Furthermore, MS actually bent over backwards on x86 and required for certification that the option to disable secure boot be provided (they could have been silent on this issue):
"Enable/Disable Secure Boot. On non-ARM systems, it is required to implement the ability to disable Secure Boot via firmware setup. A physically present user must be allowed to disable Secure Boot via firmware setup without possession of PKpriv."
I'd wait for MS's response on ARM. They've taken some interesting architectural approaches with their current ARM implementation (striped and actually secure SD cards). There may be architectural reasons for this. Or it could be that there are security issues with it, given that UEFI on ARM is pretty new.
But in any case, if this is important to an OEM they can simply not get HW certification. This doesn't block anyone from actually installing Windows 8 on ARM on machines w/o this capability.