Earlier quoted context omitted.
The signing capacity of the HSM (or possibly HSMs, I'm not sure) holding the intermediate certificate is limited. These devices are quite expensive, so it's not that easy to scale this resource. In comparison to that, a pending authorization is just a row in some table, so that doesn't take up too many resources. For use-cases like Plex (or generally things that require a large number of subdomains), there's now a fo…
Are you able to disclose the speed and/or cost? I know people working on cheaper HSM's. They might find the numbers useful as an assessment of how practical their own are.
Based on some public posts, I believe Let's Encrypt is using Gemalto HSMs, though I'm not sure which model or how many of them.