Compliance
is useful, just not for security.
* You get a cool industry certification that you can put on your website to justify the vague "we take your security seriously" platitudes we spew.
* It lets you stop putting money and effort into security once you've renewed your certs this year.
* You don't need to hire a dedicated security person, any sysadmin can check boxes.
* You can say you followed industry best practices and "did all you could" when you get breached.
It's the answer to "how do we not care about security?" across an entire industry that stands to make billions from said lack of care. In a depressing way, the company with useless performative security certs will fare better after a breach then the one without them but that actually tried.
My less cynical take about this is that if you need to actually care about security because you'll be up against sophisticated targeted attacks then you probably already know that. For everyone else there's checkboxes to stop companies from getting owned by drive-by attacks.