I think they should only be allowed with HSM's, from cheap smartcards to full-on tamper-resistant, if it's anything of significant value unless someone opts out of them. The amount of compromises of PC's, servers, and web apps means I trust an electronic signature way less than a physical one. Need extra security especially on the RNG's, timestamps, keys, and signatures.
Note: It will probably help that the best providers of inexpensive, secure IC's are European and already all over those markets.