Not a lot has happened to security-misc in Qubes outside of Qubes-Whonix. Maybe more realistic to develop Kicksecure and then create a Kicksecure Qubes template. That might meet lower resistance than hardening Qubes Debian template.
Feel free to open any Qubes tickets.
As for outreach hardened-vm-kernel seems useful to contact both linux-hardened and oss-security mailing list.