The secure element can be on the same CPU die as Apple does with the SEP but a device with only TrustZone wouldn't meet the requirements. It also needs to be a high quality implementation providing the expected features.
That's already required if you want to sell the device in the EU (or EEA?) at all. So far, Motorola hasn't left the market with their low-end devices so I presume they intend to deliver on the updates