Surely it's more that you should obtain certified binaries of openssl from a third party?
However, if I use SOUP, I'm responsible for bugs. How would I debug with no source?
I don't work in the field, but just because you're using a certified binary doesn't mean no source can ever be associated with it for debugging.
Continuing the example of a certified binary of openssl from a third party (say version 1.1.0h), I'd expect you to be able to debug the certified binary using a version-matched source tarball from the openssl website [1].