Editorial photograph illustrating Oracle / Disaster Recovery advisory work
Oracle / Disaster Recovery

Oracle disaster recovery licensing. The standby question.

Oracle gives one narrow break for disaster recovery, and a replicated standby is not it. Here is the boundary, the option parity rule, and the evidence that closes the question before an auditor opens it.

Contact Us Oracle Practice
500+Enterprise clients
$2B+Under advisory
Industry Recognized
500+ Enterprise Clients
$2B+ Under Advisory
11 Vendor Practices
100% Buyer Side Independent

Oracle's failover concession is narrow. One spare node, shared storage, a limited number of separate days a year, and only for failover. A replicated standby running Data Guard is a deployment in its own right, and it is licensable from the day the binaries are installed.

Key takeaways

  • The failover concession covers one otherwise unlicensed node in a cluster on shared storage, for a limited number of separate days per calendar year, and Oracle's published figure is ten.
  • Any part of a day counts as a whole day, and the allowance is for failover, never for reporting, load balancing or capacity.
  • A Data Guard physical standby is licensable even when it is only mounted and applying redo, because the software is installed and can run.
  • Every option licensed on the primary must be licensed on the standby, including Partitioning, Advanced Security and Advanced Compression where redo transport compression is on.
  • Active Data Guard is a separately priced option and you only need it when the standby is open read only while redo is being applied.
  • A cold backup that is never mounted or opened needs no license, and the license attaches the moment you restore and open it.
  • Data Guard is an Enterprise Edition feature, and Standard Edition 2 has included no form of Real Application Clusters since 19c.
  • In an authorized cloud the vCPU rule replaces the core factor table, and Oracle Cloud Infrastructure is not an authorized cloud environment and uses its own ratios.

Disaster recovery is where Oracle licensing costs the most money for the least deliberate reason. Nobody sets out to buy a second full set of licenses, and almost nobody plans to be told they already needed one.

This guide separates the four recovery patterns Oracle treats differently, sets the boundary on each, and shows what evidence closes the question before an auditor opens it.

What is the Oracle failover concession, and how narrow is it?

It is a single, tightly conditioned allowance for unplanned failover inside one cluster. It is not a disaster recovery exemption, and reading it as one is the most expensive mistake in this subject.

How it works

When production fails, Oracle permits one otherwise unlicensed node in the same cluster to run the database for a limited number of separate days in a calendar year. Oracle's published figure is ten, set out in the Oracle Software Investment Guide.

Read the current version of that document against your own ordering documents before you rely on it. Policy documents are not contracts, and the wording has been revised more than once.

The conditions that must all hold at once

  • Shared storage: the failover node and the production node must attach to the same disk array. A node with its own copy of the data is not a failover node.
  • One node: only a single spare node in the cluster qualifies, however many spares are configured.
  • Whole day counting: any part of a day the node runs Oracle counts as a full day against the allowance.
  • Failover only: the node runs because production failed, not because you wanted somewhere to run reports.
  • Return to normal: when the primary is back, the workload comes off the spare node.

Where the concession stops applying

Past the annual allowance, the failover node needs a full license for the database and for every option running on it. The concession is also silent on a number of things buyers assume it covers.

It does not cover a second site. It does not cover a standby copy. It does not cover a node used for batch, reporting, development or load balancing on any day of the year.

The testing question nobody gives you a straight answer on

Oracle's guide also carries a narrow backup testing provision, commonly read as permitting a small number of short tests a year on an unlicensed machine for the purpose of testing physical copies of backups. The published wording is short and the treatment of planned failover drills has been read both ways by reasonable people.

Do not resolve that ambiguity in your own favour in a slide. Ask your Oracle contact to confirm the treatment of planned drills in writing, keep the reply, and design the runbook around the conservative reading until you have it.

Does a Data Guard standby need its own license?

Yes, in almost every real configuration. A standby holds its own copy of the data on its own storage, so it fails the shared storage condition before you get to any other test.

The licensing trigger is installation and capability, not activity. Oracle's position is that software installed on a server that can run it is licensable, which is why a standby sitting quietly in mount mode still counts.

Physical standby, mounted and applying redo

A Data Guard standby in mount mode with redo apply running needs the same Enterprise Edition license as the primary. Data Guard itself is included in Enterprise Edition, so there is no separate Data Guard line to buy.

