Contents
Key takeawaysWhen to run a reviewWhat we have seenWhat counts as Oracle JavaBuilding the employee countRating the findingsAnswering OracleWhat the review producesWhat to do nextFAQA Java licensing review should end in a signed file, with a coverage statement, two registers and an employee workpaper, that shows what you would owe Oracle and what you could prove if a claim arrived tomorrow.
- The review produces a position. What matters is how many Oracle runtimes you cannot explain, far more than how many runtimes exist.
- Publish a coverage statement. Findings from an environment you only partly reached are a sample, so state your reach per population and name what you missed.
- Oracle's employee definition goes beyond payroll. It includes staff of agents, contractors, outsourcers and consultants who support your internal business operations.
- Support is inside the subscription price. There is no separate support percentage to add to the published per employee rate.
- The tier rate applies to the whole count. At every published tier boundary, the annual bill falls as headcount rises.
- 999 employees is the worst count to have. A thousandth employee drops the rate from $15.00 to $12.00 and cuts the annual bill by roughly a fifth.
There is no Oracle deadline today, no audit letter and no sales call pending. That makes now the cheapest time to establish your Java position and change it on your own schedule. A good review ends in a signed file: a charter, a method note, a coverage statement, two registers, a headcount workpaper and a conclusion.
Before you rely on any summary, including this one, read the five documents that settle most review questions. They are the OpenJDK project for what is not Oracle at all, Oracle's no fee terms, its Technology Network license, its Java SE licensing questions page and its Universal Subscription page for the metric and the rates.
When should you run a Java licensing review?
Run it at a time you pick. Three windows give you enough time and freedom to act on the findings. A fourth, the formal audit notice, arrives too late for a voluntary review, because from that point the work happens under audit rules.
| Window | Why it is the right moment | What you can still change |
|---|---|---|
| Twelve months before an Oracle renewal | A full cycle to act before anyone needs an answer from you | Everything: distribution, count, structure, and whether you renew at all |
| During diligence on an acquisition or disposal | The counterparty's Java position becomes yours on completion day | Price, warranties, indemnities, and who carries the transition |
| The quarter after an informal approach from Oracle | A friendly enquiry about Java use usually comes before a formal one | Your position and your evidence, before anything is in writing |
| After a formal audit notice | Too late for a voluntary review | Only the quality of your response |
What goes in the review charter?
Write a one page charter before anyone opens a discovery tool. Without it, the review turns into an inventory exercise and stalls there. The charter fixes six things.
- The question. One sentence, written in the language of the person who will read the answer. "How much Java do we have" is the wrong question; "what would we owe Oracle, and what could we prove, as of 30 June" is closer.
- The sponsor. A named executive who will sign the conclusion. Knowing a signature is coming keeps everyone honest about what the evidence supports.
- Scope in and out. Legal entities, geographies, and the populations you will and will not reach. Naming the exclusions is what makes the rest credible.
- The as of date. One date the whole review speaks to. Mixed dates are the quickest way to lose an argument about a number.
- The privilege position. If the answer might be unwelcome, run the work under counsel from day one. Protection cannot be added to a document that has already circulated.
- The circulation list. Who sees drafts. A draft with a wrong number in it has a long and unhelpful life once it reaches a wide audience.
Who should do the work?
You need three functions, and one of them is usually missing. Asset management reaches the machines, procurement holds the ordering documents, and legal reads the terms. A review run by asset management alone produces a count with no position behind it.
How to Negotiate the Oracle Java Employee Agreement: Honest Leverage in a Captive Deal
What have we seen in voluntary Java reviews?
Fredrik Filipsson ran roughly 35 to 45 voluntary Java reviews across 2024 and 2025. Some later held up when Oracle pushed on them and some fell apart. The ones that held up differed in four ways.
- They stated their reach. Each one said how much of each population it had actually reached, and named the assets it had not.
- They recorded who built every runtime. When Oracle later questioned the total, the discussion stayed on the total and never became a dispute about the method.
- They searched entitlements as hard as deployments. Roughly a third turned up rights the organization had forgotten it held.
- They ended in a range. The conclusion gave a low and a high figure with the assumptions that move it, instead of one number an executive could quote out of context.
What counts as Oracle Java in a review?
