@stefano That happens when auditors are mostly idiots with little technical knowledge but with a lot of power. I had to deal with those people many times, people who don't know how to open a CLI and run a fucking ping are telling you what you have to do. When I deal with cyber security auditors with strong technical knowledge things are different but in my experience most of them just care about compliance.
@jrballesteros05 I agree. They know that Debian with that version is compliant, and that's all. They don't probably know how ssh works at all.