The observatory rating does not only include the TLS setup, but as well HTTP header settings, CSP [1], etc. [1] CSP