Thanks! (No, 4096-bit RSA has never been required for A+.)
The grading criteria should be tweaked (it's on the todo list still) not to favour "too much" security because that affects site performance. It's not easy having one grading approach for all sites.