On 23 January 2023 Oracle replaced its Java SE Subscription with the Java SE Universal Subscription. The change looked like a repackaging. It was a change of tax base.
The new subscription dropped per processor and per named user pricing for a single metric: the total employee count of the licensed entity. The price scales with the payroll, not with the estate.
A 10,000 employee company that previously paid for a few hundred Java SE seats now faces a list cost around one million dollars a year, even where Java use sits in two teams. This page traces how that happened, change by change, and what it means for the estate you are holding today.
Pair it with our Oracle Java licensing brief, the Oracle services overview, and the Oracle Knowledge Hub.
Key takeaways
- The metric changed on 23 January 2023. Oracle replaced per processor and per Named User Plus pricing with the per employee Java SE Universal Subscription.
- Employee means everyone. Full time, part time, temporary, plus the staff of agents, contractors, outsourcers and consultants who support your internal business operations.
- It was the second change, not the first. The paywall arrived in April 2019 at Oracle JDK 8u211. Estates that missed that one were already exposed before 2023.
- Old contracts survive but cannot grow. Pre 2023 perpetual and Named User Plus agreements remain valid for what they cover and cannot be expanded.
- The free window closes on a schedule. Oracle JDK 17 left the No Fee Terms in October 2024. Oracle JDK 21 leaves them in September 2026. A patch pipeline can convert an estate with no purchase order.
- Audit activity rose. Download log evidence against the corporate domain is the most common trigger, and it usually predates the 2023 change by years.
- Rate discounts run 22 to 41 percent. Reductions past that come from scope, term and a credible exit, not from arguing about the rate.
- Three estates came out of 2023. Still on a legacy contract, converted to the subscription, or never licensed at all. The first move is different for each.
This is the same framework our advisors apply when we sit on the customer side of a Java conversation, whether that is an audit defence, a renewal, or a fresh quote. We are independent, we do not partner with Oracle, and we do not resell Oracle.
What exactly changed on 23 January 2023?
The billing metric, and only the billing metric. Before that date Oracle priced Java SE three ways, and all three tracked the deployment.
Java SE Desktop Subscription was priced per named user. Java SE Subscription was priced per processor for servers and per named user for desktops. A customer with 20 Java servers and 200 desktop developers paid for what it used.
The Universal Subscription replaced both. The single metric is now Employees, defined as all full time, part time and temporary employees of the licensed entity, plus the equivalent staff of its agents, contractors, outsourcers and consultants who support its internal business operations.
The metric counts people, not Java deployments. Customers do not get to license the subset of employees who use Java. The licensed entity buys Java for its entire population.
Why Oracle changed the model
The economics drove it. Java SE under the previous metrics was a modest line for Oracle relative to how much Java the enterprise actually runs, and the employee metric reset that in a single move.
It converts Java SE from a usage based fee into a population based charge. It captures a customer running one Java workload as if it ran a thousand, and it compounds with the customer's own growth.
Oracle framed it publicly as simplification: one metric, one number, no counting processors. That framing is accurate as far as it goes. The simplification moved the counting from an estate you control onto a payroll that grows without your involvement.
How did the estate get here? The full timeline
In seven steps between 2017 and 2026, of which the 2023 change is only the loudest. Most estates we open were already exposed by a change made four years earlier.
Oracle Java licensing, change by change
| When | What Oracle did | What it did to buyers |
|---|---|---|
| September 2017 | Java 9 ships and Oracle moves to a six month release cadence with designated long term support releases | Version currency becomes a rolling obligation rather than a five year event |
| September 2018 | Java 11 ships as the first long term support release under the new cadence | Oracle JDK 11 carries the Oracle Technology Network licence from day one. There is no free commercial route to it |
| January 2019 | Oracle JDK 8u202 published as the last free public update for commercial use | The dividing line most estates still turn on. Anything later is chargeable |
| April 2019 | Oracle JDK 8u211 and later ship under the Oracle Technology Network licence | The paywall arrives. Auto updated desktops cross it without anyone deciding to |
| September 2021 | Java 17 ships under the No Fee Terms and Conditions | Free in production again, but on a clock rather than in perpetuity |
| 23 January 2023 | The Java SE Universal Subscription replaces both legacy metrics | Price detaches from deployment entirely and attaches to head count |
| October 2024 | Oracle JDK 17 updates from 17.0.13 revert to the Oracle Technology Network licence | The first estates convert themselves through routine patching |
| September 2026 | Oracle JDK 21 leaves the No Fee Terms, one year after JDK 25 shipped | Scheduled. The July 2026 update is the last free one on that line |
Dates as published by Oracle to May 2025. The September 2026 row follows Oracle's stated pattern of one year after the following long term support release. Confirm the current position on the Oracle JDK licence FAQ before acting on it.
