ARM addressed this by creating ATF which most companies now use:
https://git.trustedfirmware.org/TF-A/trusted-firmware-a.git/