I think "You Shouldn't Roll Your Own Crypto" is really three separate pieces of advice, each of which deserves justifying independently.
Roughly:
- You shouldn't try to invent your own cryptographic primitives.
- You shouldn't try to design your own equivalent to (say) SSL.
- You shouldn't try to implement something like SSL, or parse ASN.1, yourself.
I don't think many people are likely to fall foul of the first.
It seems to me the second is where the real devils lurk: dealing with padding and cipher modes and all that kind of stuff.
But it's not at all clear to me that the third has been historically justified.
I think if someone in the early 2000s had thought "I don't like the look of OpenSSL and I don't think C is a good choice of language. I'm going to write my own implementation of the parts I need in (say) Ada" they might well not have regretted that choice.