There's a patch that adds SHA256 algorithms to XP, which is the biggest obstacle.
Most websites do not work with TLS v1.2 anymore.
Are you sure you don't mean 1.1 or 1.0? In my experience 1.2 is still supported by the vast majority of sites.
Also related: TLS 1.3 on Windows 3.11(!) https://news.ycombinator.com/item?id=36486512
I've been thinking about the idea of easily replaceable, minimal-dependency crypto modules along with an interface that shims them into existing OS implementations. In the meantime, my MITM proxy that I force everything on my network through will take care of HTTPS and upgrading to TLS 1.2/1.3.