I used to work for a company seeking SOC2 compliance. They told me that I had to install corporate malware because of the compliance. I didn't want to install it on my personal computer, which I had been using for work. They sent me a company computer. I installed the corporate malware on that one. I set the company computer aside and continued working on my personal computer. No SOC2 compliance was harmed in the process.
The company computer typically comes with some data protection agreement, where you agree to only access confidential data via the company computer, or at least to never copy confidential company data to personal devices.
On the one side you are liable because you are accessing company data on your personal computer. On the other you are liable because the company is forcing you to use insecure devices to access company data because of compliance. I think we need to check the contracts to see which liability to choose that will give you the least amount of headache.
I know, I was being coy, but if I'm being honest using company devices makes me really anxious, it's always in the back of my head that someone is going to abuse that outdated and opaque VPN stack from Fortinet or that Kaspersky Daemon I needed to install using a script some guy from security sent me with a Google Docs link over DM, and I'll have a really hard time explaining there was no mishandling of data from my part