I always assumed that the CPU itself would have an internal signature verification mechanism built in. But after searching it seems the OS or BIOS is responsible for quite a lot... I haven't found anything clearly stating if and where cryptographic signatures are verified. Once source at least suggested that it's only present on >2013 CPUs !