4.2 -2 does not oversell IPsec, it simply states the real situation.
I'm not going to hold your document based on the -03 text, but
I would still suggest the following edit:
While IPsec might be available in IPv4
implementations and works the same way, deployment in NAT
environments either breaks the protocol or requires complex
helper services with limited functionality or efficiency.
=>
While IPsec is commonly available in IPv4 implementations
and can support NATs, NAT support has limitations and
does not work in all situations. In addition, the use of IPsec
with NATs consumes extra bandwidth for UDP encapsulation
and keepalive overhead.