The world's largest employer (US Government) uses Smartcards (and no passwords).
Quite possibly with SMS as the fallback option in case the soft token is lost.
We have a human in the loop as the fallback. It’s just a different attack vector. Brute force becomes a lot harder, but social engineering becomes easier.
It is still very common for business clients of all sizes, in all industries (even critical infra) to request 2FA via SMS. Good for the company you work for that they dont :)
When they request it, they should receive pushback. SMS 2FA is a bad business decision with potentially severe consequences for customers.
"We recommended you went for X and listed SMS security problems as the reasons - here is the email chain"
You need to cover your ass, but you don't want to actively push back and risk losing the sale.