Like in this case. The technology here utterly depends on Google Play Services on Android or App Attest on Apple (or "secure enclave"), and that is in fact essentially the only functionality.
This could have been solved instead switching to a standard (switching to OATH, RFC 4226 and RFC 6238), thus killing the dependency on Google/Apple while still allowing those devices to work smoothly, but also allowing a Linux implementation, allowing anyone . Plenty of European companies provide implementations for this, some with and some without the dependency on Google/Apple attestation.
Could they do something better, sure. I am still glad to see they did something at all.
https://www.logius.nl/actueel/qr-code-scanner-digid-app-werk...
(Also works fine on my GrapheneOS phone with only basic integrity, also worked on microG when I tested.)