The CAB forum BR requires that CAs use HSMs, so I call bullshit. Those soft HSMs are used in dev environments. Unless you talk about enterprises internal CA, where the storage of keys is usually not the biggest concern.
https://cabforum.org/wp-content/uploads/CA-Browser-Forum-BR-...
6.2.7 Private key storage on cryptographic module
The CA SHALL protect its Private Key in a system or device that has been validated as meeting at least FIPS 140 level 3 or an appropriate Common Criteria Protection Profile or Security Target, EAL 4 (or higher), which includes requirements to protect the Private Key and other assets against known threats