I understand that the existing approach results in a worse and more expensive product, but doesn't this approach also allow agencies to focus their efforts on assuring the vendors of their critical infrastructure aren't comprimised by bad actors etc...?
(This isn't my area expertise, so I'm open to the idea of being super wrong)