I do, in fact, put stock in quality certifications. Most certifications are not worth the toilet paper they are written on; anything that gives a system as insecure as Windows top scores is obviously useless. In contrast, the best that Windows can certify against with respect to the Common Criteria is that it can verify that it is easily hacked by minimally skilled attackers which has been proven out in practice as true. That is a good sign of a security certification with standards, though by no means exhaustive.
You will find that all the certifications you are aware of, which has led you to the idea that all certifications are worthless, fall into this bad category since the commercial IT world is hopelessly incompetent with respect to security and their certifications are the corrupt supporting the corrupt. The standards and prescriptions they suggest are worthless as you state because they have not built anything great, have never seen a great system, and have no intention of creating acceptance criteria that their own incompetently designed systems would fail. Frankly, the number of security standards of any value is basically 0.
This does not mean that certifications created by entities that have never built the system they are trying to certify are useless. It is actually quite easy to create excellent acceptance criteria as long as you stray far enough away from prescriptive standards and accept based on the outcomes instead of mechanism. For instance, I am not a mechanical engineer, but I can design the acceptance criteria for a bridge as requiring 3x the maximum weight of fully loaded vehicles laid across the length of the bridge. I do not need to know how that is achieved, just that you must do so before I accept the bridge. Assuming such a standard is desirable (I am not a mechanical engineer so I do not know how bridge load specifications are actually done or what they must achieve), I created a fairly good standard with a acceptance test despite having no knowledge of how the bridge must be built. In fact, I can do this even if such a bridge can not be built with existing technology. In that case we have deemed that a adequate bridge with the desired safety properties is just plain impossible and should not be built.
In the case of the Common Criteria SKPP standard, one of the acceptance tests was that the NSA red-team must fail to find any deficiencies. Yes, the literal standard requires that the NSA be unable to hack it and it is verified by the NSA having a team attempt to hack it with full access to the source code, specifications, and proofs of correctness. Now for anybody whose gut instinct is that they will just pretend to fail (which is totally the right gut instinct to have), the NSA did the verification work for the only certified system, INTEGRITY-178B, at the behest of the DoD to verify that the core OS of the F-22 and the F-35, the top-line fighter jets of the US military, can not be hacked and either disabled or turned against the US by enemy countries. This is also the same system used in the flight and weapons control of the B-1 and B-2 intercontinental nuclear bombers and in various other NSA and DoD systems. So, pretending to fail is just shooting themselves, the US Air Force, and part of the US nuclear arsenal in the foot.
So yeah, go find me one of these uncertified systems that has achieved a "major advance in security" that the NSA can not hack and then we can start talking about whether there might be some good lessons to be learned. Until then we should probably look to the systems that can actually stop the prevailing threats in practice which the commercial IT sector thinks is literally impossible (that being protecting against nation-state attackers such as the NSA).