A random 6 digit PIN should be considered the minimum for highly secure encryption entirely reliant on the secure element throttling. An attacker unable to bypass the secure element through exploiting it will be unable to bypass this. An attacker able to exploit the secure element will trivially brute force it.
There's scrypt key derivation and then also hardware-bound key derivation in the TEE separate from the secure element throttling, which help make a passphrase stronger.