What Oracle said at the time, and what it meant
Three messages went out in 2023, and all three were literally true. What mattered was the sentence that followed each one, which mostly did not get said.
- "It is simpler." True. One metric, no processor counting, no core factor table. What follows: the number is now set by your HR system and your contractor spend, neither of which reports to the person signing the order.
- "It covers everything." True. Every desktop, server, virtual machine and container in the entity, with no incremental fee. What follows: coverage you cannot use is not value, and the fee is identical whether you run four installs or four thousand.
- "Existing agreements are unaffected." True. Pre 2023 contracts remained valid. What follows: they cannot be expanded, so any growth, any new workload and any acquisition pushes you onto the new metric.
The fourth point was not in the messaging at all. Each long term support release carries free production terms for a defined window, and when that window closes a routine patch moves the estate onto paid terms.
That is how a compliant estate becomes a chargeable one without a purchase order, a change request, or a conversation. It happened at scale in October 2024 and it is scheduled to happen again in September 2026.
Who does the employee metric actually count?
Everyone on the payroll, plus third party staff who support your internal operations. The order document defines Employee as all full time and part time employees of Customer and Customer's affiliates, plus temporary employees, contractors, outsourcers and consultants who support the customer's internal business operations.
The definition is broad. Oracle's opening interpretation of it is broader still, and the gap between the two is the single most valuable thing a buyer can close.
Affiliates and acquisitions
The reference to affiliates draws every entity in the corporate group into the count. A holding company with twelve operating subsidiaries cannot license Java for one and exclude eleven, because the order document follows control.
This matters most after acquisitions. A subscription signed in 2023 for 12,000 employees becomes a subscription priced for 25,000 once a deal closes, even where the acquired company never ran a line of Java.
Contractors and consultants
The contractor inclusion is the least intuitive part of the metric and the most argued. The clause reaches staff who support customer's internal business operations, which is a purpose test rather than an access test.
Oracle's audit position reads it broadly. The defensible reading is narrower: a consulting team building a product you sell to your own customers is not supporting your internal business operations. That reading held in roughly four out of five of the engagements in our file.
How to count, and when
Customers count at signing and recount at every annual true up. The common shortcut is to use the head count in the most recent audited annual report, because it is easy to evidence and hard to dispute.
It is also frequently wrong in both directions. It carries entities you have since divested and it usually omits the contractor population entirely.
Build the number from your own systems on a named date instead, and negotiate the counting methodology into the order document. Those clauses are the highest leverage terms in the whole agreement, and they are covered in the contract clauses section below.
What did the change do to the bill?
It multiplied it by somewhere between three and ninety nine times, depending on how much of your payroll the old metric happened to touch. Oracle's list price for the Universal Subscription is tiered by employee count.
Universal Subscription list price by employee band
| Employee count | List per employee per month | Annual list across the band |
|---|---|---|
| 1 to 999 | $15.00 | up to $179,820 |
| 1,000 to 2,999 | $12.00 | $144,000 to $431,856 |
| 3,000 to 9,999 | $10.50 | $378,000 to $1,259,874 |
| 10,000 to 19,999 | $8.25 | $990,000 to $1,979,901 |
| 20,000 to 29,999 | $6.75 | $1,620,000 to $2,429,919 |
| 30,000 to 39,999 | $5.70 | $2,052,000 to $2,735,932 |
| 40,000 to 49,999 | $5.25 | $2,520,000 to $3,149,937 |
| 50,000 and above | Not published | Quoted case by case |
List, before discount, from the Oracle Java SE Universal Subscription price list. The band rate applies to the whole count, not to the increment above each threshold. Full working, band edges and the discount curve sit on the Oracle Java cost page.