Oracle Java, for licensing purposes, means builds produced by Oracle, obtained under terms that require a subscription, and used in a way those terms do not permit for free. Everything else is noise, and most organizations carry far more noise than signal. Sort every runtime into one of five categories, in this order.
| Category | What it looks like | Obligation? | What you file as proof |
|---|---|---|---|
| 1. Not an Oracle build | Temurin, Corretto, a Microsoft build, an Azul build, a Red Hat build | No | The implementor string, read straight off the installed runtime |
| 2. Oracle build, covered by a free use term | A release obtained while Oracle's no fee terms applied to it, used within those terms | No, for that release and that use | Release, build number, date obtained, and the term text in force then |
| 3. Oracle build, covered by another Oracle order | A runtime present solely to operate a licensed Oracle product | Usually no, within the limits of that grant | The parent product's ordering document |
| 4. Oracle build, covered by a legacy Java order | A pre 2023 Java SE order still in force for its original scope | No, within the quantity and metric granted | The order, the quantity, and evidence of which machines it maps to |
| 5. Oracle build, nothing covering it | Anything left after the four tests above | Yes | Provenance, use evidence, and the date it entered the environment |
Categories one to four are cheap to prove, and each one you close shrinks the fifth. The fifth category is where every commercial conversation with Oracle eventually ends up, so you want it as small and as well documented as possible.
Why does the build number matter more than the version?
Oracle changed its Java terms several times between 2019 and 2023, and the terms attached to a runtime are the ones that applied when it was obtained. A build number is evidence. A version family is not, because one family can span two licenses.
| Oracle build | License it was released under | Free for general production use? |
|---|---|---|
| Oracle JDK 8u202 and earlier | Binary Code License | Yes, within that license, but without later security updates |
| Oracle JDK 8u211 (April 2019) and later | Java SE OTN License | No. Development, testing and personal use only |
| Oracle JDK 11 | OTN License, or a support contract | No |
| Oracle JDK 17.0.12 and earlier (releases through September 2024) | No Fee Terms and Conditions (NFTC) | Yes, within the NFTC |
| Oracle JDK 17.0.13 and later | OTN License, or a support contract | No |
| Oracle JDK 21 | NFTC for releases through September 2026; OTN for later updates | Yes for releases through September 2026; no for later ones |
| Oracle JDK 25 | NFTC for releases through September 2028 | Yes, within the NFTC |
Record the full build string for every Oracle runtime and the date it arrived. A review that records only major versions has thrown away the field that decides which license applies.
The chronology behind these changes is set out in our guide to the 2023 Java licensing changes. The current Java 21 cutoff is covered in our note on Java 21 updates ending in 2026.
How do you tell an Oracle build from an OpenJDK build?
Read the evidence off the runtime itself, and capture it with a date. Four checks cover most machines.
- The release file. Most JDK and JRE home folders hold a plain text file called release. In recent builds its IMPLEMENTOR line names the builder, for example Eclipse Adoptium or Amazon.com Inc.
- The version banner. Running java -version on an Oracle JDK prints "Java(TM) SE Runtime Environment" with the build string. An OpenJDK build prints "OpenJDK Runtime Environment".
- The system properties. Running java -XshowSettings:properties -version lists java.vendor and java.vm.vendor, which is useful where you can run a command but cannot browse the file system.
- The installer record. On Windows, Oracle's installers register entries such as "Java 8 Update 202" in the installed programs list, which gives you the update number without touching the runtime.
One trap catches many teams. Oracle also publishes free OpenJDK builds under GPLv2 with the Classpath Exception at jdk.java.net, and those builds, like some older Linux distribution OpenJDK packages, can report Oracle Corporation as the vendor. Pair the vendor field with the version banner before you place anything in category 5.
What should the coverage statement say?
It states what proportion of each population you actually reached, and how you know. Few teams write it, yet this one paragraph separates a review from an anecdote. Forty seven findings across an environment you reached 60 percent of are a sample, and Oracle will treat them as one.
- Report by population. Reaching 90 percent of servers and 40 percent of endpoints is a very different result from 78 percent overall.
- Name the unreachable. Air gapped systems, plant equipment, machines belonging to people on long leave, and anything a supplier controls.
- Say how you know. A coverage figure taken from the same tool that did the discovery is circular. Reconcile against a second source, usually the asset register or the payroll device list.
How do you build an employee count Oracle cannot pick apart?
