I actually wrote this post in preparation for a fight about WAFs with a SOC2 auditor, wish me luck! :)
The specific control says "Boundary protection systems (for example, firewalls, DMZs, IDS/IPS, and EDR systems) are configured, implemented, and monitored to protect external access points", which seems to leave room for doing stuff other than WAFs.