You can use wildcard certificates to avoid advertising the list of your subdomains.
Other than the fact that CT will be mandatory (at least for Chrome), publishing all certificates to CT increase the accountability of the CA.
If you don't care about the validity of your certificate for devices you don't control, you can set-up a private hierarchy with your own root that you install on your devices.