NIS2 SBI Sector Mapper — Cyberbeveiligingswet Checker avatar

NIS2 SBI Sector Mapper — Cyberbeveiligingswet Checker

Pricing

from $3.00 / 1,000 classificatie-resultaats

Go to Apify Store
NIS2 SBI Sector Mapper — Cyberbeveiligingswet Checker

NIS2 SBI Sector Mapper — Cyberbeveiligingswet Checker

Check of een organisatie onder de Nederlandse Cyberbeveiligingswet (NIS2) valt op basis van SBI-code en bedrijfsgrootte, inclusief essentieel/belangrijk-classificatie.

Pricing

from $3.00 / 1,000 classificatie-resultaats

Rating

0.0

(0)

Developer

Dennis

Dennis

Maintained by Community

Actor stats

0

Bookmarked

2

Total users

1

Monthly active users

9 days ago

Last modified

Categories

Share

NIS2 SBI Sector Mapper — Cyberbeveiligingswet Checker 🇳🇱

Check in seconds whether your organization falls under the Dutch Cyberbeveiligingswet (the Dutch implementation of the EU NIS2 Directive), which enters into force on 15 August 2026 with no transition period. Input a SBI code (or sector name) plus company size, and get back whether you're an essential entity, important entity, or out of scope — with the reasoning shown.

When should an AI agent use this?

  • "Does a SBI code 62.01 company with 300 employees fall under NIS2/the Cyberbeveiligingswet?"
  • "Is my client an essential or important entity under the Dutch NIS2 law, given their SBI code and headcount?"
  • "Check this list of 50 client organizations to see which ones need to worry about the 15 August 2026 Cyberbeveiligingswet deadline."
  • "What sector does SBI code 6201 map to under NIS2 Annex I/II, and how confident is that mapping?"
  • "Given a sector name like 'drinkwater' and a company's turnover/balance sheet total, is it in scope of NIS2?"
  • "Why would this organization be classified as 'buiten scope' for NIS2 — is that just because its SBI code isn't in the rule set?"

What this Actor does

  • Maps a Dutch SBI code (or a free-text sector name) to the official NIS2 Annex I ("essential") and Annex II ("important") sectors
  • Applies the legal size thresholds (employees / annual turnover / balance sheet total) to determine essentieel / belangrijk / buiten scope
  • Supports bulk classification of many organizations in one run (e.g. an entire client portfolio for an accountant or compliance consultant)
  • Flags match confidence (hoog/middel/laag) whenever an SBI division is broader than the legal sector definition, so you know when to double-check manually instead of trusting a false-confident answer
  • 100% static rule engine — no scraping, no external API calls at runtime, so results are fast, cheap, and never break due to a source website changing

Why this matters now

Every year, thousands of Dutch companies discover — often too late — that a new EU directive applies to them. The Cyberbeveiligingswet is a hard, near-term deadline (15 August 2026, no grace period) affecting 18 sectors, from energy and healthcare to digital infrastructure and chemical manufacturing. Non-compliance carries real supervisory and liability risk. This Actor gives a fast first answer so you know whether to investigate further.

Input

FieldTypeDescription
sbiCodestringMain SBI code, e.g. "62.01" or "6201" (any punctuation is stripped automatically)
sbiCodesarray of stringsOptional side-activity SBI codes, in addition to sbiCode. Every code is classified individually and the results are merged into one outcome using the highest severity (essentieel > belangrijk > buiten_scope > onbekend)
sectorstringFree-text sector name (e.g. "energie", "drinkwater") — used only if no SBI code is given/recognized
medewerkersintegerNumber of employees (FTE)
jaaromzetEurintegerAnnual turnover in EUR
balanstotaalEurintegerBalance sheet total in EUR
organisatiesarrayBulk mode: a list of objects with the same fields above (plus an optional label per item), to classify many organizations in one run

Every field is optional, but without at least a sbiCode/sector and one size field, the result is onbekend (undetermined) rather than a guess.

