I've seen no indication that security updates are ever stopped on "non-compliant" hardware: works just fine here.
The only hurdle I've personally come across is feature update releases not being installed as only SETUP.EXE (and sub-programs called from there) really checks CPU, TPM and other requirements.
I consider that a bonus and prefer LTSC and IoT anyway.
The only other known hurdle, which I haven't personally faced is the requirement for POPCNT support starting with 24H2 releases, I don't operate hardware that old any more.
I'm running Windows 11 (and Windows 2025 server) on Ivy Bridge and every Intel generation since (as well as Zens) from puny Atoms to hefty workstations without issues or TPM. Anything that ran Windows 10 is also running Windows 11 24H2 (apart from POPCNT), using Windows 10 drivers when needed.
I don't install, but clone from a well maintained and periodically updated base image: saves tons of time and effort, never complains about hardware compatibility and comes without nuisances such as OneDrive, Edge, Co-Pilot, Teams, secure boot, HVCI and plenty other nasties.
I also run both as "to go" variants (thanks Rufus!) on nice 1TB/s Kingston Data Traveller USB sticks.
The OS is much nicer and more flexible than what Microsoft wants to allow...