NIS2 SBI Sector Mapper — Cyberbeveiligingswet Checker
Pricing
from $3.00 / 1,000 classificatie-resultaats
NIS2 SBI Sector Mapper — Cyberbeveiligingswet Checker
Check of een organisatie onder de Nederlandse Cyberbeveiligingswet (NIS2) valt op basis van SBI-code en bedrijfsgrootte, inclusief essentieel/belangrijk-classificatie.
Pricing
from $3.00 / 1,000 classificatie-resultaats
Rating
0.0
(0)
Developer
Dennis
Maintained by CommunityActor stats
0
Bookmarked
2
Total users
1
Monthly active users
9 days ago
Last modified
Categories
Share
NIS2 SBI Sector Mapper — Cyberbeveiligingswet Checker 🇳🇱
Check in seconds whether your organization falls under the Dutch Cyberbeveiligingswet (the Dutch implementation of the EU NIS2 Directive), which enters into force on 15 August 2026 with no transition period. Input a SBI code (or sector name) plus company size, and get back whether you're an essential entity, important entity, or out of scope — with the reasoning shown.
When should an AI agent use this?
- "Does a SBI code 62.01 company with 300 employees fall under NIS2/the Cyberbeveiligingswet?"
- "Is my client an essential or important entity under the Dutch NIS2 law, given their SBI code and headcount?"
- "Check this list of 50 client organizations to see which ones need to worry about the 15 August 2026 Cyberbeveiligingswet deadline."
- "What sector does SBI code 6201 map to under NIS2 Annex I/II, and how confident is that mapping?"
- "Given a sector name like 'drinkwater' and a company's turnover/balance sheet total, is it in scope of NIS2?"
- "Why would this organization be classified as 'buiten scope' for NIS2 — is that just because its SBI code isn't in the rule set?"
What this Actor does
- Maps a Dutch SBI code (or a free-text sector name) to the official NIS2 Annex I ("essential") and Annex II ("important") sectors
- Applies the legal size thresholds (employees / annual turnover / balance sheet total) to determine essentieel / belangrijk / buiten scope
- Supports bulk classification of many organizations in one run (e.g. an entire client portfolio for an accountant or compliance consultant)
- Flags match confidence (
hoog/middel/laag) whenever an SBI division is broader than the legal sector definition, so you know when to double-check manually instead of trusting a false-confident answer - 100% static rule engine — no scraping, no external API calls at runtime, so results are fast, cheap, and never break due to a source website changing
Why this matters now
Every year, thousands of Dutch companies discover — often too late — that a new EU directive applies to them. The Cyberbeveiligingswet is a hard, near-term deadline (15 August 2026, no grace period) affecting 18 sectors, from energy and healthcare to digital infrastructure and chemical manufacturing. Non-compliance carries real supervisory and liability risk. This Actor gives a fast first answer so you know whether to investigate further.
Input
| Field | Type | Description |
|---|---|---|
sbiCode | string | Main SBI code, e.g. "62.01" or "6201" (any punctuation is stripped automatically) |
sbiCodes | array of strings | Optional side-activity SBI codes, in addition to sbiCode. Every code is classified individually and the results are merged into one outcome using the highest severity (essentieel > belangrijk > buiten_scope > onbekend) |
sector | string | Free-text sector name (e.g. "energie", "drinkwater") — used only if no SBI code is given/recognized |
medewerkers | integer | Number of employees (FTE) |
jaaromzetEur | integer | Annual turnover in EUR |
balanstotaalEur | integer | Balance sheet total in EUR |
organisaties | array | Bulk mode: a list of objects with the same fields above (plus an optional label per item), to classify many organizations in one run |
Every field is optional, but without at least a sbiCode/sector and one size field, the result is onbekend (undetermined) rather than a guess.
