IEC 62443-3-3 Carries 51 System Requirements and Up to 150 Controls
The part described as the operational backbone defines 51 system requirements translating into roughly 100 to 150 implementable controls depending on the target Security Level.

IEC 62443-3-3 is described as the operational backbone of industrial cybersecurity implementation, defining 51 system requirements that translate into roughly 100 to 150 implementable controls depending on the Security Level targeted. Those requirements cover restricted data flow through segmentation, timely response to security incidents, and ensuring resource availability so that service does not degrade under attack.
The spread between 100 and 150 controls is the number worth planning around, because it makes the point that Security Level is a cost decision as much as a security one. Moving up a level does not add a feature; it multiplies the evidence, the testing and the ongoing maintenance across every requirement. Choosing a level higher than a customer asks for is an expensive way to be thorough.
Resource availability under attack is the requirement that most often surprises teams coming from IT security. In an office environment, a system under denial-of-service degrades and people wait. In an industrial control system the equivalent may be a process that cannot pause safely, which is why the standard treats availability as a security property in its own right rather than as an operations concern — an inversion of the usual priority ordering, and one that changes which trade-offs are acceptable.
Source: TeepTrak