See also: https://https.cio.gov/
I suspect they haven't caught up with the mandate.
I suspect they haven't caught up with the mandate.
Though the GSA's HTTPS adoption dashboard does include legislative branch domains, including senate.gov:
Would it be worth trying to update pulse.cio.gov to detect cases like this? That's non-trivial to do in a reliable automated fashion, but seems like it might be worth the effort?
In the case of the Senate, their current configuration prevents them from using HSTS or enforcing HTTPS, so the other columns will still show as lacking.