Output
One flat JSON object per organization:
{"input": { "sbiCode": "62.01", "medewerkers": 300 },"sbiDivisieCode": "62","matches": [{"code": "62","sbiSectie": "K","codeTitel": "Computerprogrammering, consultancy en aanverwante activiteiten","categorie": "I","nis2SectorNaam": "ICT-dienstbeheer (business-to-business)","matchZekerheid": "middel","toelichting": "Managed service providers/MSSP's vallen hieronder, maar niet elke software-consultant — handmatig verifiëren."}],"grootteklasse": "groot","status": "essentieel","toelichting": "Grote organisatie in een Bijlage I-sector (ICT-dienstbeheer (business-to-business)) — waarschijnlijk een essentiële entiteit.","disclaimer": "Dit is een indicatieve classificatie ... GEEN juridisch bindend advies.","regelsetVersie": "2026-07-12","laatstGecontroleerd": "2026-07-12"}
status:essentieel,belangrijk,buiten_scope, oronbekend(missing input to decide)matches: can contain more than one entry when an SBI division spans multiple legal sector definitions — the ambiguity is shown, not hiddenmatchZekerheid:hoogmeans the SBI division maps almost 1:1 to the legal sector;middel/laagmeans the division is broader and manual review is recommendedregelsetVersie/laatstGecontroleerd: version and last-checked date of the underlying SBI↔NIS2 rule set, for audit trailscodeMatches: only present whensbiCodes(side activities) is used — the per-code matches/status before merging into the finalstatus/matches
Use cases
- Accountants & compliance consultants: bulk-classify an entire client portfolio in one run to flag who needs NIS2 attention before 15 August 2026
- KvK-enrichment / compliance platforms: plug this in as a classification step on top of an existing SBI-code lookup
- MKB self-check: a single company checking its own SBI code before consulting a lawyer
- AI agents: structured JSON output, ideal as an MCP tool for compliance-assistant workflows
Pricing
This Actor uses Apify's Pay-Per-Event (PPE) pricing model.
- Actor Start: $0.00005 (Apify default)
- classificatie-resultaat: $0.003 per classified organization
Legal
- Based on the Cyberbeveiligingswet (Dutch NIS2 implementation, in force 15 August 2026) and the NIS2 Directive Annex I/II sector lists, cross-referenced against the official CBS SBI2025 classification (live-verified via the CBS SBI Typeermodule API).
- This is an indicative classification, not legal advice. The SBI-to-NIS2 mapping is a best-effort interpretation by the developer — SBI codes do not map 1:1 onto the legal sector definitions in every case (see
matchZekerheidper result). Always verify with the official law text, the NCSC, or a legal/compliance advisor before making compliance decisions. - No personal data is processed — only organization-level classification data (SBI code, sector, size).
FAQ
Q: Does a "hoog" matchZekerheid mean I'm definitely in scope? A: It means the SBI division is a strong match for the legal sector description — still not a legal guarantee, but the most reliable tier this Actor produces.
Q: What if my SBI code isn't in the rule set at all?
A: You get buiten_scope — most likely you're not covered, but this rule set is not exhaustive of every edge case in the law. If your company is close to a covered sector, double-check manually.
Q: Can I check hundreds of companies at once?
A: Yes — use the organisaties bulk input field with one object per company.
Q: Why no live database lookup by KvK number? A: This Actor deliberately stays a pure, static rule engine (no external calls) — it's your input that determines the SBI code. Pair it with a KvK/SBI-lookup actor or your own CRM export if you need that step.
Related Actors
- NL & EU Government Tenders Scraper — public procurement leads, another compliance-adjacent Dutch/EU data source by the same developer.
- ../upv-classificatiechecker — the sibling Dutch regulatory-classification checker, built on the same shared rule-engine, but for UPV/Uitgebreide Producentenverantwoordelijkheid (Extended Producer Responsibility) instead of NIS2/Cyberbeveiligingswet.
Keywords
nis2, cyberbeveiligingswet, sbi-code, compliance, cybersecurity, nederland, mkb, essentiële entiteit, belangrijke entiteit, kvk
Changelog
0.1.1
- Added optional
sbiCodesinput field for side/secondary activities: every code is classified individually and merged into one outcome (highest severity wins). No pricing change. - Added
regelsetVersie/laatstGecontroleerdoutput fields for auditability of the underlying rule set. No pricing change. - Invalid input now fails the run with a readable Dutch error message naming the exact field/item
(including the 1-based item number for
organisatiesbulk input) instead of a raw stack trace.
2026-07-12 - Internal refactor (no behavior change)
- Matching logic and field names (
code/codeTitel/categorie/toelichting) moved to the sharedshared-rule-enginepackage, now that a second classification actor (UPV) uses the same pattern. Classification results are unchanged; only the JSON field names inmatches[]were renamed for consistency across actors.
0.1.0 - Initial release
- SBI-code and free-text sector classification against the NIS2 Annex I/II rule set.
- Essentieel/belangrijk/buiten_scope determination based on legal size thresholds.
- Bulk classification via the
organisatiesinput field. - Match-confidence flagging (
hoog/middel/laag) for transparency where SBI divisions are broader than the legal sector definition.