It's a performative announcement - most American and Israeli cybersecurity vendors either don't sell in China or white label a Chinese product for the Chinese market.
I know 2 companies in that list that have done that very thing because otherwise it would have put their FedRAMP and CMMC pipelines at risk.
Even with white labeled products so they stay legally compliant, is it really justifiable to increase the risk? They're having people flying in and out for "sales meetings", shared office spaces, devices, maybe even staff overlap.
I understand it's a good way to make money but it comes with some tail risk.
I worked at a place that faced exactly that.
I initially was in the Huawei client engagement where they wanted copies of all of our source code. We said “no, nobody gets that”. They just keep asking over and over.