Doesn't this just mean handing over authentication keys to proprietary systems? I couldn't find a single open source hardware FIDO L2 implementation. Looking at the specification, is it even possible for an open source implementation to gain L3+ certification?
Authenticator certification is inherently incompatible with open source, so you are forced to use a proprietary implementation.