Choosing KBLI Business Codes for IT Consultants

Choosing KBLI Business Codes for IT Consultants
An Indonesian IT consultancy needs four codes to start: 62209 (computer consulting), 62199 (custom programming), 62900 (other IT services), and 70209 (management consulting). Add a second layer only for services you will really sell. Take the low-risk trading codes early — they cost nothing to hold and are painful to add later.
KBLI is the government's official list of business activity codes. Every Indonesian company picks a set of them for its deed of establishment, and that set follows the company everywhere: into the business registration number, into the online licensing system, into every tender document that asks what your company is allowed to do.
Why does the code list decide more than what the notary types?
Because each code carries a risk rating, and the risk rating decides how much licensing work you have signed up for.
Government Regulation 28/2025 on risk-based business licensing sorts every code into four tiers. Low risk needs only a NIB — the business registration number that acts as your company's ID card. Medium-low risk needs a NIB plus a Standard Certificate you issue yourself by declaring that you meet the requirements. Medium-high risk needs a NIB plus a Standard Certificate that a ministry actually verifies before it becomes valid, which means waiting.
So two consultancies with identical offices and identical clients can sit in very different queues, purely because one of them put a heavier code in its deed.
The list also decides what you may bid on. Procurement packages name the KBLI codes a bidder must hold. Miss the code, fail the administrative check — no appeal, no explanation. The e-katalog system goes further and checks the codes on your registration against the product category you are applying to sell.
Codes are cheap while the deed is being drafted and expensive afterward. Adding one later means amending the deed at a notary, then re-registering the activity in the licensing system. Adding one now costs a line of text. That asymmetry is the whole reason to think about this before signing rather than after losing a bid.
What changed in KBLI 2025, and does it affect you?
The classification was rewritten. Regulation of Statistics Indonesia (BPS) No. 7/2025 brought KBLI 2025 into force on 18 December 2025, replacing KBLI 2020 and realigning the whole structure to ISIC Rev. 5 — the United Nations industry classification standard published in 2024 that most countries use as their base. The list shrank from 1,789 five-digit codes to 1,559, a net loss of 230.
Three dates matter for anyone registering now:
- 27 April 2026 — BPS published the official 2020-to-2025 conversion table and the government confirmed that KBLI 2025 does not require anyone to obtain new permits.
- 13–14 June 2026 — the OSS licensing system went down for maintenance to migrate.
- 15 June 2026 — OSS reopened running on KBLI 2025, converting existing registrations automatically where the scope of activity did not change.
For a new company, none of that is a burden. It is a trap only in one specific place: the notary's template. Plenty of drafts still carry KBLI 2020 numbering, and the conversion is not always one-to-one. Several 2020 codes were split into two or three 2025 codes, and a careless conversion carries over one fragment while dropping the rest — leaving you licensed for a slice of what you meant to do. Check every final number against the official migration table before the deed is signed. That check takes twenty minutes and is the highest-value twenty minutes in the whole process.
Which four codes does every IT consultancy need?
| KBLI | Covers | Risk and licensing |
|---|---|---|
| 62209 | Computer consulting and IT facility management: advising on hardware and software needs, designing systems, procuring components through vendors, running a client's IT operations | Medium-high — verified Standard Certificate from the Ministry of Communication and Digital Affairs |
| 62199 | Custom programming: business applications, web, databases, IoT applications, and customising software inside a client's environment | Medium-low — self-declared Standard Certificate |
| 62900 | General technical work: software installation, workstation setup, disaster recovery, incident response, digital forensics | Low — NIB only |
| 70209 | Management and business consulting: strategy, business process work, digitisation advisory. Often required by tenders that include a study component | Low — NIB only |
62209 is the code that describes what a consultancy actually does, and it is also the only one of the four that makes you wait. It sits at medium-high risk at every business scale, micro included — being small does not buy you a lighter tier here.
The requirements across the 62 group are similar: an organisational chart showing technically competent staff on a contract of at least one year (a small company can satisfy this with one technical person), a flowchart of how the service is sold and delivered, and a list of equipment with photographs. The standard processing time is seven working days once the file is complete.
62199 replaced 62019 in the renumbering, and that pair is worth memorising — it is the one you will keep seeing in tender documents. More on that below.
Which codes match your actual service lines?
Add these only where the service is real. An unused code is harmless, but a code that pulls you into a heavier tier for work you do not do is not.
| KBLI | Take it when | Risk |
|---|---|---|
| 63101 | You do data entry, migration, or cleanup, or you produce reports from client data | Medium-low |
| 62201 | You sell security audits, vulnerability testing, or security policy work | Medium-high, all scales |
| 62191 | You build e-commerce applications or online stores for clients | Medium-low |
| 58290 | You license your own software product or SaaS rather than only selling project work | Medium-low; micro scale needs only a NIB |
| 63102 | You run servers, cloud, or hosting yourself for clients — not merely deploying into the client's own cloud account | Medium-high, verified certificate |
| 62204 | You design integrated IoT solutions (see below) | Medium-low |
| 85572 | You run paid IT training | Medium-high |
| 63900 | You operate a paid web portal or information service | Low — NIB only |
The distinction inside 63102 catches people out. Deploying an application into a client's AWS account is consulting work under 62209 and 62199. Operating infrastructure that you own and bill for is a different business, with the verification queue that goes with it.
Niche codes exist for blockchain applications (62193), AI components built for other developers (62194), video games (62110, 58211, 58219), and VR/AR (62192). Note that an AI application built to a client's order is ordinary custom programming under 62199 — 62194 is for selling AI libraries and components as such.
Why take the trading codes if you only sell services?
Because sooner or later a client asks you to supply the hardware, and a consultancy holding only service codes has to refuse or subcontract.
