I just successfully installed a new NixOS machine with an encrypted root (yes, the latest installer does LUKS2) and followed the latest quickstart guide in order to setup secure boot. Enabling the UEFI setup mode on my new Asus laptop worked the same as described for Thinkpads.
Next up, trying to see if I can enable TPM LUKS unlocking. (For me, this is not a must, but nice-to-have).
UPDATE: Setting up TPM Unlocking as described here worked flawlessly. Awesome.