Contents
Key takeawaysWhy inventory comes firstFinding every installMoving to OpenJDKWhat a 5,000 employee exit savesServing noticeBefore the term endsWhat Oracle will sayWhat we have seenWhat to do nextFAQLeaving the Oracle Java SE subscription is an inventory project first: find where Oracle Java runs, move it to free OpenJDK builds and record every removal. Your rights end at term end, and one reinstalled binary reprices the whole workforce.
- Inventory before anything else. Oracle Java ran on 10 to 30 percent of the machines the employee bill implied, and you cannot remove what you have not found.
- OpenJDK carries most workloads. In our exits, 70 to 95 percent of workloads moved to free OpenJDK builds with no application change, and the choice of distribution is an operational one.
- The saving recurs every year. Net Java spend fell 60 to 90 percent once migrations were complete, against a migration effort that ends.
- Notice is a legal act. Written notice to the party your notices clause names stops automatic renewal, and an email to your account rep does not.
- Term rights end on a date. Every Oracle JDK binary downloaded under the subscription must be gone by the term end date, with each removal recorded.
- One reinstall reprices the workforce. Under the employee metric, a single Oracle binary found after the exit supports a claim across your full headcount, so block reinstallation in policy and pipelines.
Why does exiting the Oracle Java SE subscription start with an inventory?
The invoice tells you nothing about where Oracle Java runs. The Java SE Universal Subscription is priced per employee, so the bill is the same whether Oracle Java sits on every laptop or on a few servers. Across the exits we guided, Oracle Java ran on only 10 to 30 percent of the machines the bill implied.
That gap shifts the hard part of an exit away from the technology. The blocker is visibility: you cannot remove what you have not found, and you cannot prove a removal you did not record.
Why does the employee metric make the business case for leaving?
A subscription priced on headcount for software running on a tenth of your machines pays for the whole exit program. The migration effort is bounded and ends on a date you set. The subscription has no end date and grows with every hire, so the reduction you bank repeats every year.
How to Negotiate the Oracle Java Employee Agreement: Honest Leverage in a Captive Deal
How do you find every Oracle Java install before you leave?
Scan file systems for the runtime binaries themselves. Installer lists miss the places that matter most: private JREs bundled inside third party applications, jlink images baked into internal tools, and build pipelines that pull an Oracle JDK by default.
The discovery method is the one set out in our JRE licensing brief and the shadow install analysis. An exit adds one column to it. Every install gets a disposition (migrate, retain commercially, or retire), a named owner and a target date.
Which checks show whether a machine runs Oracle Java?
- Version string. Run java with the version flag against every Java binary the scan finds, not only the one on the path. Oracle JDK builds report "Java(TM) SE Runtime Environment". OpenJDK builds report "OpenJDK Runtime Environment" and usually name the distributor. IBM's own SDK also prints "Java(TM)", so confirm the java.vendor property (java with the XshowSettings:properties flag) before you count a machine as Oracle.
- Windows machines. Check installed programs for entries such as "Java 8 Update" and the JavaSoft registry keys, then search disks for java.exe, because bundled runtimes rarely register.
- Linux and Unix servers. Query rpm or dpkg for JDK packages, then search for java binaries the package database does not know about, such as those inside application folders.
- Containers and pipelines. Inspect base images, Dockerfiles and CI definitions. An Oracle JDK base image, or a GitHub Actions setup step with the distribution set to oracle, puts Oracle binaries into everything built from it. See our notes on Docker base images and pipeline and workstation cleanup.
| Population | Typical share | Disposition |
|---|---|---|
| Standard workloads on Oracle JDK or JRE | 70 to 95 percent of workloads | Move to an OpenJDK build with no application change, migrated in batches |
| Vendor bundled and pinned runtimes | The stubborn middle | Resolved vendor by vendor: their license, their upgrade, or a supported open build |
| Workloads that truly depend on Oracle Java | A small set, identified from the scan and never assumed | Retained commercially, scoped to named hosts, priced deliberately |
| Leftovers on machines no one had counted | The surprise: the bill assumed 3 to 10 times the footprint that actually runs Oracle Java | Retired, with each removal recorded in the evidence pack |
Java subscription exit guide
The inventory method, notice mechanics and evidence pack for leaving the Oracle Java SE subscription.
