My customers were already using OL8 for their "not a mission critical" systems. If they go OL8 all the way, they can choose to buy support for their critical systems and still have "bug for bug" compatibility that they had previously, just not via RHEL + clone.
Besides: Oracle actually bothers to get certified hardening benchmarks through CIS and DISA.