Why are you storing certificates in an HSM?

Keys you store in an HSM. Certificates are supposed to be public. That's the whole point of certificates.

And the proposal suggests using keys stored in an HSM. They're not reinventing that wheel; they're suggesting you use it.

