Ironically the shortening of cert lengths has pushed me to automated systems and away from the traditional paid trust providers.
I used to roll a 1-year cert for my CDN, and manually buy renewals and go through the process of signing and uploading the new ones, it wasn't particularly onerous, but then they moved to I think either 3 or 6 months max signing, which was the point where I just automated it with Let's Encrypt.
I'm in general not a fan of how we do root of trust on the web, I much prefer had DANE caught on, where I can pin a cert at the DNS level that is secured with DNSSEC and is trusted through IANA and the root zone.
There can be theoretical audit or blame issues , since you're not "paying" then how does the company pass the buck (SLA contracts) if something fucks up with LE.