Get the white paper →Will your applications run on OpenJDK once Oracle Java is gone?
Almost all of them will, unchanged. OpenJDK builds come from the same codebase as the Oracle JDK, so the work is in sequencing, testing and replacing binaries at scale. Our migration decision guide and the three cost modeled migration patterns set out the sequence:
- Batch replacement. Standard servers and desktops move to an OpenJDK build of the same major version through your normal deployment tooling.
- Pinned applications. Workloads tied to a runtime by a vendor are handled one at a time, with the vendor asked in writing which builds it supports.
- Pipeline conversion. Build images and toolchains switch to the new distribution, so the next release does not bring Oracle binaries back.
The distribution comparison covers Amazon Corretto, Eclipse Temurin and Azul Zulu. All three are free to run in production, and paid support is available for teams that want a supplier to call.
Why picking the OpenJDK distribution first is the wrong place to start
Much of the published advice on leaving Oracle Java opens with the choice between Corretto, Temurin and Zulu. We think that order is backward. All three ship the same OpenJDK code on the same quarterly update cycle, so the choice is an operational preference with little risk attached.
The exits that ran into trouble in our work did so on missing inventory and missed deadlines. Start with the file system scan and the contract dates. Once you know how many machines need a new runtime, choosing the distribution takes one short meeting.
What should you do with workloads that need an Oracle build?
Treat them as a separate decision. The usual case is an application whose vendor supports it only on the Oracle JDK. Scope that set to named hosts and price it against the alternatives before anything is renewed by default.
- Rights you already hold. Several Oracle products include restricted use rights to Java SE for running that product.
- Oracle JDK under the No Fee Terms. Oracle's current long term support release can run in production free for a set window, planned until September 2028 for JDK 25. After that date, later JDK 25 updates move to the OTN license, which does not allow general production use. It helps only if the application supports that release and you plan the next upgrade, as our note on the JDK 25 free window explains.
- The application vendor's license. Where a vendor ships the runtime inside its product, ask the vendor to confirm in writing that its license covers it.
- A negotiated residual. If you still need Oracle, a bounded, evidenced list of hosts gives you a far stronger hand than the all or nothing renewal ever did.
How much does leaving Oracle Java save a 5,000 employee company?
It saves most of the subscription, provided the inventory is complete and the residual Oracle set stays small. The hypothetical company below has 5,000 employees, which puts it in Oracle's $10.50 per employee per month band, and runs 4,000 desktops and 600 servers.
| Step | Figure | How it is reached |
|---|---|---|
| Annual subscription at list | $630,000 | 5,000 employees x $10.50 x 12 months |
| Machines found running Oracle Java | 920 | 20 percent of 4,600 machines, inside the range we saw |
| Moved to OpenJDK with no application change | 782 | 85 percent of the 920 |
| Vendor bundled runtimes resolved with the vendor | 90 | Vendor upgrade, vendor license or supported open build |
| Retired | 36 | No owner and no use found |
| Retained on an Oracle build | 12 | Named servers, covered separately |
| Net annual Java spend at the reduction range we saw | $63,000 to $252,000 | Support, residual Oracle cover and tooling combined |
The 12 retained servers are where the negotiation happens. Oracle sells the Universal Subscription on the employee metric, so those servers need cover through existing rights, the NFTC route, a vendor's license or a negotiated arrangement. Leaving them on a full employee subscription would erase the saving.
How does the exit change with company size?
- Around 500 employees. At Oracle's entry rate of $15 per employee per month, the subscription costs $90,000 a year. One team can usually scan and migrate everything in a single pass, so the real risk is administrative: the notice and the removal records need the same care a large company gives them.
