Postquantum (PQ) security is a mandate for organizations anticipating Q-day, the day when quantum computers can break asymmetric cryptography and algorithms. In this document we review the state of quantum security, current PQ encryption standards, and critical use cases of PQ security and offer security and risk (S&R) professionals actionable guidance for exploring PQ security and crypto infrastructure migration.