HTTPS is used almost everywhere. And it's not like a government decrees something and it's done. Laws involve multiple stakeholders, and there are multiple governments which converge on the same decision.
It is correct to state that security best practices are not decided by one entity but rather figured out organically and on a non centralized basis.