If they are honest about this, then providing you with a nice laptop would be far cheaper than dealing with multiple-agent issues. Let alone getting into "how do we need to do this, to comply with laws & regulations?" conversations with lawyers. If they are not honest...
Legally I work for a company in the EU which I own.
They are willing to pay for a decent laptop. That is not the issue. The issue is that I feel quite upset about this requirement. My motivation to discuss it here is to get an idea if I am out of touch with current reality (like some old guys some times are) - or if this is a form of cancer it's worth fighting against.
I agree with much of what has been said, security theatre etc etc; but at the highest level, should companies take IT security seriously, absolutely. Is the implementation correct? Probably / certainly not. The real cancer is the total disregard for security and data privacy that has metastasized to the point where a leak containing everything from a company doesnt even register as an incident anymore.
If your contract was with the CIA and they had requirements, you would probably be on board with them. We have all been around the block and seen the state of some peoples computers; even technically gifted people with malware and spyware riddled computers, with the CashFollowerDataScrape Browser Toolbar installed and Password123 securing everything. Do these tools stop this sort of stuff, not really.
Work / Personal device seperation is always the answer, the red flags are the companies that demand compliance, but refuse to provide equipment. If the contract wants you to do something you are free to accept or decline. If the contract wants code written using their style guide it would be a similar cosideration, even if it meant spaces instead of tabs. if the contract wants you to code only using your index fingers only, are comfortable with it taking 10x longer and will pay 10x your normal hourly rate, you are free to accept or decline.
I recognize that you are just making a creative suggestion here, but that is impossible. SOC2 certification is incredibly complex and hard to manage (not to mention, costing tens of thousands of dollars a year). It is difficult to the point of impossibility for one person to achieve.
Not only is is practically impossible, it is also literally impossible for a one-man show to achieve SOC2, because there are control objectives that require separation of duties and verification of one person's work by another. I think the absolute smallest a company could be and achieve a SOC2 would be three people.
One of our clients at $Day_Job is a laboratory - subject to arbitrary (from their viewpoint) rules for certifications, etc. If the certifying agency says "round this value to 3 decimal places" - it doesn't much matter if $Client hates that idea, or if it is (science-wise) wrong. One can argue with them...if done wisely, that occasionally works.
I'd be tempted to look into the SOC 2 stuff. Especially real-world accounts of how the AICPA interprets and applies the rules. There can be wide gulfs between what the written rules (plus "reasonable professional" logic) say, and the standards which the auditors (with their own mindsets and habits) actually apply.
Hmm...does the US startup you're working for have someone really familiar with SOC 2 certification working for them? Or just some energetic manager-type, who's zealously trying to apply his own interpretation of the written rules?
Best wishes.
Not that I'm aware of.
I don't know the details. My interpretation is that some manager hired some company to help them with this certification that the sales people says that they need.