I've no absolute expertise in this area, nor have I got access to equipment for accurate measurements
But I've made some boards with HyperRAM @ 100MHz and USB ULPI @ 60MHz with some educated guessing (from various appnotes)..
What I've done is make an estimation of the output impedance of the driver pin. I do this by looking up the datasheet drive strength at a given voltage drop. R=U/I even at exotic frequencies, so say a pin drops 0.6V at 12mA, then its output impedance is 50Ohms.
For STM32F407; it actually specifies them as VSS+0.4V / VDD-0.4V @ 8mA, and VSS+1.3V / VDD-1.3V @ 20mA
So thats 50-65Ohm's (some non-linear behaviour as its a FET).
Then I calculate the characteristic impedance of the PCB traces (often microstrip). This indeed needs the trace width, copper thickness, layer prepreg thickness and permittivity of the core/prepreg material. Lets say a 0.2mm trace gives you a characteristic (single ended) impedance of 70 Ohms.
Then you want the source (the 50Ohm GPIO) to match the PCB transmission line of 70Ohms. With source matching, you add a 20R resistor to match it to the 70Ohm transmission line. At DC it should not matter because its still an "open circuit".. (unless you terminate at the destination but that burns a lot of power)
I'm guessing here many applications would be fine with a 10-40R resistor. You aren't going to run 100+ Ohm traces across many 4L boards (<0.1mm width). Neither will you see many MCUs with a 10Ohm GPIO driver.
Getting a SPI bus to run at high frequency distance is often held back by the MISO line. The SCK master to slave is a single propagation across the board. CS and MOSI travel in the same direction and are sync'ed to the master edges.
MISO on the other hand has to wait for SCK, account for propagation in the slave device, and then propagate back across the PCB and adhere to the setup/hold time of the master MISO pin.
The velocity factor on PCBs is often around 0.6-0.7 times speed of light, so around 2E8 m/s. A bus of 15cm in round trip then adds ~0.8ns each way. That doesn't sound like much, but lets say I have an ENC28J60 (Rated for max SPI 20MHz) and a STM32F407:
SCK period: 50ns
Assuming 50% duty cycle there is 25ns between SCK edges
STM32F4 GPIO rise/fall time at max speed, 30pF load: 4ns
SCK PCB trace: 0.8ns
ENC28J60 SCK rise/fall to SDO valid delay 30pF load: 10ns
MISO PCB trace: 0.8ns
STM32F4 MISO setup time: 6.5ns
Total: 22.1ns
But is your PCB trace actually a 30pF load? When you have 10 I/O pads each adding 5pF then obviously not

.
Seeing a 1ns extra I/O delay gets ever so closer to timing violations..
Also some SPI slave devices are absolutely horrible spec'ed. Whilst typing this post I opened the MCP3911 ADC datasheet which says it supports a 20MHz SPI bus. But they spec'ed the SDO output delay at "max 25ns". So it can do 20MHz if you have a SPI master with a negative setup time. But otherwise the maximum frequency is 1 / 2 / (25ns + everything else), so in this example of ~12ns of the PCB+MCU, the max SPI clock would actually be closer to 13.5MHz.
With 10 slaves, all those stubs can also be a giant issue.
Maybe my calculation is not 100% correct or spot on, but usually it gets me in the ballpark.