My bank(s) used password+client certificate, but now they have switched to proprietary mobile OTP apps. (also due to some directives). For some stuff, SMS codes are used.
Also, I've seen CA's simply deliver the .P12/.PFX file now instead of securely generating the key on the client and then signing it.