I generally agree.
I can understand why people are concerned about the risks to them, but for the most part, this seems to be a bit like GDPR - most of the effort needed went into initial assessments/documenting compliance for things you were already doing.