Notarization is about protecting users who are not capable of making an informed decision about code safety from developers who refuse to comply with Apple's terms of service. Epic willfully violated their terms with Apple to make a point, and Apple is responding in the same way that they did to Facebook: taking away their access to the users, because they cannot be trusted to comply with the restrictions placed on their behavior.
Most (if not all) of the restrictions on the App Store exist to protect users from app developers who prioritize their own greed over the rights of privacy and safety that Apple promises the users of the App Store. Developers are the threat model, and there's nothing inherently wrong with Apple's response to Epic declaring themselves a rulebreaker — and, thus, a threat.
(If Epic was not trying so hard to be able to sue for damages, they might have been able to negotiate, same as Facebook did. But they wanted to be a martyr for the cause, so here we are.)
Consider this thought experiment: At your employer, an IT employee goes rogue and installs malicious code on your computer to read your email. How would you feel if IT leadership said "they promised not to do it again" and allowed them to continue unsupervised work on your computer while you're away? Most people would feel awful, because you can't trust the IT employee's word — they literally just broke their agreement not to snoop! — and because your leadership clearly doesn't care about your privacy.
Should Apple "fire" Epic, now that Epic's word can no longer be trusted? This answer should, in theory, match the answer above. I bet for most software developers, it does not. I encourage thinking through that dissonance rather than rejecting the thought experiment.