- 40,000 employees or more. At 40,000 employees, Oracle's lowest published band of $5.25 still gives $2,520,000 a year at list, and above 50,000 employees Oracle prices by quote. Inventories span business units, acquisitions and outsourced IT, so plan more time for discovery than for migration.
- Legacy Named User Plus or Processor subscriptions. Oracle says legacy subscribers may renew only as far as their existing order permits, subject to confirming usage. Compare exiting with renewing on the legacy metric first.
How do you give notice so the Java subscription does not renew automatically?
Serve written non renewal notice to the party named in the notices clause of your contract, in the form that clause requires, inside its window, and keep proof of delivery. An email to your Oracle account rep does not count as notice, and an automatic renewal clause will run if that email is all you sent.
What should you check in the order documents before setting the calendar?
- Term end date. Read it from the ordering document, since invoices often show billing periods instead.
- Renewal terms. Whether the order renews automatically, and at what price.
- Notice requirements. The window, the required form, and the Oracle entity and address named.
- Governing agreement. The Oracle master agreement the order sits under, where notice and audit terms often live.
- Proof of delivery. A courier receipt, a registered post record or a written acknowledgment from Oracle's contracts team.
The notice window can close months before the subscription expires, which usually makes it your first hard deadline.
What has to happen before the subscription term ends?
Every Oracle JDK binary licensed under the subscription has to be gone by the term end date. The subscription grants term rights only. Oracle's own FAQ states that your rights to commercial software downloaded under it end with the subscription, along with Premier Support.
The day after expiry, any Oracle JDK still installed is unlicensed unless the No Fee Terms or another license covers that exact release.
- Where Oracle Java ran. Host, path, version and owner for every install.
- When it was removed. The date and the change ticket.
- What replaced it. The OpenJDK distribution and version, or the retirement decision.
- Scan outputs and the notice. Raw before and after results, plus the letter and its proof of delivery.
Build the pack as the removals happen. Oracle's approach to Java compliance starts from its download records rather than your inventory, and a complete pack turns that opening into a short exchange of letters. Our pages on proof of removal and decommission log standards set out the format.
How do you keep Oracle Java from coming back after the exit?
Use technical controls, because under the employee metric a single reinstalled binary can support a claim across the whole workforce. For the company in the worked example, one forgotten install puts the full annual subscription back on the table.
- Application control. Block Oracle Java installers and binaries in AppLocker, Windows Defender Application Control or your endpoint tool, using a publisher rule scoped to Oracle's Java product name so other signed Oracle software keeps running.
- Pipeline gates. Fail any build whose base image or toolchain resolves to an Oracle JDK.
- Update checks. Disable the Java auto updater on Java 8 desktops not yet migrated, as covered in our note on blocking update checks.
- Gold images. Rebuild VM templates, laptop images and container base images, or old Oracle builds return with the next deployment.
The audit activity that tends to follow an exit, and the retroactive claims Oracle often opens with, are covered in our Java audit process guide and the lookback analysis.
What will Oracle say when you tell them you are leaving?
Expect the account team to test your inventory and your deadlines. Few arguments will be about the technology. These are the lines we hear most, with replies that hold up.
- "Our records show Oracle Java downloads across your company." A download record shows what someone fetched, and your removal record shows what happened to it. Ask Oracle to name any host it believes still runs an Oracle binary.
- "OpenJDK is unsupported, and you will be exposed on security." OpenJDK builds receive quarterly security fixes, and you have a named distributor plus paid support where a workload needs it. Say so once, in writing.
- "Stay one more year while you migrate, and we will improve the price." Compare the offer with the cost of finishing on time. If you do need cover, keep it short, with a fixed end date and the same notice terms.
- "We will need a license review once the subscription ends." Point to the notice, the term end date and the evidence pack, and share only what the contract requires, as our guide on what not to hand over explains.
What have we seen across 30 to 40 Oracle Java exits?