What people miss is the options. If the primary runs Partitioning, the standby carries the partitioned objects and needs Partitioning too. See our Active Data Guard licensing guide for where the extra option line begins.

When you need Active Data Guard, and when you do not

Active Data Guard is a separately priced option, and you need it when the standby is open read only while redo apply is running. A standby that is only ever mounted does not need it.

  • Mounted, redo applying, never opened: Enterprise Edition and the matching options. No Active Data Guard.
  • Open read only with apply running: Active Data Guard on the standby. The tell is OPEN_MODE showing READ ONLY WITH APPLY.
  • Open read only with apply stopped: permitted without the option, and this is the configuration teams forget they moved away from.
  • Far sync instances, DML redirection, automatic block repair: treat these as Active Data Guard functionality and check the manual before you enable any of them.
  • Snapshot standby for testing: converts the standby to read write and relies on Flashback Database, which is Enterprise Edition, but the standby is fully licensable while it runs.

Array based replication and remote mirrors

Storage replication that copies the database files to a remote site needs a full license at the target, because Oracle software is installed there and can be started against those files. Oracle outlines the supported designs on its high availability page.

The one genuinely arguable case is a target where no Oracle binaries exist at all, so the copy cannot be opened without an installation first. That is a defensible position, and it is also a position you have to be able to prove with a build record.

The option parity rule that produces the second invoice

Match the standby line by line against the primary. A standby licensed for the database engine alone is a partial answer, and partial answers are what audit letters are built from.

Oracle recovery patterns and what each one needs

Recovery patternDatabase licenseOptionsConcession available
Clustered failover node, shared storageCovered while the conditions holdConfirm in writing before you rely on itYes, limited days per year
Physical standby, mounted, redo applyFull Enterprise EditionEvery option on the primaryNone
Standby open read only with applyFull Enterprise EditionOptions plus Active Data GuardNone
Array based remote mirror with binaries presentFull Enterprise EditionEvery option on the primaryNone
Cold backup files, no binaries, never openedNoneNoneBackup treatment
Restored and opened for any purposeFull Enterprise EditionEvery option usedNone
Cover of the Redress Compliance Oracle white paper

White Paper · Oracle

Oracle CIO Complete Playbook

The five year plan to control Oracle spend. Read it free.

Read the white paper
Put your own numbers on this. The free Oracle calculator prices your processor vs Named User Plus position, VMware cluster exposure, Java SE employee tiers, and the 22 percent support line, then hands you a two page executive summary you can forward to your CFO. No account, no sales call. Run the Oracle calculator →

What does an unlicensed standby actually cost?

It costs the same as the primary, plus support, plus back support for every year the standby has existed. That last clause is the one that turns a design decision into a board conversation.

A two socket standby, priced line by line

Take a single standby server with two sockets and eight cores per socket, running Enterprise Edition with Partitioning and Advanced Security, mirroring a primary of the same shape.

Line Arithmetic Result
Cores on the standby2 sockets x 8 cores16 cores
Core factor appliedIntel Xeon at 0.58 Processor licenses
Enterprise Edition at list8 x $47,500$380,000
Partitioning at list8 x $11,500$92,000
Advanced Security at list8 x $15,000$120,000
License subtotal$380,000 + $92,000 + $120,000$592,000
Support, one year at 22 percent$592,000 x 0.22$130,240
Three years of back support$130,240 x 3$390,720
Exposure as first presented$592,000 + $390,720$982,720

List prices from the Oracle Technology Global Price List, before discount. Substitute your own option mix and core factor. The point is the shape of the number, not the exact figure.

Nothing in that column is unusual. It is one server, one design decision, and a support line that compounds quietly for as long as the design stays undocumented.

Where the standby sits changes the arithmetic

Put the standby in a public cloud and the counting rule changes with it. In an authorized cloud environment Oracle applies a vCPU based rule and the Processor Core Factor Table does not apply.

Oracle Cloud Infrastructure is not an authorized cloud environment. It has its own conversion rules, so do not carry an AWS or Azure calculation across to an OCI standby and assume it holds.

How do backups and DR testing affect licensing?

Backups are free until you open them, and testing is where teams trip. The line is whether Oracle software runs against the data, not whether the data exists.

