I'm not entirely up to speed on the situation of UEFI secure boot for ARM; didn't Microsoft mandate that it can't be disabled for such devices to boot Windows? Is that the case here?
The UEFI secure boot requirements only apply if you want to distribute a commercial product and want to slap a "Designed for Windows 10" sticker on it - or negotiate a special distribution license with Microsoft (i.e. do not expect Windows 10 to be "free" if you want to use it in a commercially distributes product).