Depending on the motherboard it can be very hard, pretty easy, or very easy. For my one motherboard that isn't covered by me-cleaner due to the newness, I verifiably turned off ME the "pretty easy" way: By downloading the latest bios from gigabyte, opening it in Intel's CSME tools (there are download links on some forums geared towards bios modding), flipping the unlabeled "reserved bit" which turns on "high assurance platform mode", and then flashing that bios .bin, also with Intel's tools.
I believe some motherboards won't let you flash the modded bios if it's cryptographically unsigned or something like that, which is good for other reasons... but I haven't run into it myself.
I've disabled ME on a couple of supermicro boards too, using me-cleaner, since they were supported. (What I consider the "very easy" method.)
edit: Sibling poster is right that it can't be fully disabled. I do assume it's effectively disabled when it no longer appears in device manager and Intel's ME inspection tools show it as disabled.