I’m kinda familiar with that rabbit hole :P . Though, I didn’t quite consider your 3rd and 4th methods. So kudos to you for that!
While writing up a draft, I actually stumbled upon an (unfinished) article that goes over this subject in way more depth than I could.
Though, the author doesn’t mention NovaCustom that intends to combine Boot Guard, Heads and QubesOS certification on their devices.
I wonder how long it will take before it will drop off the top 10.