When you enabled TPM 2.0 in your BIOS, the PC Health Check app saw that change right away because it scans your components in real time. Windows Update relies on a background task that only checks your system compatibility - so it's not immediate. As far as I can tell, Windows Update might be still looking at old data from before your BIOS change, This also might be causing the error message about missing security fixes.
Since your PC Health Check already shows all green check marks, you do not have to wait for Windows Update to catch up You can bypass the process by using Windows 11 Installation Assistant (https://www.microsoft.com/en-us/software-download/windows11). Download it first and then run it (Windows11InstallationAssistant.exe). It should check your hardware, recognizing the TPM 2.0 setting you enabled earlier today. Once the tool confirms your computer is ready, it will display the software license terms on your screen. Click the accept and install button at the bottom of the window to proceed.
If the above response helps answer your question, remember to "Accept Answer" so that others in the community facing similar issues can easily find the solution. Your contribution is highly appreciated.
hth
Marcin