You are totally right... Nix is cool for advanced CPUs (i.e. x86, armv7, aarch64, etc) and much less so for microcontrollers.
But if your platform can run NixOS ... then ... let's see...
With nix I have a file that exactly describes the git sources (pinnable on precise changesets if required) for all my components (including custom kernel patches, device drivers, etc).
I use a nix config to create a fully GPLV3 compliant rootfs and another set of nix config files in a separate repo to create our device specific intellectual property, in a separate encrypted image different from the rootfs.
The nix config files easily describes everything i need to fully support Secure boot, as well as code to unseal a TPM luks password used to decrypt the image that contains our intellectual property for that device (basically the application).
All this is fully reproducible, so I can provide our clients with the nix config files for our rootfs, tell them to use nix and they can reproduce our exact rootfs image to run in the device , for GPLv3 compliance. Of course , then the device is "broken" , because our IP will not be decryptBle anymore. But the GpLv3 does not mandate full functionality when running foreign images...
Now I am absolutely certain all this can be also done with Yocto... but with less simplicity ... less joy ... :)
I used pSOS in the past, got burned when Integrated Systems was sold... then stayed away from proprietary OSes as much as I could. Used Debian with XEN later on... then Yocto in many products, then back to a Debian-like OS and now , finally, using Nix. It just works.