Strictly speaking, you can get traditional vendors to do firmware signing -- but getting them to put your public key in there will be more difficult, with volume most of the big vendors will be... accommodating.
Dell's 12th generation PowerEdge for example has a pretty good baseline outlined here:
http://en.community.dell.com/cfs-file.ashx/__key/telligent-e...
But that only covers the BIOS really, not things like firmwares in different PCI cards. But its a start.