SOC2 did not force you to use Yubikeys everywhere. How I know that is: no mid-sized organization I've seen SOC2 has ever gotten everyone onto Yubikeys. The median SOC2 auditor hasn't the slightest clue what a Yubikey is (the median SOC2 auditor probably doesn't know the difference between a URL and a hostname).
I understand what you're trying to say: the threat of a SOC2 information gathering process scared your engineering team into taking 2FA seriously. Your team was able to use it as a forcing function. Not to put too fine a point on it: your team is dysfunctional and has a poorly-communicating and unpersuasive security practice.†
That's the problem you needed to fix. There will be things you very seriously need to get rolled out after Yubikeys, and you won't have another $70,000 Big5 audit to wave around to get it done. Meanwhile: people who don't want to endure that audit can get Yubikeys deployed without bothering with the SOC2 part.
An important thing not enough people understand about SOC2 is that the profile of controls that you use (where controls are things like "logs we monitor" and "onboarding processes" and "2FA mechanisms") are self-determined. Auditors have a set of very high-level goals --- much higher level than "services need 2FA SSO --- and you get to pick what controls you map to them. You get to pick what SOC2 makes you deploy, and the auditors ostensibly just keep you honest.
I would be surprised if anything close to 50% of reliably SOC2 -Type-2'd shops had any hardware 2FA at all.
† Almost everyone does!