

These protections work at different layers and hence, you use both.
First off, you can’t really encrypt the first boot loader by design, your UEFI needs something it can read and run. You need to protect this first boot stage somehow, and this is what Secure Boot is for; it verifies the signature of the payload it starts to protect it against tampering.


Keep in mind this is a statement by a manufacturer who’s trying to get his customers to sign long term contracts at current prices, so it’s in their interest to have people believe that the shortage continues.
Doesn’t mean it’s not possible, bit it should be read in that context