But how can you verify that the processor's own software, which ultimately runs the application, has not been compromised?
If you disallow installing applications post-issuance (which is probably a good idea for ID cards), you don't even have to worry about VM runtime integrity either, as there will be only your application running on the card.
This is how payments work for chip-and-pin system of EMV and login and signing systems of many businesses in the EU already. There is no need for third party attestation already.