A funding model where you pay the company to hire auditors, implementors and researchers directly could be argued to be the better funding model.
I'm not saying it is better, since open-source has proven itself many times, but it has also failed miserably many times because of lack of funding or interest.
Open source, especially open-source that is produced and maintained by companies with different agendas (for instance google) as opposed to a foundation is prone to having that agenda color the way it works. Commercial product's agenda usually align better with it's customers then some random company. Some would say that in a security product it is vitally important that the creators' motivations are aligned with the users'.
So there's incentive to save money and wait for someone else to do audits.
But in practice almost all cryptography is deployed via open source software. Large tech companies like Google and Apple can develop reliable and safe closed source cryptography. But most companies don't because that's expensive and usually unnecessary.
I knew a guy who worked at a medium size company (few thousand people). They tried to drag him back into an old product he worked on years ago to help because.... They still had one customer paying support on it, but someone realized they couldn't find the source code. This guy couldn't help and fortunately the customer hadn't asked for any changes to the software in several years. So no, paying for software doesn't necessarily mean it's supported in any meaningful way.
Note that I used the word "can", not the word (which you used) "necessarily."
My estimation is that typical support consists of listening to customer complaints and suggestions and prioritizing development around that and available resources. I doubt many companies do extensive analysis or hire consultants to do security audits or much of anything that isn't directly customer driven.
The company I mentioned previously actually does extensive design, testing and regression testing on most of their products but the smaller side project just didn't get that attention. YMMV even within one company.
So in a situation where your choice in crypto is open vs closed & legal/security funded you might pick the closed solution.
OSS <= CSS does not imply CSS <= OSS...
> why on earth would you ever choose closed source components
There are often no open source alternatives to closed source things that are meaningfully equivalent. For example, the iPhone is a secure and closed source phone. There is no open source equivalent to that package. Android devices have critical closed source components with almost no exception, but also are not equivalent to an iphone in many meaningful ways.
I think a better take-away is the nuanced "evaluate things on a case-by-case basis, don't let a security system having closed source components needlessly bias you"