They likely offer at least some of:
* typical deployments
* training/consulting
* compliance with Ditch regulations
* shared infrastructure for custom builds, and CVEs
* typical deployments
* training/consulting
* compliance with Ditch regulations
* shared infrastructure for custom builds, and CVEs
As for the third item - that's not answering my question, it's a homunculus answer: What could the Netherlands have regulated that requires making changes to NixOS? Which NixOS maintainers themselves could not oblige?
I'm sure NixOS can provide those, but rather than each department figure out how to do that, organisations try to centralize figuring this out: which packages and configuration satisfies the requirements.
One of the items discusses MFA. Organisations will want to standardise on exactly which MFA devices they provide and support.