I tried reading up a bit. It seems that SAFE_FIRM is what we're really talking about, and it truly is separate from NATIVE_FIRM.
In the event that 3DS is bricked by instances other than NATIVE_FIRM itself, I doubt fixing NATIVE_FIRM will unbrick the system, but at this point I don't think we have any idea what's currently on that 3DS/how it was bricked/what version it was on before downgrading.
If patching NATIVE_FIRM doesn't work (which might or might not be possible depending on which system files are corrupt), then we'll have to find a way to decrypt and inject a working SAFE_FIRM, which I am not sure is publicly possible. (Injecting it back into the NAND, anyway. I'm sure it's possible to dump from a working 3DS)