Contents
Key takeawaysThe failover ruleWhat needs a full licenseData Guard standbysWhat we have seenEvidence to keep readyWhat to do nextFAQOracle gives disaster recovery one narrow concession: a single spare node in a shared storage cluster, for ten separate 24 hour periods a year. Almost every standby and mirror site outside it needs a full license, options included.
- The concession covers one spare node. Oracle's failover rule allows a single unlicensed spare in one cluster and one data center to run the database for up to ten separate 24 hour periods a year.
- Maintenance counts against the ten. Oracle's December 2024 wording counts maintenance downtime and every partial period, so monthly patching through the spare uses up the allowance.
- Standbys need full licenses. A Data Guard standby holds its own copy of the data, fails the shared storage test and needs the same edition as production, even in mount mode.
- Options follow the data. Oracle's policy requires the standby's options and license metric to match production, so Partitioning or Advanced Compression on the primary means the same on the standby, with Real Application Clusters the main exception.
- Drills sit in a gray area. The testing right covers restoring backups up to four times a year, so get Oracle's treatment of switchover drills confirmed in writing.
- Records settle the question. Keep a storage map, a spare node count, a whole day log and an option inventory ready before any audit asks for them.
What does Oracle's failover rule allow for disaster recovery?
It allows one unlicensed spare node in a cluster to run the licensed database for up to ten separate 24 hour periods in a calendar year while the primary is down. That is the whole concession. Oracle has no general disaster recovery exemption, and reading the failover rule as one is the most expensive mistake in this subject.
Oracle's policy text calls it the 10 day rule, first set out in the software investment guide, and the current wording sits in Oracle's Licensing Data Recovery Environments document, dated December 15, 2024. Both are policy documents outside your contract and have been revised more than once, so check the current version against your ordering documents before relying on it.
Which conditions must all hold at once?
- Shared storage. The failover node and the production node sit in one cluster and attach to the same logical disk array.
- One data center. That array is located in a single data center, which rules out a second site by definition.
- One node. Only a single spare in each cluster qualifies, however many are configured.
- Whole period counting. Any part of a 24 hour period the node runs counts as a full period.
- Failover only. The node runs production's workload because the primary is down. Using it as somewhere to run reports is licensed use.
- Return to normal. When the primary is repaired, you switch the workload back to it, or you designate the repaired server as the new failover node.
How are the ten days counted?
By separate 24 hour periods, and partial use rounds up. Oracle's own example counts two hours of failover on Tuesday and three hours on Friday as two periods. Once the total passes ten in a calendar year, the failover node must be licensed.
The 2024 wording also says downtime for maintenance counts toward the ten. That changes the arithmetic for patching. On that reading, a team that runs production on the spare for a few hours each month while it patches the primary uses 12 periods a year, and breaks the limit before any real failure happens.
Which Oracle disaster recovery setups need a full license?
Every setup except that single spare node needs a full license for the database and for every option running on it, and so does the spare once it passes the allowance. The rule is also silent on several things buyers assume it covers. The table sets out the configurations we meet most often.
| Configuration | Covered by the failover rule | What it actually needs | Why buyers get it wrong |
|---|---|---|---|
| Spare node, shared storage, same data center, used only when the primary is down | Yes, within the allowance | Nothing extra inside the limit | This is the only covered case |
| Second site | No | Full license for database and options | It is read as disaster recovery relief |
| Standby copy on its own storage | No | Full license, because it fails shared storage | The node looks passive, so it looks free |
| Node used for batch, reporting or development | No | Full license for every day of the year | The spare is treated as spare capacity |
| Restore test of a backup on an unlicensed server | Handled by a separate testing right | Nothing, within four tests a year of up to two days each | Teams stretch it to cover switchover drills |
| DR server with no Oracle software installed | Not needed | Nothing until someone installs the software | The install happens during a test and is never removed |
Are planned failover drills covered?
The wording does not settle it. The data recovery document carries a narrow testing right: an unlicensed server, including one in a cloud environment, may run the program up to four times in a calendar year, for no more than two days each time, to test physical copies of backups.
That right is written for restoring backups. A Data Guard switchover drill or a cluster failover test is a different activity, and reasonable people have read its treatment both ways. The clause that counts maintenance downtime suggests that, at best, a planned drill uses up part of the ten periods.
Why should you not settle that question yourself?
An auditor will read any gap in the wording against you. Ask Oracle for written confirmation of how planned drills are treated, keep the reply with your license records, and design the runbook around the conservative reading until you have it.
- Does a planned switchover or failover drill to the designated spare count against the ten 24 hour periods?
- Does the testing right for physical copies of backups extend to a restore performed on the standby hardware?
- Which version and date of the data recovery policy will Oracle apply to our agreement?
- If a cluster has two spares configured, may we choose which one is the designated failover node?
