Hello,
Take a look on the i.MX 95 SWUpdate enablement through AN13872 and the meta-swupdate-imx Yocto layer.
You can use boot_a/rootfs_a and boot_b/rootfs_b, update the inactive slot, and let U-Boot manage bootslot, bootcount, bootlimit, and a “confirmed-good” flag using redundant persistent environment storage. See AN13872.
Recommended references are AN13872, i.MX Yocto User’s Guide UG10164, meta-imx, meta-swupdate-imx, swupdate-scripts, and the NXP Security Reference Design layer.