For a smaller manufacturer (e.g. Fairphone), that may mean a lot. If I remember correctly in 2021 Fairphone was selling 100k phones per year?
Also I am genuinely interested: is it that hard to meet GrapheneOS' requirements? Feels like it shouldn't take years of R&D for every new iteration. And also that it's about getting the right deals with the suppliers, which is not really an R&D issue?
Hardware-wise it seems to be doable now that more and more CPUs have MTE. (And secure processors exist, most OEMs outside Google/Samsung are just too cheap to add them.)
What does add ongoing cost is doing monthly driver/firmware/kernel/etc. updates. But IMO they should be required by law. Just doing the minimal ASB patching is not keeping your users secure.
Also I am genuinely interested: is it that hard to meet GrapheneOS' requirements? Feels like it shouldn't take years of R&D for every new iteration. And also that it's about getting the right deals with the suppliers, which is not really an R&D issue?