List is rarely the buying price. On rate alone we have seen 22 to 41 percent conceded between the opening quote and a signed three year order, and the spread tracked the band the customer sat in more than how hard the customer pushed.
Reductions past that range do not come from arguing about the rate. They come from scope, term and a credible exit, which is a different negotiation with different evidence behind it.
For a 10,000 employee company the list cost is $990,000 a year. The same customer's previous Java SE Subscription, priced on the actual deployment, may have been forty thousand. For most enterprises this was a five to twenty times step, and for a few it was worse.
What actually counts as Oracle Java?
Only Oracle JDK and Oracle JRE binaries distributed by Oracle. Your compliance position depends on which distribution is running, not on the fact that Java is running.
Customers running alternative OpenJDK builds are outside the subscription entirely. Customers running Oracle binaries downloaded from Oracle, even unintentionally, are inside it.
Java distributions and their licence status
- Oracle JDK 8, commercial use after April 2019. Requires a paid subscription from 8u211 onward. 8u202 and earlier remain free.
- Oracle JDK 11 through 16. Oracle Technology Network terms. A subscription is required for commercial use.
- Oracle JDK 17 and later under the No Fee Terms and Conditions. Free in production until one year after the following long term support release, then chargeable on later updates.
- Eclipse Temurin from Adoptium. Free, open source, built from the same OpenJDK source as Oracle JDK. The most common replacement we see.
- Microsoft Build of OpenJDK. Free, backed by Microsoft, common in Azure estates.
- Amazon Corretto. Free, backed by AWS, common in Amazon estates.
- Azul Zulu. Free at the community tier with commercial support available. Widely used in financial services.
- Red Hat build of OpenJDK. Free with a Red Hat subscription. Used in Red Hat estates.
The compliance question is which binary is running. The audit question is whether you can prove it. The remediation question is how to replace the Oracle binaries without service disruption. All three are engineering work rather than contract argument.
Which of the three post 2023 estates are you in?
One of three, and the right first move is different for each. Almost every organisation we open lands cleanly in one of them, and the most expensive mistake is applying the wrong playbook.
Three estates came out of January 2023
| State | How you can tell | The biggest risk | First move |
|---|---|---|---|
| Still on a legacy agreement | A live Java SE Subscription or a perpetual Java SE Advanced entitlement priced per processor or per named user | Losing it by accident through a consolidation, a lapse, or an innocent looking amendment | Read the contract, evidence what it covers, and refuse any expansion onto the new metric |
| Converted to the Universal Subscription | An order document priced per employee, usually signed in 2023 or 2024 | The count and the uplift both ratchet at renewal while the estate stays the same size | Work the renewal as the only lever: count, band, price hold, growth cap, and a funded exit plan |
| Never licensed at all | Oracle builds running with no Java agreement of any kind, usually discovered by a sweep | A claim priced backwards to the first download date, opened by a letter you did not expect | Sweep, split free builds from chargeable ones, and remediate before any contact with Oracle |
The third state is the most common and the most fixable. An estate with no agreement has no contractual clock running against it, which means the sequence is entirely yours to control until the day you answer a letter.
What does the Oracle Java audit motion look like now?
Industrialised, and usually triggered by something that happened years ago. Four triggers recur in the engagements in our file.
- Download evidence. Oracle holds a record of downloads from its own portal against your corporate domain. One accepted click through licence is enough to start.
- Installed base without a subscription. Customers who appear as Java users in Oracle's own records but not as paying subscribers.
- An adjacent renewal. A Database, Applications or unlimited agreement renewal in the next twelve to eighteen months puts you in the queue.
- Regulated sectors. Where software compliance is an internal control, a finding carries weight beyond its price.
The formal route follows the standard Oracle audit clause. Oracle issues a notice with 45 days of written warning before the audit begins, then proposes a measurement methodology and asks for data from each host running an Oracle binary.
The output is a list of installations, your claimed employee count, and a finding. The finding is rarely the final number. It is the opening position in a settlement negotiation.
See our Oracle audit response playbook and the Oracle license audit defense playbook for the full framework.
Which four defences actually work?
