Surely the effect depends on what you're running, and you can't put a single number on it. There are actually somewhat contradictory results I've seen for HPC-type applications, and no useful analysis of them with low level profiling.
For HPC-type applications you're probably not running code from multiple trust domains on one CPU, in which case you might not need the mitigations at all