Build it as a workpaper with a source, a test and a note for every line. A payroll extract is only the starting point. The finished count is a reasoned position that has to survive someone challenging each line on its own.
Who does Oracle's employee definition include?
Oracle's employee definition for the Universal Subscription is broad, and it is the single term that decides your bill. Read the current wording on Oracle's own price list rather than relying on any summary, including ours.
In substance it covers two groups of people:
- Your own staff. Full time, part time and temporary.
- Staff of your suppliers. The full time, part time and temporary staff of your agents, contractors, outsourcers and consultants who support your internal business operations.
The definition is not limited to people who use Java, and outsourced staff are not automatically outside it. Our guide to counting contractors and consultants works through the borderline cases.
| Line | Source | The test | Where it gets argued |
|---|---|---|---|
| Permanent staff | Payroll at the as of date | Heads, not full time equivalents | Long term absence, parental leave, dormant records |
| Part time and temporary | Payroll plus agency records | Each person counts once | Seasonal peaks, and which date you chose |
| Agency and contract staff | Supplier management system | Do they support your internal business operations? | People delivering a project on the supplier's own systems |
| Outsourced service staff | The outsourcing agreement itself | The same internal operations test, applied to their people | The most contested line in every negotiation we have run |
| Acquired entities | Completion documents | Are they inside the contracting entity at the as of date? | Timing, and whether the order names affiliates |
| Divested entities | Transitional service agreement | Who is the contracting party while services continue? | Transitional arrangements almost always go uncounted |
What do the published tier rates do to that count?
Oracle publishes seven employee tiers. The rate for your tier applies to your entire count, including the employees below the threshold, and support is included in the price rather than added on top.
| Employee count | Per employee per month | Worked annual example |
|---|---|---|
| 1 to 999 | $15.00 | 500 employees, $90,000 per year |
| 1,000 to 2,999 | $12.00 | 2,000 employees, $288,000 per year |
| 3,000 to 9,999 | $10.50 | 5,000 employees, $630,000 per year |
| 10,000 to 19,999 | $8.25 | 15,000 employees, $1,485,000 per year |
| 20,000 to 29,999 | $6.75 | 25,000 employees, $2,025,000 per year |
| 30,000 to 39,999 | $5.70 | 35,000 employees, $2,394,000 per year |
| 40,000 to 49,999 | $5.25 | 45,000 employees, $2,835,000 per year |
| 50,000 and above | Not published | Priced individually. Ask for the rate in writing before anything else. |
Why is 999 employees the worst count to have?
Because the rate applies to the whole count, the annual bill drops every time you cross a tier boundary upward. At 999 employees you pay the top rate on every head, and a thousandth employee takes you to $12.00 and cuts the bill by roughly a fifth. Each row below can be checked against the published rates.
| Just below | Annual cost | Just above | Annual cost |
|---|---|---|---|
| 999 at $15.00 | $179,820 | 1,000 at $12.00 | $144,000 |
| 2,999 at $12.00 | $431,856 | 3,000 at $10.50 | $378,000 |
| 9,999 at $10.50 | $1,259,874 | 10,000 at $8.25 | $990,000 |
| 19,999 at $8.25 | $1,979,901 | 20,000 at $6.75 | $1,620,000 |
| 29,999 at $6.75 | $2,429,919 | 30,000 at $5.70 | $2,052,000 |
| 39,999 at $5.70 | $2,735,932 | 40,000 at $5.25 | $2,520,000 |
Two practical consequences follow. If your count lands just under a boundary, test whether a broader reading that you could support just as well costs less. And do not accept a supplier's claim that a growing headcount must mean a growing Java bill.
A worked example near a tier boundary
Say a hypothetical company has 2,640 permanent staff and 190 part time and temporary staff on payroll at the as of date. It also has 120 agency contractors working inside its own operations.
A systems integrator also has 90 people delivering a project for the company from the integrator's own offices and systems. That line can be argued either way.
| Workpaper line | Narrow reading | Broad reading |
|---|---|---|
| Permanent staff | 2,640 | 2,640 |
| Part time and temporary | 190 | 190 |
| Agency contractors supporting internal operations | 120 | 120 |
| Integrator project team | Excluded, works on supplier systems | 90 |
| Total count | 2,950 | 3,040 |
| Tier rate per employee per month | $12.00 | $10.50 |
| Annual cost | $424,800 | $383,040 |
The broader reading is 90 people larger and $41,760 a year cheaper. You must be able to support whichever reading you choose, so test both and record why the integrator line is in or out. A line you include this year is hard to remove at the next renewal, so weigh the saving against that precedent.
