Says who? Besides, those certificates are not fool-proof, there have been stories recently about an improperly signed driver wrecking havoc on Windows machines.Said “malware” would have to have a signed security certificate to run provided Apple allows apps to be sideloaded similarly to the default settings on macOS (App Store & Trusted Developers).
If the user downloads Office from Microsoft’s website, it won’t be an issue.
On top of the scenario I outlined, none of the measures you mentioned are fool-proof. If you want to side load, go to Android. Leave the one ecosystem that doesn't have that vulnerability alone