Four, and none of them is sufficient alone. Used together they have cut the finding by 60 to 90 percent across the engagements in our file.
- Distribution defence. Demonstrate which hosts run non Oracle builds. Document it with binary evidence, package manager logs and a software bill of materials.
- Scope defence. Negotiate the population in scope. The affiliate definition, the contractor definition and the counting methodology are all negotiable in a settlement.
- Migration defence. Present a credible plan. It must name the target distribution, the host count, the method and the completion date. Oracle settles more readily against a funded exit.
- Time defence. Audits accelerate when the customer is in a hurry. Treating it as a routine compliance exercise, with the patience to argue on the merits, consistently settles lower.
The binary fingerprint defence
The strongest form of the distribution defence is binary evidence. Take a hash of every Java binary in the estate and read the release file beside it, because Oracle builds and non Oracle builds are distinguishable at that level.
Present the inventory as proof of what is running. It moves the conversation from a compliance argument to an evidence argument, and auditors are far more practised at the first than the second.
Across the 35 to 45 Oracle Java engagements in our 2024 and 2025 file, this was the single defence that shortened the process most reliably.
Is OpenJDK a credible alternative in 2026?
Yes, for the large majority of workloads, and that credibility is itself the negotiating asset. The Universal Subscription was designed in part to make partial migration pointless, since moving 90 percent of the estate saves nothing at all.
Your leverage is therefore not cost based, it is risk based. A customer who can credibly complete a migration inside the renewal window forces Oracle to discount or to lose the line entirely. A customer who cannot accepts whatever is quoted.
The migration path
Moving from Oracle JDK to an OpenJDK distribution is straightforward for most workloads, because they are built from the same source. Compatibility for standard server and desktop workloads is high, and the work is engineering rather than architecture.
The exceptions are narrow. Workloads that depend on features specific to an Oracle build, or on monitoring agents tied to one, may need attention before the switch.
Which OpenJDK to choose
Choose on your existing platform alliances rather than on the bytecode. AWS estates standardise on Corretto, Azure estates on the Microsoft build, Red Hat estates on the Red Hat build.
Customers without a strong alliance, or running across clouds, usually standardise on Eclipse Temurin. Financial services customers who need contractual production support often take Azul Zulu and pay Azul for it.
Whichever you pick, standardise on one. Estates that permit three distributions spend the saving on auditing themselves.
Running OpenJDK at production scale
The runtime is open source, but production support is a commercial decision. You can self support, buy support from Azul, or use the support you already hold with Red Hat, Microsoft or AWS.
The cost of any of these is typically 10 to 30 percent of the Oracle Java SE Universal Subscription for the same population. The economic case holds even after the migration cost is fully loaded.
Which contract clauses should you negotiate?
Six, and most customers get four or five of them simply by asking. Customers who must keep Oracle Java for some workloads should negotiate the order document rather than the discount.
| Clause | Standard Oracle | Customer protective |
|---|---|---|
| Employee definition | All employees plus contractors | Contractor inclusion limited to staff supporting internal operations, with the test written down |
| Affiliate scope | All affiliates included | Named entity list with carve outs and a stated treatment for acquisitions |
| Counting methodology | Oracle determined | A named system of record and a named snapshot date |
| Audit notice | Oracle standard notice period | 60 to 90 days with a documented scope and an agreed toolset |
| Price hold | Annual escalation, uncapped | Multi year fixed rate with a capped escalation |
| Migration carve out | None | A right to reduce scope at renewal on notice |
Every one of these is achievable, and none is achievable without raising it. Customers who raise all six and stay in the conversation typically obtain four or five. Customers who raise none accept Oracle's standard document unchanged.
What does a realistic migration timeline look like?
Nine to fifteen months for a large estate, and the runtime swap is the easy part. The structure below is the timeline we run with clients.
- Month 1 to 2. Inventory and assessment. Read the release and LICENSE files across the estate. Identify every Oracle build, its version, its host, its application owner and its platform dependencies.
- Month 2 to 3. Vendor selection. Choose one target distribution. Run a proof of concept on representative workloads and validate compatibility, performance and operational tooling.
- Month 3 to 6. Pilot migration. Move the non production estate and one production application. Validate the runbook and train the operations team on it.
