Absolutely. Self-certification imposes non-negligible and
recurring (recertification) costs to a business.
And when you're industry-agnostic, you have to play whack-a-mole with whatever the chosen industry wants (e.g. HIPAA/HITRUST, FEDRAMP, etc.).
Additionally, indemnification clauses and contractual negotiation of same can be a minefield. "You assume all the risk, for any breach, even if it's our fault, with unlimited liability" is every customer's preference. Small companies have neither the cash reserves to survive an (unlikely) claim nor the clout to push back on bad terms with a big customer. Microsoft et al. do.