Must vet the 3rd party (Trustworthy? Likely to stick around and have timely security updates?). Must do testing with my setup – nginx is not the only thing that's using OpenSSL on the server. I would test the official backport as well, but it would likely have more users and so more issues already taken care of.
And TLS 1.3 is not yet a must-have requirement for me.