The first phase will probably be omitting the CN when none of the SANs are short enough to fit in the size limit, which is a strict improvement over failing to issue certs, but is still potentially troublesome if those certs don't universally work. It definitely seems like a change that's perilous, as this thread shows.
I think it probably makes sense to have a flag / pair of flags to control whether certbot includes a CN, but that's firmly into making dangerous compatibility hazards for all but the most sophisticated users with a deep understanding of the x509 ecosystem.