Cold backups and what keeps them cold

A backup that is never mounted or opened does not need a license. The moment you recover and open it for use, it does. Oracle confirms the boundary in the Oracle Database Licensing Information manual.

  • RMAN backup pieces on disk, tape or object storage carry no license by themselves.
  • A standby that is only a file copy target, with no Oracle installation, is closer to a backup than to a standby.
  • Installing the binaries on the recovery host to shorten recovery time is the moment the position changes.
  • An automated recovery test that opens the database is a running deployment for the duration.

Drills, and how to run one without creating a finding

A planned drill runs Oracle software on the target, so treat the target as licensable for the duration unless you hold written confirmation otherwise. Where the drill runs on an already licensed standby, there is no incremental question at all.

That is the cheapest fix available in this subject. Run the drill on the licensed standby rather than on an unlicensed spare, and the argument disappears.

How do you evidence a DR configuration before Oracle asks?

You evidence it with four artefacts: a topology map, a dated database role extract, a storage relationship record, and a failover log. Together they answer every question an auditor can ask about recovery in a single folder.

The extract to take from every database

Run this on the primary and on every standby, keep the output with a date and a hostname, and refresh it quarterly.

SELECT name, db_unique_name, database_role, open_mode,
       protection_mode, switchover_status, log_mode
  FROM v$database;

SELECT dest_id, dest_name, status, target, type, database_mode
  FROM v$archive_dest_status
 WHERE status != 'INACTIVE';

DATABASE_ROLE tells you what the instance thinks it is. OPEN_MODE is the column that decides whether Active Data Guard is in play, and the value to look for is READ ONLY WITH APPLY.

The feature usage row that settles the Active Data Guard argument

The feature usage view carries an Active Data Guard row, and it is dated. Pull it on the standby before anyone else does, because it will be read as the record of whether you ever opened the standby with apply running.

If the row shows use that stopped years ago, that is a closed historic event and it should be argued as one. If it shows current use, the option is a budget line, not a debate.

The failover log that protects the concession

A concession you cannot evidence is a concession you do not have. Keep a single register, one row per event, and review it annually against the allowance.

  1. Date and time the workload moved, and the date and time it moved back.
  2. Which node ran, with its hostname and its cluster membership at the time.
  3. Whether the event was unplanned failover, a planned drill, or a maintenance switchover.
  4. The incident reference and the person who authorised the move.
  5. The running total of days used against the allowance for that calendar year.

Proving the shared storage condition

Shared storage is a factual question with a documentary answer. Keep the array mapping, the cluster node list and the disk group configuration together, dated, and signed off by whoever runs the storage.

In several of our reviews the DBA team believed the storage was shared and the storage team knew that it was not. Two teams, one assumption, and a license position that did not survive the first question.

Editorial photograph of an infrastructure team reviewing a disaster recovery topology diagram on a wall display
The concession applies only to a clustered failover node on shared storage. A replicated standby or remote mirror is a separate deployment and carries a full Oracle license, options included.
36
Oracle estates reviewed 2024 to 2025
61%
Recovery sites found underlicensed
7
Estates licensed for the engine but not the options

Source: Redress Compliance advisory engagement file, 2024 to 2025.

Nobody buys a standby. They design one, and the license arrives three years later with interest attached.

Where the common advice on Oracle disaster recovery licensing is wrong

The common advice is that the failover concession makes most disaster recovery effectively free, so teams build a recovery site and assume no license cost. We disagree, and the evidence is not close. In roughly 6 out of 10 estates we reviewed, the concession did not even apply, because the design used a separate standby copy or failed the shared storage condition, so the site was unlicensed and exposed. The buyer side move is to classify every recovery component against the actual wording before you call any of it free, then buy the standby licenses inside a renewal where you have leverage rather than inside a compliance settlement where you have none.

What buyer side moves keep DR compliant and cheap?

Four moves remove most of the risk, and three of them cost nothing. The fourth is a commercial decision you want to make on your own timetable.

Move one. Classify every recovery component

Label each node as clustered failover, standby, mirror, or backup, and write the label on the topology diagram. The label sets the license rule, and an unlabelled node defaults to the expensive answer.

Move two. Verify the shared storage condition with the storage team

Confirm in writing that the failover node shares storage with production. If it does not, the concession does not apply and the node is a licensed node from the day it was built.

