-SUP, OT-CTRL, DMZ, Corporate IT), and a title block matching the HDS document number series. Device placeholders are set up with tag-number and IP-address label format pre-applied. The IQ-SYS-001 input documents table explicitly lists DWG-HDS-002 as a mandatory prerequisite document, with the as-built revision requirement noted. The diagram produced as Appendix B is the IQ team's primary reference document for physical network topology verification.