How do you rate and rank what the review finds?
Put every asset into one of five evidence classes, then drive one of those classes to zero. Ranking findings by dollar value first is the common mistake, because it hides the class that decides your position.
| Class | What it means | Evidence standard | Who owns closing it |
|---|---|---|---|
| Confirmed | An Oracle build in use with nothing covering it | Provenance plus evidence of use | Commercial |
| Probable | An Oracle build present, entitlement search not yet finished | Provenance, entitlement work in progress | Procurement and legal |
| Covered | An Oracle build covered by another order or a free use term | The order or the term text, filed against the asset | Procurement |
| Excluded | Not an Oracle build at all | The implementor value, captured at a stated date | Asset management |
| Unknown | An asset no technique reached | None, which is the problem | The review sponsor, personally |
At sign off, the unknown class is the one that counts, and the target for it is 0. A review that closes with 300 confirmed findings and zero unknowns is a strong position. One that closes with 30 confirmed findings and 2,000 unknowns is no position at all, because Oracle will fill every unknown with its own assumption.
How do you turn the classes into a range?
Report a low case and a high case, and name the two or three decisions that separate them. A single figure gets forwarded without its caveats, while a range carries its assumptions with it.
- The low case. Confirmed findings only, with covered and excluded assets fully proved and every probable resolved in your favor.
- The high case. Every probable resolved against you, every unknown assumed to be an uncovered Oracle build, and the broadest reading of the employee definition.
- The swing factors. Usually three: the outsourced staff line, the treatment of one large application supplier, and the assets you could not reach.
Why we advise against starting with a discovery scan and a count
The usual advice is to run a discovery tool across every machine and count the Java installations. We disagree, because a raw count never survives contact with Oracle. Oracle will press on the runtimes you cannot explain, and explaining one takes provenance, an entitlement search and a coverage statement a stranger could reproduce.
An early unqualified total also tends to leak, get quoted back to you, and become Oracle's opening figure in the negotiation. Produce the workpapers first and the number last.
What will Oracle say, and how should you answer?
Most Java conversations start with an informal message from an Oracle account or licensing contact. With a finished review in hand, you can answer each opening line calmly and in writing. These are the lines we hear most often, with replies that keep the discussion on your evidence.
| What Oracle says | What to say back |
|---|---|
| "We would like to understand how you use Java. Can we arrange a short call?" | "We run an internal review on our own schedule. Please send your questions in writing and we will respond once it is complete." |
| "Our records show Java downloads from your corporate domain." | "A download is not a deployment. Please send the list with dates, builds and user accounts so we can check it against our register." |
| "Your annual report shows your headcount, so that is the employee count." | "Annual report figures use different dates and definitions. We will give you a count as of a stated date, line by line, with its sources." |
| "Contractors are always included under the employee metric." | "The definition covers staff who support our internal business operations. We apply that test to each supplier and can show the reasoning." |
| "If you sign this quarter, we can set aside the prior years." | "Please show the contractual basis for any prior year fee. We will consider an offer once our review has concluded." |
If the first call has already happened, our note on what to say on the first Oracle call covers the next steps. Our guide to checking Oracle's headcount claim shows how to test the number Oracle puts forward.
What does a finished Java licensing review produce?
A finished review produces seven documents and one signed conclusion. If it ends with a slide instead of a file, it will not survive the first serious question, and that question always comes eventually.
- The charter. The question, the sponsor, the scope, the as of date, the privilege position and the circulation list.
- The method note. How each population was reached, in enough detail that a third party could repeat it and get the same answer.
- The coverage statement. Proportion reached per population, the reconciliation source, and a named list of what was not reached.
- The entitlement register. Every Oracle order touching Java, including grants hidden inside orders for other Oracle products.
- The findings register. Every asset, its class, its provenance evidence and its owner.
- The employee workpaper. Six lines, six sources, and a written note on each disputed line.
- The conclusion. One page: a range, the assumptions that move it, and the three decisions the sponsor now has to make.
