HSTS explicitly requires HTTPS. CSP works over both HTTP and HTTPS but is much less useful over HTTP since an on-path attacker could strip it. Cookies with Secure attribute require HTTPS. In practice: security headers assume HTTPS, and any site not on HTTPS in 2026 has a bigger problem than missing security headers.