The part that GitHub implemented (uploading keys to the site, displaying verified signed commits in the UI) looks like it is both.
Configuring a project to only accept signed commits in various ways looks to be EE only.