I think it is worth noting that:
a) Pentesting 3rd party vendors is uncommon. This is something that the majority of companies rely on a SOC2 for.
b) Pentesting is not what the article is talking about, it's talking about bug bounties/ Vulnerability Reporting Programs. It is equally, if not more, uncommon for a company to bring a vendor into its VRP.
And yes, companies care greatly about traffic being routed through China.