Yes — updates will be available and you can deploy them via SCCM (or your Windows Update pipeline). But yes, there are additional steps required* beyond just “deploy patch”. You need to make sure firmware, Secure Boot state, diagnostic data & policy/registry settings are all aligned. If you skip those, you risk devices that:
don’t get updated certificates
can’t receive Secure Boot security updates after expiry
potentially fail boot integrity checks