This reads like an article of 5 years ago... Did time stand still?
The USA Feds seem to be on a similar plan, but it's more like a 10 year lag, and it finally seems to them like this HTTPS thing isn't just a fad.
Funnily enough the official website for the Holy See is also not HTTPS encrypted. (http://www.vatican.va)
So that turns out to be a funny misconfiguration. https://www.vatican.va/content/vatican/en.html works perfectly fine, but https://www.vatican.va redirects to http://www.vatican.va/content/vatican/it.html.
However, it's all fighting the insane bureaucratic system that requires mountains of paperwork to do anything, as well as requirements to contract out jobs to expensive and shitty contractors.