I've heard people saying things like "even a windows device could be ryf-certified if it was in ROM", but I see nothing even close to this when I look at currently ryf-certified devices. People are probably influenced by this: https://puri.sm/posts/librem5-solving-the-first-fsf-ryf-hurd... where a Purism engineer describes a "trick" to store a memory controller training firmware in ROM and run it on a "secondary processsor" so it can get Librem 5 ryf-certified; but to this day Librem 5 is still not certified and probably won't because of this specific issue.
Also there are the people who correctly question that ryf is silly because it accepts software without code available if it is in ROM and only runs on a secondary processor. I currently have no counter-argument to this and I think it would be great if FSF explained it clearly. Nevertheless, there are some reasonable points to consider that stance:
- AFAIK, the form of accepted code is only for "secondary processors" and can't take over the system or compromise it,
- having things in ROM forces manufacturers to maximally simplify it,
- having things in ROM forces manufacturers to implement more features in software that can be checked and
- having things in ROM forces manufacturers to be extra careful when implementing it.