It's important to set up security quality criteria for each release stage, such as threat modeling, design, coding, testing, and deployment. The objective of the release gate is to improve the quality of security releases in each stage. When you start defining release gates, it's suggested to start with a few major or high-priority security issues, since a long checklist will result not only in overhead but also in resistance from the development or QA teams.
For the introduction of security release gates, allow the team to learn, to become familiar with the security practices, and also to make mistakes. Try to be a coach to support and help the team to meet a higher standard of security quality instead of acting like the police and inspecting deliverables.