As a White House memorandum, that mandate only applies to the executive branch.
Though the GSA's HTTPS adoption dashboard does include legislative branch domains, including senate.gov:
Though the GSA's HTTPS adoption dashboard does include legislative branch domains, including senate.gov:
Would it be worth trying to update pulse.cio.gov to detect cases like this? That's non-trivial to do in a reliable automated fashion, but seems like it might be worth the effort?
In the case of the Senate, their current configuration prevents them from using HSTS or enforcing HTTPS, so the other columns will still show as lacking.