How does a standby in the cloud change the picture?
The failover section of Oracle's document does not mention cloud at all. A standby running in AWS or Azure is counted under Oracle's authorized cloud policy on its vCPUs, with the same edition and options as production. Only the backup testing right names cloud servers explicitly.
Oracle CIO Cost Control Guide
How to govern Oracle licensing, renewals and audits over five years without paying for capacity you do not use.
Get the white paper →Does an Oracle Data Guard standby need its own license?
Yes, in almost every real configuration. A physical standby keeps its own copy of the data on its own storage, so it fails the shared storage condition before any other test applies. Oracle's document says that in copying, synchronizing and mirroring setups every program installed or running must be licensed under standard policy.
Why does an idle standby still count?
The trigger is installation and capability. Software installed on a server that can run it is licensable, which is why a standby sitting in mount mode, applying redo and serving no users, still counts. The node being idle changes nothing about the position.
The same logic applies to storage replication. If array replication copies the Oracle home to a DR server that can mount it and start an instance, count that server as installed when you reconcile your own records.
Which options does the standby need?
A standby applying redo needs the same edition license as the primary, and Data Guard itself is included in Enterprise Edition. If the primary runs a priced option such as Partitioning, the standby carries those objects block for block and needs the option too. Oracle's document goes further and requires license metrics and program options to match on both servers.
- One exception for Real Application Clusters. The policy names two exceptions to the matching rule. RAC is not needed on the recovery server unless it is used there, and the other exception applies only to production licensed through certain Oracle cloud database services.
- Same metric. If production is licensed by Named User Plus, so is the standby, and the Enterprise Edition minimum of 25 Named User Plus per processor applies to the standby's own hardware.
- Active Data Guard. Opening the standby for queries while redo apply runs adds a separate option that is licensed on the primary as well. Our active standby guide works through that line, and the replication technology is documented on the Data Guard product pages.
What does a standby cost at list price?
Say production runs on a two socket Intel server with 24 cores in total and uses Partitioning and Advanced Compression. At Oracle's 0.5 core factor, 24 cores count as 12 processors. The standby sits on identical hardware at a second site, so the failover rule never applies.
| Line | Calculation | License | Annual support at 22 percent |
|---|---|---|---|
| Database Enterprise Edition | 12 x $47,500 | $570,000 | $125,400 |
| Partitioning | 12 x $11,500 | $138,000 | $30,360 |
| Advanced Compression | 12 x $11,500 | $138,000 | $30,360 |
| Standby total | $846,000 | $186,120 |
A discount lowers every line by a similar share, so the proportions hold at any negotiated price, and the two option lines come to $276,000 of license and $60,720 a year of support. Those are the lines that go missing when the standby is licensed as a bare database. Check current figures against the price list before you budget.
What have we seen in Oracle disaster recovery reviews?
Across roughly 30 to 40 Oracle environments I reviewed in 2024 and 2025, disaster recovery was the most misunderstood area of the licensing. The most common single finding was a fully replicated standby treated as exempt. Four patterns recurred.
- Unlicensed standby. In about 6 out of 10 environments the standby or mirror site carried no license at all, on the belief that disaster recovery is free.
- Drills under the concession. Teams stretched the failover rule to cover routine drills, which the wording does not clearly allow and which no one had confirmed with Oracle in writing.
- Shared storage failed. Where the concession did apply on paper, the cluster failed the shared storage condition, so the relief was never available.
- Options left off. In 7 environments the standby was licensed for the database but not for the options on it, usually partitioned or otherwise optioned objects that had never been entitled separately.
The unlicensed standby is the large, expensive finding. The options gap is smaller and was budgeted by no one, and it survives the first remediation because everybody fixes the database line and stops.
Disaster recovery is where Oracle licensing costs the most money for the least deliberate reason.
Why we reject the idea that a standby site is free
The usual advice is that disaster recovery falls under the failover concession, so a standby site costs nothing, and we disagree. The concession covers one node in one cluster in one data center, for ten periods a year. A second site fails it on location, and a replicated standby fails it on storage.
The better course is to classify every recovery node against the six conditions, license the ones that fail, get the drills treatment in writing and reconcile the standby's options against the primary. Our Oracle practice runs that classification before an auditor opens the question.
What evidence closes an Oracle DR licensing question early?
A configuration record that answers each condition before anyone asks. The conditions are objective, so you can assemble the evidence once and keep it current as the design changes.
