there are a lot of SHALLs. Point 3 below in particular can be done via WEM. It may be possible to do it in a different manner, but probably not as elegantly or efficiently as through ERA and WEM.
3.2.1.2 Security Guidelines for RoT Attributes 1. Endpoint vendors SHALL provide the attributes defined in Section 3.2.1.1. 2. Endpoint vendors SHALL provide reference measurements of executable BIOS boot code at the lowest level of granularity for which they provide update and maintenance and that can be used to verify measurements returned from the RTR. 3. Endpoint vendors SHALL provide a mechanism for measuring and reporting a baseline of measurements for BIOS configuration data. 4. Endpoint vendors SHOULD deploy BIOS measurement and reporting mechanisms that do not preclude extension to option ROMs external to the system BIOS. 5. Endpoint vendors SHOULD provide attributes in a standardized format. 6. Endpoint vendors MAY provide an indication of compliance with [NIST-SP800-147].