In practice, this often has the force of law. There are many domains where regulatory bodies arbitrarily require that all contracts conform to one or more of these recommendations to be in compliance or fit for purpose even if they don’t come from the government. Government contracts often have language that product and delivery must conform to a long list of such reference documents.
This is less common in web tech, but in other market sectors compliance with a set of common public guidelines is a cost of doing business and contracts sometimes have long lists of things to conform to. The real issue is that most organizations do just enough to check the box, even if violating the spirit of the requirement, because it turns out that customers just want that conformance for ass-covering and don’t care about rigorous compliance. Rigorous compliance would be expensive, especially if anyone tested it (which virtually never happens).
People will comply with the NIST guidelines because their contracts will require it. The problem is that is not enough.