At Evolving maturity, code security becomes a recognized part of the software delivery lifecycle. SAST integrates into CI pipelines for key repositories, and teams have basic policies about when security checks must pass before merging code. Rules map to established standards like OWASP Top 10, ASVS, or internal secure coding guidelines. Dashboards track vulnerabilities, trends, and mean time to resolution.