Zero of 773 FIPS 140-3 certificates are validated at Level 4
808bits.comAll the really high end stuff is in financial data centers anyway, surrounded by TV cameras 24/7. Tamper reactance in the HSM itself is cool and everything but the surrounding security handles a lot of what the HSM is made to do.
Side-channel ignorance: none of the SW solutions are properly zeroing the data. Side-channels can still read them. SW vendors refuse to do that because of performance. Clearing the caches is too expensive.
That's not surprising. FIPS 140 is primary a signalling mechanism for how desperate you are to sell to the USG and USG-affiliated organisations, not a security indicator. Only a company prepared to set fire to $100k or more gets to play.
And if you're a hardware vendor, you have to set fire to $300-400k because to play there you need to be level 3. Levels 2 and 4 may as well not exist because you need 1 for software and 3 for hardware, why would any company set fire to more money than they need to to get their ticket to ride? It's not like we're talking about AI here.