Which four records should you be able to produce on request?
| Record | What it proves | Where it comes from |
|---|---|---|
| Storage topology | Which nodes attach to the same array, and in which data center | The storage team's array and zoning documentation |
| Spare node count | That each cluster has one designated spare | The cluster manager's node list, such as olsnodes for Oracle Clusterware |
| Whole day log | Every 24 hour period a spare ran production, counted as whole periods | Instance startup entries in the database alert log and the cluster's failover events |
| Option inventory | The options on each standby against the primary | DBA_FEATURE_USAGE_STATISTICS on the primary, plus the role and open mode in V$DATABASE on each standby |
A physical standby's data dictionary is a copy of the primary's, so the primary's feature usage history is the best record of which options production uses and the standby must match. Review it the way you would review the feature usage report before any audit script runs.
How do you match your design to Oracle's published names?
The architecture is public. Oracle documents the configurations on the high availability pages, and the licensing treatment of each feature in the Oracle Database 19c edition of the licensing information manual. With each node described in Oracle's own terms, any disagreement is about published text, which is easier to settle.
What will Oracle say, and how should you answer?
- "The standby has been installed since the site was built, so it has needed a license since then." Agree with the principle, then check the install dates in your own change records before accepting any backdated support charge.
- "Every option used on the primary is required on the standby." The policy supports that, with the RAC exception. Ask for usage per option on the primary with first and last usage dates, and challenge anything triggered only by a default setting, because an option that production does not need is one the standby does not need either.
- "Your drills exceeded the ten day allowance." Produce your day log and ask which dates Oracle is counting, and from what evidence.
- "A wider agreement would cover the DR servers." Price the DR gap on its own first, so you know what the larger deal is replacing.
Which mistakes cost the most?
- Calling a second site's server the spare. It fails the single data center condition, so the full license was owed from installation.
- Running reports on the spare while it waits. One reporting job makes the node licensable for every day of the year.
- Patching through the spare every month. Twelve maintenance windows exceed the ten periods on their own.
- Building the standby on a shared virtualization cluster. Oracle's partitioning position counts every host the standby could run on, so the DR bill can exceed production's. The virtualization guide covers the containment options.
- Buying standby licenses on a different metric. Named User Plus on production and processor on the standby, or the reverse, breaks the matching rule even when the counts look generous.
What to do next
- Classify every recovery node against the six conditions. The concession covers one node in one cluster in one data center, so list each standby, mirror and spare and mark which condition it fails.
- Check the storage topology first. It is the quickest test to run, and it settles the status of most standbys and mirrors in one pass.
- Keep a whole day log for every spare. Any part of a 24 hour period counts in full against the published ten, and maintenance windows count too.
- Get the treatment of planned drills confirmed in writing. Design the runbook around the conservative reading until that reply exists.
- Reconcile the option inventory on the standby against the primary. Match the metric as well, including the Named User Plus minimum on the standby hardware, and leave RAC off the standby only if it is never used there.
- Assemble the configuration record before it is requested. The Oracle practice can build it with you and price any gap before Oracle does.
Frequently asked questions
Is Oracle disaster recovery free?
No. Oracle licenses software that is installed or running, and the only relief is the failover rule for one spare node. In about 6 out of 10 environments we reviewed, the standby or mirror site carried no license at all because the team had assumed recovery servers were exempt.
What does Oracle's failover rule cover, and which conditions apply?
One otherwise unlicensed node in a cluster that shares a single logical disk array in one data center, running the database while the primary is down. It must be the only spare counted in that cluster. Once the primary is repaired, the workload goes back or the repaired server becomes the designated spare.
How many days does Oracle's failover allowance give you?
Ten separate 24 hour periods in a calendar year. Any part of a period counts as a whole one, so a spare that starts up for 20 minutes on ten different days has used the entire allowance, and a planned maintenance window uses a period just as an outage does.
Does an idle or replicated Data Guard standby need a license?
Yes. A mounted standby that serves no users is still installed software on a server that can run it. A replicated standby also fails the shared storage condition, because it holds its own copy of the data, so the failover rule does not reach it however rarely it is opened.
Are DR drills covered by Oracle's failover or testing rules?
Not clearly. The testing right is written for restoring physical copies of backups, up to four times a year for two days each. Switchover drills are a different activity. Ask your account team for written confirmation and plan the drill calendar around the stricter reading until the reply arrives.
Does the standby need the same options as the primary?
Yes. Oracle's data recovery policy says program options and license metrics on production and recovery servers must match. Real Application Clusters is the exception for most buyers: it is not required on the recovery server unless it is used there. In our reviews the options gap outlasted the first round of fixes.
Is Oracle's data recovery policy binding?
It is a policy document outside your contract, and Oracle states it may not be incorporated into any contract. The wording has been revised more than once, so note the version date you relied on and read it against your ordering documents, which are what your agreement is measured by.
What records should we keep to prove our Oracle DR licensing?
A configuration record kept current: the storage topology, the spare count per cluster, a whole day log of every period a spare ran, and the standby's option inventory against the primary. Assemble it before an audit starts, because rebuilding failover history from old logs after the request arrives is slow and invites dispute over missing dates.