Organizations, I believe, have the ability to discern whether they are going to slip in such slippery slope. I will never recommend to subject Amazon to 8.4. There's no value in it. But maintenance service provider of production equipment, in my view, should be controlled. Provision of maintenance services to an organization's production equipment is not a one-time engagement and, usually, build long-term relationship for both parties. One way of ensuring the contractor deserves that relationship is through monitoring of their performance (an 8.4 control). If an organization need to look for another contractor, they need to subject the prospective contractor to their selection/evaluation process (again another 8.4 control).
You mentioned:
This is your view, but can be viewed differently by others. Others might have experiences of lousy maintenance job that resulted to quality and delivery problems. So, it pays to subject maintenance contractors to controls. Obviously, they will do this because organizations need to "ensure that externally provided processes, products and services do not adversely affect the organization’s ability to consistently deliver conforming products and services to its customers" (8.4.2). Why would an organization deem 8.4 is not applicable to maintenance services provider for production equipment when they are already fulfilling it.
You mentioned:
This is your view, but can be viewed differently by others. Others might have experiences of lousy maintenance job that resulted to quality and delivery problems. So, it pays to subject maintenance contractors to controls. Obviously, they will do this because organizations need to "ensure that externally provided processes, products and services do not adversely affect the organization’s ability to consistently deliver conforming products and services to its customers" (8.4.2). Why would an organization deem 8.4 is not applicable to maintenance services provider for production equipment when they are already fulfilling it.
That said, it doesn't mean that an organization can't vet them in the same manner if they so choose, but don't go trying to force fit it as a requirement.