A review is finished when you could hand the whole file to someone hostile and still be comfortable.
How should you sign off and refresh the review?
- Sign it, with a date. An unsigned review stays a draft forever, and drafts get quoted without their caveats.
- Refresh it annually, and immediately after any corporate event that changes the entity list or the headcount materially.
- Keep the registers live. Asset management should maintain the entitlement and findings registers through the year, so next year starts from a current file instead of a rebuild.
- Store it where it outlives the tooling. Discovery platforms get replaced every few years. The file should not depend on any one of them.
What does the review feed into next?
The conclusion drives one of three decisions: remediate, buy, or do nothing and monitor. Each needs its own program, and the review tells you which one you are choosing. Size the buy case against your own numbers with the Oracle Java license calculator.
If the answer needs a negotiation, our Oracle advisory practice runs the commercial side without reselling anything. Whoever negotiates, the review should shape the contract terms you ask for.
- A stated count and date. Put the employee count and the as of date in the order, so the baseline cannot be reopened later.
- An agreed definition for disputed lines. Record in writing how the outsourced and contractor lines were treated, so the next renewal starts from the same reading.
- Named entities. List the legal entities covered, and say how acquisitions and divestments during the term are handled.
- Renewal price protection. Ask for a cap on the per employee rate at renewal. Without one, the tier rate is the only reference point.
- A release of prior use. If Oracle raised past use, ask for written confirmation that the new order settles it.
What to do next
- This week: write the charter. One page, six fields, and a named sponsor who will sign the conclusion.
- Fix the as of date first. Make every source, from payroll to discovery, speak to that same date.
- Decide the privilege position before drafting starts. It costs nothing now and cannot be added later.
- Search entitlements before machines. Every right you already hold reduces the work on the deployment side.
- Capture provenance for every Oracle runtime. Record the builder and the full build number, since the major version alone does not decide the license.
- Publish the coverage statement. Report it per population, with the reconciliation source named.
- Drive the unknown class to zero before anyone starts debating the size of the number.
- Close with a range and three decisions, then put the refresh date in the sponsor's calendar.
Has Oracle contacted you about Java? Talk to us before you reply. Our Oracle Java audit defense is led by former Oracle insiders and runs on a fixed fee.
Frequently asked questions
Who should sponsor a Java licensing review?
An executive who can act on the answer, usually the CIO or the CFO. The sponsor signs the conclusion, and that signature forces the team to claim only what the workpapers support. Reviews sponsored at manager level tend to end as an unsigned slide deck that commits the company to nothing.
How much time should we allow for a Java licensing review?
Allow six to ten weeks for a large organization and three to four weeks for a focused one. Entitlement work and the employee workpaper run alongside discovery, so the timeline is set by the hardest populations to reach, not the analysis. Reviews that overrun almost always started without a written charter.
Should a Java licensing review be run under legal privilege?
Yes, if there is a realistic chance the answer will be uncomfortable, and decide before any drafting starts. Instruct counsel at the outset and route the work and the drafts through them. Trying to protect a document after it has already circulated internally does not work.
Does a Java review have to reach every machine?
No, but it has to say which machines it missed and why. A stated gap is a manageable weakness, while an unstated one damages the credibility of everything else. Record the barrier for each unreachable population and whatever compensating evidence you obtained, such as a written statement from the equipment manufacturer.
Do outsourced staff count toward the Oracle Java employee metric?
Often they do, which surprises many buyers. The test is what the people do for you, so outsourced staff who support your internal business operations fall inside the definition regardless of who employs them. Check the current wording in Oracle's price list and document your reasoning supplier by supplier.
Is support charged on top of the Java SE per employee price?
No. Support is part of the Java SE Universal Subscription fee. If a quote or an internal model adds a support line on top of the per employee rate, the model is wrong and will overstate your exposure by a wide margin.
What if the review finds we already own more Java rights than we thought?
That happens in roughly a third of the reviews we run, usually through Java rights embedded in orders for other Oracle products. Those grants are normally limited to running the parent product, so map them to specific machines instead of claiming them broadly, and file each ordering document in the entitlement register.
How often should a Java licensing review be refreshed?
Once a year as a baseline, and straight after any event that changes the legal entity list or the headcount materially. In between, keep the entitlement and findings registers up to date. Rebuilding the review from nothing every year costs several times what maintaining the registers costs.