Hi,
everything related to secure boot and encryption should be tested with BBRAM based keys before doing any attempts to blow EFUSES. If EFUSE is blown by the customer we no longer can help in most cases. When working with EFUSE, it has to be taken into account that "bricking" may happen, and that it may also permanent with no recovery.
In your case, it seems that it may be possible to "unbrick" but in order to really support this case, we should duplicate all the steps you have done, and "brick" some of the SoM's just for this tests.
Some hints:
if JTAG to FPGA and PS is dead, but the BOUNDARY SCAN is still alive, then it maybe possible to rewrite the spi -flash with new recovery fsbl over boundary scan, but if jtag is totally unresponive this would not be option
There are ERROR LED'S they should have a programmed sequence on failure, this may help understand why the sd card image is not booting
on other setup with same SoM make same security settings in BBRAM, then create encrypet sd card image and get it to boot, then try that sd card with the bricked one
there are maybe some more things to try
br
Antti