Insta-revocation therefore wouldn't really make this notably more painful for them -- they're walking dead at this point either way and there's a good chance they may even close shop before the deadline. All it would do is immediately put a bunch of their innocent customers in immediate pain, for essentially no gain. It might also send the message to, say, Symantec, that they can get away with anything, because no browser would risk revoking 30+% of the web instantly. Establishing a procedure that allows for executing a CA of any size puts everyone on notice.