I thought it's standard practice to MITM at the workplace. How else can you flag exfiltration of sensitive information and stop incoming malware? Add a certificate to browsers on employee's computers, encrypt on proxy after inspection.
Client certs are a different thing entirely, and unrelated to this discussion.
One supposes there might be some banks or B2B sites that might use client certs, but they're such a minority that no one ever heard of them.
Separate from that, client certificates are certainly common, being used for authentication, in the US Federal Government, which issues tens of millions of certificates for this purpose as well as smartcards, since George W. Bush banned passwords with HSPD-12.