Because with Nix you define your whole system as a Nix expression, it should be possible to get an inventory of everything for further analysis - for example for vulnerability scanning.
Of course it's never quite that easy! There's a lot of potential, but also a lot of work remaining before we can get a nice signal-to-noise ratio without missing things.
I wrote up an introduction to and summary of the current state of SBOM tools for NixOS, including nice clickable example output. Still a bit of a draft, I expect updates - feedback welcome!
