KVM EFI support might have considerably improved meanwhile. For example, Debian nowadays can be easily installed on EFI and even SecureBoot enabled systems.
Therefore would be good to test both, EFI and SecureBoot.
Then making any changes to the Whonix libvirt KVM config files to support EFI, SecureBoot.
Yet to be decided if EFI (and maybe later SecureBoot) will become the new default for Whonix VMs as per: