First, it's interesting to see where you draw the line, Colin. As FBSD Security Officer, you also attempted to have the OS disable Hyperthreading, ostensibly to eliminate localhost timing channels. That was a change with user-perceptible impact and minimal security benefit.
Second, seperate PCI auditors out from security audits (though Hacker News readers should be familiar with both). I agree with your sentiment regarding PCI auditors. (PCI, for those who don't know, is the Payment Card Industry standard you get audited against if your application accepts credit cards).
Third: like it or not, when you get dinged on a report like that, you can lose a sale. "Hah-hah!", Colin says. "Screw the auditors!" But Colin, and FreeBSD at large, loses nothing from failing an audit. Want some horror stories about people who do lose?