Some customers fear that their users export their smartphone certificates and install them unto their own devices to get full access to the network. Solution today is to implement non-exportable certificates, so no 802.1X for smartphones (or similar).
It would be easier, if it was possible to match the MAC and a certificate attribute for certain device types (of the customers choosing). Especially if there was an alarm/trap/etc, when this match fails.