- Month 6 to 9. Production migration. Move the long tail. Track it on a dashboard the application owners can see, because visibility is what keeps the tail moving.
- Month 9 to 12. Decommission. Remove Oracle binaries from every host, retire the subscription at renewal, and document the new state with dates.
- Month 12 onward. Steady state. Maintain the chosen distribution, write the policy that prohibits Oracle builds, and run a quarterly inventory check.
Customers who plan twelve months and finish in nine to fifteen pay no Oracle Java licence afterwards. The avoided cost is the entire subscription run rate, every year, and the migration cost does not recur.
For a 10,000 employee company that is $990,000 a year at list, or somewhere between $584,000 and $772,000 at the rate discounts we typically see. The return on the migration is fast on any reasonable engineering assumption.
White Paper · Oracle
The Oracle Java Audit Defence Playbook
What the Universal Subscription really costs and how buyers push back. Read it free.
Pattern study: a 22,000 employee manufacturer
A global manufacturer in our 2024 engagement file received a Universal Subscription quote priced at 22,000 employees in the 20,000 to 29,999 band. The annual list came to $1,782,000. Its previous Java SE Subscription, priced on the deployment, had been $86,000.
The defence ran in four steps.
- Binary inventory. We demonstrated that 80 percent of the Oracle installations could move to Eclipse Temurin without a code change.
- Migration plan documented. Named application owners, target dates and a steering committee with a budget behind it.
- Order document negotiated. For the remaining fifth of the estate we secured a six month renewable term and a contractor exclusion that took the in scope population from 22,000 to 14,000.
- Right sized renewal. The residual signed at $260,000, with a contracted right to reduce scope further at the next renewal.
The run rate landed 85 percent below the original quote and the Temurin migration completed in eleven months.
Be careful reading that number across. Most of it came from scope and term, not from rate. The rate concession sat above the 22 to 41 percent we normally see, and it was bought with a funded migration plan Oracle could verify, not with negotiating pressure.
For more audit and negotiation patterns see our case studies library, the Aegean Airlines Java case study, and the Oracle Java audit defense brief.
How should a CFO frame the decision?
As a population charge with a binary alternative, which makes the expected value calculation unusually simple. There are only three numbers in it.
- The Oracle line. $63 to $180 per employee per year at list, or roughly $50 to $150 after the rate discounts we typically see.
- The alternative. Between zero and $25 per employee per year, depending on whether you buy commercial support and from whom.
- The migration. A one time engineering project, typically $250,000 to $1.5 million for a mid sized enterprise depending on complexity.
For most enterprises the break even on migration is one renewal cycle. The CFO who funds it in year one breaks even in year two and books a step down in software spend from year three.
The CFO who does not fund it pays the population charge in perpetuity, with annual escalation and audit settlement exposure on top. Those are the only two paths, and the choice is made by whoever controls the engineering budget rather than by procurement.
Oracle Java versus OpenJDK distributions
| Distribution | Commercial use | Support model | Typical use |
|---|---|---|---|
| Oracle Java SE | Requires Universal Subscription | Oracle paid support | Estates preferring a single vendor stack |
| Eclipse Temurin | Free | Community plus optional paid | Most common OpenJDK replacement |
| Amazon Corretto | Free | Amazon long term support | AWS heavy estates |
| Azul Zulu | Free, paid optional | Azul extended support | Latency sensitive workloads |
| Microsoft Build of OpenJDK | Free | Microsoft long term support | Azure and Microsoft heavy estates |
Where the common advice on Oracle Java licensing is wrong
The standard reseller pitch is that the Universal Subscription is the safe choice because it covers everything and removes audit risk. We disagree.
In roughly seven out of ten estates we modelled, the Universal Subscription was the most expensive answer on the table. It removes audit risk by paying the maximum possible price for it, which is a strange definition of safe.
The buyer side move runs the other way. Sweep the estate first, isolate Oracle Java to the workloads that genuinely require Oracle support, migrate the rest to a free OpenJDK distribution, and only then price any residual subscription against a far smaller employee envelope.
Source: Redress Compliance advisory engagement file, 2024 to 2025.
The Universal Subscription is not a Java license. It is a per employee fee with no link to how the technology is used. Treat it as a commercial choice, not a technical one.