These codes sit at low risk and need nothing beyond a NIB, so there is no reason to leave them out of the deed:
- 46511 — wholesale of computers and peripherals. The general B2B procurement umbrella.
- 46512 — wholesale of software. Read the 2025 scope carefully: it narrowed to software on physical media with a perpetual licence. Digital licences and subscriptions now belong to 58290.
- 47401 / 47403 — the retail counterparts, for computers and software. Government software packages often name one of these as an acceptable alternative to a programming code.
- 73100 — advertising, if you run digital marketing campaigns for clients.
- 72102 — engineering and technology R&D, if you do prototyping. One caveat: R&D performed as a service for others rises to medium-high risk with a Standard Certificate. R&D for yourself stays low.
There is a practical wrinkle in public procurement worth knowing before you read your first tender document. Many packages still specify KBLI 2020 codes — you will see requirements written as "NIB with KBLI 62019 or 46512/47413". The official 2025 equivalents are 62199 and 47403 respectively, both already in the lists above, so a registration issued under the new numbering still satisfies the requirement. Bring the conversion table to the clarification meeting rather than arguing from memory.
Government IT work also runs through direct appointment and e-katalog far more often than through open tender. E-katalog checks the codes on your registration against the product category automatically when you apply as a supplier, which makes holding the right trading code a precondition rather than a formality.
What does an IoT line add?
The anchor is 62204: designing integrated systems to order, including hardware modification such as sensors and microcontrollers. The software, firmware, and dashboards around it are already covered by 62199. What you add beyond that depends on how you make money from the devices:
| KBLI | Take it when | Risk |
|---|---|---|
| 46523 | You sell IoT devices, routers, modems, or gateways to business clients | Low — NIB only |
| 77399 | You run a subscription model where the hardware stays yours and the client pays monthly | Low — NIB only |
| 26513 | You sell monitoring devices, data loggers, or meter readers under your own brand | Medium-low |
| 33201 | You do machine or system integration projects inside client factories, software included | Low — NIB only |
| 95102 | You provide after-sales repair and servicing for devices | Low |
| 27120 | You assemble your own electrical or control panels | Medium-low |
26513 rewards a careful read. It is an industrial code, and a company that owns the design and the brand still counts as the manufacturer even when the physical assembly is contracted out to another workshop. If you are selling a meter reader with your name on it, that is your code, regardless of who solders it.
Watch the installation codes. 43213 (electronic system installation — alarms, CCTV, building electronics) and 43212 (telecommunications network installation) sit inside the construction services regime. They are medium-high risk at every scale including micro, and the certification runs through the construction business certificate track under the Ministry of Public Works rather than through the usual IT channel. Listing them in the deed is fine, so the scope is available when you need it, but leave the licensing until a project actually requires it. Light IoT device installation at a client site generally stays within 62204 and 62900 as long as it is not formal building installation work.
Which codes look right but are traps?
Three of them, and all three are tempting because the titles read like consulting work.
62202 (digital identity) and 62203 (electronic certificates). These are for operators of identity systems and certificate authorities, not for consultants who advise on them. The licensing is heavy, and 62203 is registered only for large-scale enterprises. If what you mean is "general IT consulting", the correct code is 62209.
61201 (telecommunications service resale). A strict regime: formal partnership with an ISP, billing in the ISP's name, and a ministry certificate at every scale. Irrelevant to a normal consultancy, and expensive to hold by accident.
The PMSE obligation on 58290. If you later sell SaaS or software through your own online platform, the electronic-commerce scope attached to 58290 escalates to high risk and requires a trading licence through electronic systems (SIUPMSE). This is not something to solve at incorporation. Write it on the list of things to handle on the day you first put a payment button on your own site.
The same principle applies to intellectual property in your contracts: what you declare you do should match what you actually deliver and what you actually own. Mismatches between the registered scope, the contract, and the delivered work are the ones that surface during an audit or a dispute, which is the theme of who owns the code when a freelancer builds it. The equivalent problem on the supplier side — vendor SDKs shipped with no licence text at all — shows up in hardware integration contracts.
What happens after the deed is signed?
Five things, in this order:
- Issue the NIB through OSS. Activate the low and medium-low risk codes first — 62199, 62900, 70209, plus whichever second-layer codes you took. These are self-declared and go through quickly.
- File the verified Standard Certificate for 62209 immediately (and for 63102 if you took it). This one waits on ministry verification, so it is the long pole. Starting it last is the most common self-inflicted delay.
- Prepare the supporting documents before you start: organisational chart, the employment contract for your technical staff, the business process flowchart, and the equipment list with photographs.
- Deposit the capital and report the owners. Electronic proof of the paid-up capital is due within 60 days of the deed, and the beneficial ownership report — naming the real people who ultimately control the company, required by Presidential Regulation 13/2018 — is filed alongside it.
- File the quarterly investment activity report (LKPM) once operations begin. It is a routine obligation that becomes an irritation only when it is ignored for several quarters.
The list is a promise, not a formality
A code list is a description of what your company is prepared to be asked for. Too short, and you are the consultancy that cannot invoice for the laptops. Too long in the wrong places, and you are queuing for a certificate you will never use.
Start with the four. Add what you actually sell. Take the NIB-only codes while they are free. And file for 62209 the week you get your registration number, because that queue does not care when you remembered it.
This article is a research guide based on KBLI 2025 and the current OSS risk-based licensing profiles. Licensing requirements change, and profiles for individual codes are adjusted from time to time — verify each final code in OSS and against the BPS migration table before signing anything.
Related Posts
Building something similar?
Hotel Management System Development
Custom ERP-style hotel management software: bookings, room status, invoicing, staff, and WhatsApp automation — built around how your hotel actually runs.
See how I can help