The two words describe different legal machinery. In an attestation, management asserts something — “our controls were suitably designed and operated effectively” — and a CPA firm, working under AICPA attestation standards, examines the evidence and opines on whether that management assertion is fairly stated. SOC 2 works this way, which is why the deliverable is a long report rather than a badge. A certification, by contrast, is issued by an accredited certification body against a published standard: ISO 27001 ends in an actual certificate with a scope statement and an expiry date.
“SOC 2 certified” is, strictly speaking, a phrase that describes nothing — there is no such certificate, and vendors who use it are at best imprecise. What exists is a report with an opinion inside, and the opinion is the payload: an unqualified opinion means the auditor found the assertion fairly stated, while a qualified one flags criteria the evidence could not support. Security reviewers therefore ask for the report itself, read the opinion letter first, and check the period it covers — three things a logo on a trust page cannot convey.
Only a licensed CPA firm can sign a SOC 2 attestation, and the firm must be independent of the company it examines — the consultants who built your program cannot also opine on it. That independence rule is what gives the document its weight: the signature belongs to a regulated professional staking a license on the opinion, not a vendor grading its own marketing.