Hi Tristan,
You are hitting a Secure Boot state that cannot validate or read the Windows boot files when TPM is present. The fix is to reset the platform Secure Boot keys to factory defaults and then rebuild the EFI boot files while TPM and Secure Boot are both enabled.
Power the PC off. Enter UEFI setup and set Boot or CSM to UEFI only. Make sure Secure Boot is enabled and the mode is Standard or Factory, not Custom. Use the option that resets Secure Boot to factory defaults. Enable TPM 2.0 in firmware as Intel PTT or AMD fTPM. Save changes, keep Secure Boot on, and boot from a Windows 11 USB installer.
At the first Windows Setup screen press Shift+F10 to open Command Prompt. Run:
diskpart
list vol
Note the small FAT32 partition marked System, usually 100-260 MB. Select it by volume number and assign it a letter like S: with:
assign letter=S
Type exit to leave diskpart. Now recreate the signed UEFI boot files with:
bcdboot C:\Windows /s S: /f UEFI
Wait for the success message, close the window, remove the USB, and let the machine boot from Windows Boot Manager. If your Windows drive is not C: in this environment, substitute the correct letter you see for your Windows volume before running bcdboot.
Once back in Windows, open Settings > Windows Update and install everything offered so the Secure Boot DBX is current. Confirm the result in System Information. BIOS Mode should read UEFI and Secure Boot State should read On.
If you still see the same error, return to UEFI and verify that SATA or NVMe controller modes have not been left on a legacy or RAID-only setting. With a clean Windows 11 install, AHCI for SATA and pure NVMe for M.2 are typically the most compatible when Secure Boot and TPM are on.