The past 2 major OS releases have taken a couple of weeks.
Android 13 was released August 15th and we had an initial release on the 21st. https://grapheneos.org/releases#2022082100
However there is no set timescale, we were able to do this despite large features like sandboxed Google Play and Storage/Contact Scopes etc is because of our focus on preparing for new releases throughout the whole year.
Regards security features these are added all the time as you'll see from the release cycle above the linked one.
Take how Lineage and by association those based on it handle a major OS release, they took until December to have an initial port ready. That means their Pixel users had months of missed critical security patches.
We're always working on making changes more minimal, less invasive and revising the commits implementing them by splitting them, squashing them, reordering them, etc. We always have everything maintained as a clean patch set on top of the latest stable. Our approach is different.