Move three. Track failover days and drill days separately

Log every event with a date, a node and a reason, and keep the two categories apart. A single register that mixes drills with failovers destroys the evidence value of both.

Move four. Buy the standby inside a renewal, not inside a settlement

If you know the standby needs licensing, put it on the next order rather than waiting to be told. The same product bought as a planned purchase and bought as a compliance remedy are two very different conversations.

Ask for the standby quantity to be named on the ordering document, ask for the option lines to match the primary explicitly, and ask how the support base will be recalculated. Silence on any of those three is where next year's surprise lives.

What should a buyer do next?

  1. Map every recovery node and its storage relationship to production, and date the map.
  2. Classify each node as failover, standby, mirror, or backup, and write the classification down.
  3. Run the database role extract above on the primary and every standby, and keep the output.
  4. Check OPEN_MODE on every standby, and check the feature usage row for Active Data Guard.
  5. Reconcile the option lines on the standby against the option lines on the primary, one by one.
  6. Confirm the shared storage condition with the storage team, in writing, for any failover claim.
  7. Start the failover register, and set a calendar reminder to review it annually.
  8. Separate drills from failovers in the runbook, and run drills on licensed hardware.
  9. Engage independent Oracle advisory before the next audit letter, not after it.
Need help? Try our AI agents. Ask the Oracle licensing AI agent → Scoped to one vendor and one problem. Runs in your browser.

Frequently asked questions

What is the Oracle ten day rule for disaster recovery?

It lets one otherwise unlicensed node in a cluster run Oracle during failover for a limited number of separate days per calendar year, published by Oracle as ten. The failover node must share storage with production, and any part of a day counts as a full day.

Does a Data Guard standby qualify for the failover concession?

No. A Data Guard standby is a separate copy of the database on its own storage, so it fails the shared storage condition. It must be fully licensed for Enterprise Edition and every matching option, with no relief.

Do I need Active Data Guard for a standby?

Only when the standby is open read only while redo apply is running. A standby that stays in mount mode with apply running needs Enterprise Edition and the primary's options, but not the Active Data Guard option.

Does a standby need the same options as the primary?

Yes. Partitioning, Advanced Security, Advanced Compression and the rest apply on the standby wherever the data or the configuration uses them. A standby licensed for the engine alone is the most common partial finding we see.

Do I need to license a remote storage mirror?

Yes, where Oracle software is installed at the target and could be started against the replicated files. The replication technology does not change the position, and the only arguable case is a target with no Oracle installation at all.

Are cold backups licensable?

A backup that is never mounted or opened does not need a license. The moment you restore and open it for use, it becomes a running deployment and needs a full license like any other.

Does a disaster recovery drill use up the failover allowance?

Oracle's published wording is short on this point and has been read both ways, so get the treatment confirmed in writing. The safe design is to run drills on already licensed hardware, which removes the question entirely.

Can I use Standard Edition 2 for the recovery site?

Not as a Data Guard standby for an Enterprise Edition primary, because Data Guard is an Enterprise Edition feature and editions cannot be mixed that way. Standard Edition 2 has also included no form of Real Application Clusters since 19c, so cluster based designs need a rethink.

How does cloud change disaster recovery licensing?

In an authorized cloud environment Oracle counts vCPUs under its cloud policy and the Processor Core Factor Table does not apply. Oracle Cloud Infrastructure is not an authorized cloud environment and uses its own ratios, so never carry an AWS or Azure calculation across to OCI.

How do I prove I stayed inside the failover allowance?

Keep a failover register with dates, node names, incident references and the running annual total. A dated log maintained before the audit is worth more than any reconstruction afterwards.

White Paper · Oracle

Control Oracle spend: the 5-year CIO playbook.

The governance, renewal and negotiation moves that hold Oracle cost across a five year horizon.

Used across more than five hundred enterprise engagements. Independent. Buyer side. Built for procurement leaders running the next renewal cycle.

Get the white paper →
Opens the white paper landing page. We only email you about this download.
Run the Oracle Java license calculator against your estate in under five minutes.
Open the Tool →
Pass it on

Know someone facing this exact decision?

Send this to whoever owns the renewal, the audit response, or the budget. It takes two clicks and it saves them a quarter of guessing.

Share on LinkedInShare by email