I think it is bit more complicated than that. I checked some presentations [1] about UEFI/SB, and they do seem to imply that there is potentially some blobs (namely option roms, uefi applications and dxe drivers) that need to pass signature check. I don't know how much such modularity is really used in real life, especially in the boot path, but I think the "best practice" recommendation is to keep dxe core small and have stuff as loadable drivers.
[1] eg http://c7zero.info/stuff/Windows8SecureBoot_Bulygin-Furtak-B...