Not require. But without a requirement, vendors are making their own choices. Some have gone with one-time programmable fuses to store the keys. Once programmed, only images signed with that key can be used. Otherwise, the device is a brick. Those vendors deserve to burn in hell (in my opinion as an embedded engineer that has implemented secure boot on a variety of platforms).