Different market and different product. Cellebrite customers have the devices in hand, and need to extract data for forensics. NSO customers compromise phones remotely and silently in order to spy on what the owner is doing.
Edit: Oh, they ran up against this just a few weeks ago according to their Wikipedia article. How about that.
Google could potentially sue them under civil CFAA if there was some unauthorized access to Google infrastructure needed to develop the exploits, but that's unlikely to be the case.
Using NSO tools against unwilling targets would violate US law, but that's not what NSO does.
Standby while I look for a source.