What should a buyer do next?
- Run an estate sweep and record the distribution, version and licence file for every Java instance, with the date of the sweep.
- Place yourself in one of the three post 2023 states, because the sequence that follows is different for each.
- Separate Oracle Java from other distributions, since only Oracle builds need a subscription.
- Split the Oracle builds into free and chargeable at the 8u202 line and at the No Fee Terms window for each long term support release.
- Diary the September 2026 JDK 21 revert against your own patch calendar before it arrives.
- Build a defensible employee count from your own systems and document the contractor test you will hold.
- Plan the OpenJDK migration for every workload that does not need Oracle support, and fund it.
- Quantify the residual Oracle footprint before you accept any quote.
- Negotiate the subscription against the smaller residual envelope, and get the six clauses above into the order document.
- Preserve any pre 2023 contract and confirm it is not expanded by accident.
Closing thought
January 2023 reframed Java for the enterprise from a software licence into a per employee subscription. The buyer side response has matured since then: the defence pattern is established, the migration path is well travelled, and the clauses are well understood.
Customers who treat Java as a strategic procurement decision, with a credible alternative and a documented plan, negotiate well. Customers who treat it as a default renewal pay the population charge year after year with audit risk on top.
Redress Compliance is independent and entirely buyer side. We have advised on Java negotiations and audits across financial services, manufacturing, healthcare, telecommunications and the public sector. If you are facing a quote, a renewal or an audit notice, the next step is a confidential briefing.
Frequently asked questions
What changed in Oracle Java licensing in January 2023?
Oracle replaced the per processor and per Named User Plus Java SE Subscription with the Java SE Universal Subscription, priced per employee. The new metric counts the entire workforce rather than Java users, which makes the same deployment far more expensive for large organisations.
Was 2023 the first Oracle Java licensing change?
No. The paywall arrived in April 2019, when Oracle JDK 8u211 and later moved onto the Oracle Technology Network licence. Estates that missed that change were already exposed before the 2023 metric change repriced the exposure.
Who counts as an employee under the Universal Subscription?
Every full time, part time and temporary employee, plus the equivalent staff of your agents, contractors, outsourcers and consultants who support your internal business operations. The count is independent of Java use, and the qualifying phrase about internal operations is the main thing buyers should challenge.
Do our pre 2023 Oracle Java contracts still work?
Yes. Perpetual and Named User Plus agreements signed before January 2023 remain valid for the deployments they cover, and they still price on usage rather than payroll. They cannot be expanded, so new growth must move to the Universal Subscription or to an OpenJDK distribution.
Can our estate become chargeable without us buying anything?
Yes, and it is the most common way it happens. Each long term support release carries free production terms for a defined window, and a routine patch after that window closes moves the estate onto paid terms. Oracle JDK 17 did this in October 2024 and Oracle JDK 21 is scheduled to do it in September 2026.
What triggers an Oracle Java audit?
Download evidence, most often. Oracle can see downloads of Oracle Java from its site against your corporate domain, and those records usually predate the enquiry by years. Reviews before a Database or E Business Suite renewal and large documented deployments are the other recurring triggers.
Is OpenJDK a credible replacement for Oracle Java?
Yes for most workloads. Eclipse Temurin, Amazon Corretto, Azul Zulu, the Microsoft Build of OpenJDK and the Red Hat build are production grade and free for commercial use. The blocker is rarely technical. It is tooling discipline on developer workstations and build pipelines.
How much can we save by migrating off Oracle Java?
On rate alone, 22 to 41 percent is what we see conceded between quote and signature. Larger reductions come from scope: isolating Oracle Java to the workloads that need it and migrating the rest cut the subscription envelope by more than half in most estates we modelled.
How long does an OpenJDK migration take?
Nine to fourteen months at large enterprises. The runtime swap is straightforward. The schedule is set by developer tooling, continuous integration pipelines and validation of third party applications that bundle a Java runtime.
What is the buyer side move if we must keep some Oracle Java?
Scope down first. Quantify the residual Oracle footprint, build a defensible employee count, and document the contractor test you will hold. Then negotiate against that smaller envelope rather than the whole workforce, and get the counting methodology and the price hold into the order document.