Doing so would require altering the bootrom (which is read-only and thus cannot be altered), or developing new System Software and then giving it a legitimate signature with Nintendo's private keys (which is only slightly less impossible). The bootrom will not load any code that doesn't have a valid signature, and trying to install anything without a valid signature will cause the system to be bricked. The only reason we're able to get into emuNand currently is because of bugs that happen that allow us to break that Chain of Trust.Is it possible to boot directly into emunand rather than default booting into sysnand?


https://gbatemp.net/threads/release-rxtools-roxas75-3ds-toolkit-fw-2-0-9-2.382782/
Check the RXmode section.
The closest I can think of is the MSET downgrade on New 3DS. It allows use of the NVRAM exploit to reach emuNand without requiring Cubic Ninja or Zelda. For Old 3DS, the entire System Version can be downgraded to 4.x to achieve the same effect. Anything installed to sysNand must have a valid signature, so nothing custom can be made and installed at this time.Is there at least a CIA that could be installed into NAND to save a few steps when getting into EmuNAND mode?