Across roughly 30 to 40 Oracle Java exits I guided between 2024 and 2026, the per employee metric drove the decision in almost every case. The proportions described above, the gap between the bill and the real footprint and the size of the saving, held from one exit to the next.
The exits that failed did so for procedural reasons. In none of them did OpenJDK break an application.
Which mistakes cause Oracle Java exits to go wrong?
The first three below are the failures we saw in those exits. The fourth is worth adding to your own checklist, because it undoes finished work.
- Notice served to the wrong party. An email to the rep, or a letter to the wrong Oracle entity, left the subscription free to renew.
- Binaries surviving past term end. They sat in forgotten corners: a build agent, a disaster recovery server, a vendor appliance, an old VM template.
- Evidence assembled after the letter. Rebuilding what ran where after Oracle writes costs far more than logging removals as they happen.
- Pipelines left unconverted. The server work finishes, and the next release ships with an Oracle JDK inside its image.
Every failed exit we saw was preventable by the same discipline the successful ones ran: inventory first, a calendar worked back from the term end, and removal records kept as part of the migration.
What to do next
- 12 months before term end. Pull the ordering document and master agreement, note the term end date, renewal terms and notices clause, and start file system scans.
- 9 months before. Give every install a disposition, an owner and a date, bundled and built runtimes included, and open talks with vendors whose products ship Java.
- 6 months before. Migrate the standard workloads to an OpenJDK build, convert the pipelines and scope the residual Oracle set to named hosts.
- Before the window closes. Serve notice in writing to the party the clause names, with delivery evidenced.
- 1 month before. Run final scans, clear every remaining Oracle binary and close the evidence pack by the term end date.
- After the exit. Keep reinstallation controls in policy and pipelines, and rescan on a schedule. Our Java audit defense service and the Oracle Java licensing guide cover the exit and what follows it.
Frequently asked questions
How do we exit the Oracle Java SE subscription?
Find every Oracle Java install at the file system level, move the standard workloads to OpenJDK, scope any remaining Oracle need to named hosts, serve written non renewal notice as the contract requires, and remove every Oracle binary by the term end date with each removal recorded.
How much does leaving Oracle Java actually save?
Net Java spend fell 60 to 90 percent in our exits once migration was complete. The saving comes from the employee metric: you pay for every employee, while Oracle Java usually runs on a small fraction of the machines that bill implies. The migration is a one time cost, and the subscription recurs.
Will our applications work on OpenJDK?
Almost all of them, unchanged. OpenJDK builds share the Oracle JDK codebase, and in our exits the large majority of workloads moved with no application change. Corretto, Temurin and Zulu differ mainly in support options and packaging. Name any application that depends on Oracle Java from the inventory, with the vendor's support statement attached.
How do we cancel the subscription without it renewing automatically?
Send written non renewal notice to the Oracle entity and address your notices clause specifies, in the form it requires and inside the window, and keep proof of delivery. An email to the account rep does not count. Read the clause before planning anything else, because its window is usually the first deadline you meet.
What happens if Oracle Java is found after we exit?
A single Oracle JDK found after term end can support a claim priced on your full employee count, not only the machine it sits on. For a 5,000 employee company at the $10.50 band that is $630,000 a year, which is why reinstallation controls belong in the commercial plan.
Do we need to keep proof of the migration?
Yes, and keep it indefinitely. Oracle's compliance approach opens from its download records, so a record of what ran where, when it was removed and what replaced it, with raw scan outputs, closes a later inquiry quickly. Built during the exit it costs little; rebuilt after a letter it costs a great deal.
Can we keep using Oracle JDK for free after the subscription ends?
Only for releases under Oracle's No Fee Terms, currently JDK 25 until September 2028. Oracle JDK 8 and 11, JDK 17 updates after September 2024 and JDK 21 updates after September 2026 fall under the OTN license, which excludes general production use. Old Java 8 builds released before April 2019 carry the earlier Binary Code License but no security fixes.