With federated services, the problem is more difficult. For one, if a centralized service can't clamp down on cp to Apple's standards (as unrealistic and inconsistently applied as they may be), what chance does a decentralized system have, where individual instance operators have to collaborate to keep their own instances clean and not federate with poorly-janitored instances?
It also increases the barrier to running an instance. Dealing with cp is not fun and having to manage that on top of usual mod/maintenance tasks has the potential to escalate running an instance from reasonable hobby to hellish timesink. If running instances is too hard, your federated system is probably DOA.
Of course, if a federated system were created with strategies for dealing with cp and other cannot-host content in mind, that would be a genuine improvement over existing designs that'd be worthy of discussion.
---
That said, if they aren't actually hosting any of the content they probably won't run into the same problem Tumblr did. They will be able to pin the blame on third party servers. The app store still has a Tor client for example, because the Tor project doesn't host any user editable content. It's when someone loads a CP image from movim.eu that they get in trouble.