We're actually instead working towards using certs less even for other hardware.
Since all devices are managed, they will get the WPA (2/3) PSK automatically, and a device which isn't managed, they will not be able to access.
The "security increase" one believes certificates offer isn't worth the annoyances with devices not always being online.
--
https://wheretofind.me/@NoSubstitute