I am still using my almost-4-years-old Asus laptop, so I don't know much about this secure boot thingy, but I thought they require vendor to allow consumers to turn the secure boot off?
Turning off secure boot is only required for x86 and the actual article (at mjg59.dreamwidth.org) says "in case you don't want to fiddle with firmware settings."
So for Arm you would still need a signed boot loader.