I'm not sure by the term "very strong compliancy certification", at present there is only one PABP certification, either certified or not certified.
As to why, marketing benefit and the writing on the wall is that eventually, VISA and MasterCard, through it's indirect lines via member banks, processors, gateways and eventually the merchants will require all applications to be PABP compliant. Right now it is more of a "strongly suggested" program and the degree of enforcement is, for the most part, up to the individual merchant bank.
As to how this got through a certification audit, auditing standards are still being ironed out. Right now, different auditors will catch or not catch different issues. I can tell you for a fact that either of the two auditing companies that we use would have caught this particular issue. We were just a participant in a security round table with VISA & MasterCard and standardizing the audits was a topic and it is being addressed. I can almost guarantee you that when a recertification takes place (they happen annually), this issue will be caught and at a minimum, vendors will need to provide detailed documentation and/or utilities to sanitize preexisting data.