The Netherlands Picked NixOS. France Was Already Using It

When we heard about the Netherlands’ DAWO initiative, a formal mandate to replace outside software across Dutch public institutions with a NixOS-powered platform, we asked ourselves: How could France miss out on this?
Turns out, they didn’t. DINUM, the country’s Interministerial Directorate for Digital Affairs, has been running its own NixOS-based workstation setup on internal machines for months now.
Sécurix and its NixOS Bet

DINUM has developed Sécurix, a security-hardened NixOS setup aimed at system administrators. It builds on top of NixOS without forking it, applying the security guidelines published by ANSSI, France’s national cybersecurity authority.
The project is MIT licensed, lives under the cloud-gouv GitHub organization, and is currently in alpha, with v0.20.1 being its newest release having been introduced just a few hours ago.
According to Emilien Ercolani of The Stack, who attended a DINUM briefing in April, they are targeting implementation across ~250 of their staff’s workstations. This comes after a successful pilot run across 70 machines.
In its current avatar, Sécurix uses FIDO2 hardware security keys as the main login method, supports TPM2 and YubiKey, and leans on NixOS’s reproducible build model.
Keep in mind that this is not meant to be a Linux distro but rather a foundation from which workstations can be operated and managed centrally.
Alongside it, DINUM has published Bureautix, a companion reference template for regular office workstations. It ships with KDE Plasma, LibreOffice, ONLYOFFICE, and WPS Office.
The docs describe it as a “dummy example” that organizations are meant to fork and adapt privately, not a separately running system.
Why is NixOS the go-to?
The project itself has a European origin. Eelco Dolstra created it at Utrecht University in the Netherlands, and the NixOS Foundation is a Dutch nonprofit. For European governments, the appeal is obvious.
Mainstream Linux distro offerings like Fedora trace back to Red Hat, which is owned by the US-based IBM; openSUSE is tied to the Luxembourg-based SUSE; and Ubuntu is from England’s Canonical.
The underlying approach here seems to be avoiding projects that are based in foreign countries that could be forced to comply with the whims of their leaders.
From what I can see, France, the Netherlands, and Denmark are each taking a different path to the same place. In the end, if one wants control over their infrastructure, vendor-neutral and reproducible is the way to go.
Suggested Read 📖: postmarketOS is no more; not in that sense! It has undergone a rebrand.
![]()
