rwk, I am very bullish on the shalls you mentioned as I have commented on before, and was commenting mostly on dabears post (even though it was a (reply-link-fail)
this stretch:
"The BIOS image and configuration baseline should be continuously monitored. If an unapproved deviation from this baseline is detected, the event should be investigated, documented, and remediated as part of incident response activities. The incident response plan should document the process and set of authorized tools that can be used to capture the evidence to help determine the root cause. The secure local update mechanism should be used to recover from a BIOS image compromise."
admittedly this is more of a operational response section, the more important point being the well-mention requirement for RoTU, with the only mentioned example being a TPM, and Wave's clear focus on this step-by-step with NIST and the complete harmony their products have in addressing exactly that.
I'm really just trying find weakness in the speculation, not that I am doing a particularly good job at convincing even myself.
The above content is my opinion.