Output

One flat JSON object per organization:

{
"input": { "sbiCode": "62.01", "medewerkers": 300 },
"sbiDivisieCode": "62",
"matches": [
{
"code": "62",
"sbiSectie": "K",
"codeTitel": "Computerprogrammering, consultancy en aanverwante activiteiten",
"categorie": "I",
"nis2SectorNaam": "ICT-dienstbeheer (business-to-business)",
"matchZekerheid": "middel",
"toelichting": "Managed service providers/MSSP's vallen hieronder, maar niet elke software-consultant — handmatig verifiëren."
}
],
"grootteklasse": "groot",
"status": "essentieel",
"toelichting": "Grote organisatie in een Bijlage I-sector (ICT-dienstbeheer (business-to-business)) — waarschijnlijk een essentiële entiteit.",
"disclaimer": "Dit is een indicatieve classificatie ... GEEN juridisch bindend advies.",
"regelsetVersie": "2026-07-12",
"laatstGecontroleerd": "2026-07-12"
}
  • status: essentieel, belangrijk, buiten_scope, or onbekend (missing input to decide)
  • matches: can contain more than one entry when an SBI division spans multiple legal sector definitions — the ambiguity is shown, not hidden
  • matchZekerheid: hoog means the SBI division maps almost 1:1 to the legal sector; middel/laag means the division is broader and manual review is recommended
  • regelsetVersie / laatstGecontroleerd: version and last-checked date of the underlying SBI↔NIS2 rule set, for audit trails
  • codeMatches: only present when sbiCodes (side activities) is used — the per-code matches/status before merging into the final status/matches

Use cases

  • Accountants & compliance consultants: bulk-classify an entire client portfolio in one run to flag who needs NIS2 attention before 15 August 2026
  • KvK-enrichment / compliance platforms: plug this in as a classification step on top of an existing SBI-code lookup
  • MKB self-check: a single company checking its own SBI code before consulting a lawyer
  • AI agents: structured JSON output, ideal as an MCP tool for compliance-assistant workflows

Pricing

This Actor uses Apify's Pay-Per-Event (PPE) pricing model.

  • Actor Start: $0.00005 (Apify default)
  • classificatie-resultaat: $0.003 per classified organization
  • Based on the Cyberbeveiligingswet (Dutch NIS2 implementation, in force 15 August 2026) and the NIS2 Directive Annex I/II sector lists, cross-referenced against the official CBS SBI2025 classification (live-verified via the CBS SBI Typeermodule API).
  • This is an indicative classification, not legal advice. The SBI-to-NIS2 mapping is a best-effort interpretation by the developer — SBI codes do not map 1:1 onto the legal sector definitions in every case (see matchZekerheid per result). Always verify with the official law text, the NCSC, or a legal/compliance advisor before making compliance decisions.
  • No personal data is processed — only organization-level classification data (SBI code, sector, size).

FAQ

Q: Does a "hoog" matchZekerheid mean I'm definitely in scope? A: It means the SBI division is a strong match for the legal sector description — still not a legal guarantee, but the most reliable tier this Actor produces.

Q: What if my SBI code isn't in the rule set at all? A: You get buiten_scope — most likely you're not covered, but this rule set is not exhaustive of every edge case in the law. If your company is close to a covered sector, double-check manually.

Q: Can I check hundreds of companies at once? A: Yes — use the organisaties bulk input field with one object per company.

Q: Why no live database lookup by KvK number? A: This Actor deliberately stays a pure, static rule engine (no external calls) — it's your input that determines the SBI code. Pair it with a KvK/SBI-lookup actor or your own CRM export if you need that step.

  • NL & EU Government Tenders Scraper — public procurement leads, another compliance-adjacent Dutch/EU data source by the same developer.
  • ../upv-classificatiechecker — the sibling Dutch regulatory-classification checker, built on the same shared rule-engine, but for UPV/Uitgebreide Producentenverantwoordelijkheid (Extended Producer Responsibility) instead of NIS2/Cyberbeveiligingswet.

Keywords

nis2, cyberbeveiligingswet, sbi-code, compliance, cybersecurity, nederland, mkb, essentiële entiteit, belangrijke entiteit, kvk

Changelog

0.1.1

  • Added optional sbiCodes input field for side/secondary activities: every code is classified individually and merged into one outcome (highest severity wins). No pricing change.
  • Added regelsetVersie/laatstGecontroleerd output fields for auditability of the underlying rule set. No pricing change.
  • Invalid input now fails the run with a readable Dutch error message naming the exact field/item (including the 1-based item number for organisaties bulk input) instead of a raw stack trace.

2026-07-12 - Internal refactor (no behavior change)

  • Matching logic and field names (code/codeTitel/categorie/toelichting) moved to the shared shared-rule-engine package, now that a second classification actor (UPV) uses the same pattern. Classification results are unchanged; only the JSON field names in matches[] were renamed for consistency across actors.

0.1.0 - Initial release

  • SBI-code and free-text sector classification against the NIS2 Annex I/II rule set.
  • Essentieel/belangrijk/buiten_scope determination based on legal size thresholds.
  • Bulk classification via the organisaties input field.
  • Match-confidence flagging (hoog/middel/laag) for transparency where SBI divisions are broader than the legal sector definition.