Contents
Key takeawaysThe six builds comparedWhich build to chooseOracle price versus OpenJDKWhat breaks in migrationJava that stays on Oracle JDKWhat we have seenOracle's lines and your repliesSupport contract termsWhat to do nextFAQEvery credible alternative to Oracle Java compiles from the same OpenJDK source and passes the same compatibility tests. Compatibility is rarely the question. Choose which vendor holds your security patch calendar, and plan around the JVMs that cannot move.
- Six certified builds. Temurin, Corretto, Zulu, Red Hat's build, the Microsoft Build and Liberica all pass the Java SE TCK that Oracle JDK passes.
- Choose by existing vendor. Corretto on AWS, the Microsoft Build on Azure, Red Hat's build on RHEL, Temurin where no tie exists, and Azul for Java 6 and 7.
- The price gap is wide. In our worked example a certified free build with support on production only cost about 5 percent of Oracle's per employee quote.
- Most failures are configuration. Startup flags, fonts, Java Web Start and monitoring agents cause most failures, and each is usually fixed within hours.
- Some JVMs must stay. WebLogic, Enterprise Manager and Oracle packaged applications are certified on Oracle JDK and remain covered by their product licenses.
- The free Oracle route has dates. JDK 21 left the No Fee Terms in September 2026, and JDK 25 is planned to stay free until September 2028.
Which OpenJDK builds can replace Oracle Java?
Six mainstream builds can replace Oracle JDK: Eclipse Temurin, Amazon Corretto, Azul Zulu, the Red Hat build of OpenJDK, the Microsoft Build of OpenJDK and BellSoft Liberica. All six compile from the same upstream OpenJDK source and pass the Java SE Technology Compatibility Kit, as Oracle JDK does.
That certification, whichever brand is on the binary, is what an application vendor's support desk can be held to. The free builds are not unsupported builds either. Corretto, Temurin, Liberica and the Microsoft Build all ship the quarterly Critical Patch Update backports, usually inside 72 hours of Oracle's own release.
| Distribution | Vendor | Cost | Paid support route | Best for |
|---|---|---|---|---|
| Eclipse Temurin | Eclipse Foundation | Free | Contracted through partner companies | The neutral default, no vendor tie |
| Amazon Corretto | AWS | Free | Included in an existing AWS Support plan | Companies that run mostly on AWS |
| Azul Zulu | Azul | Free build | Paid Azul support contract | Legacy versions and audit grade support |
| Red Hat build of OpenJDK | Red Hat | Bundled with RHEL | Covered by the RHEL subscription | RHEL servers and FIPS requirements |
| Microsoft Build of OpenJDK | Microsoft | Free on supported releases | Azure support plans, for workloads on Azure | Companies that run mostly on Azure |
| BellSoft Liberica | BellSoft | Free build | Tiered commercial support | JavaFX, embedded devices and small containers |
How long does each vendor keep patching Java 8, 17 and 21?
Support windows differ more than the binaries do, and they set how often you must upgrade. The dates below are from each vendor's published roadmap in September 2026. Vendors extend them, so confirm before you sign.
| Build | Java 8 | Java 17 | Java 21 |
|---|---|---|---|
| Eclipse Temurin | At least December 2030 | At least October 2027 | At least December 2029 |
| Amazon Corretto | December 2030 | October 2029 | October 2030 |
| Azul Zulu (paid) | December 2030 | September 2029 | September 2031 |
| Red Hat build of OpenJDK | Full support to November 30, 2026, extended to December 2032 | Full support to December 2027, extended to January 2029 | Full support to December 2029, extended to September 2031 |
| Microsoft Build of OpenJDK | No Java 8 build | September 2027 | September 2028 |
| BellSoft Liberica (paid) | March 2031 | March 2030 | March 2032 |
Two details in that table catch buyers out. Microsoft does not build Java 8 at all and points those users to Temurin. Red Hat's full support for Java 8 ends on November 30, 2026, so RHEL shops still on Java 8 need to budget for the extended lifecycle add on or plan an upgrade.
How to Negotiate the Oracle Java Employee Agreement: Honest Leverage in a Captive Deal
Which OpenJDK build should you choose?
Pick the build whose vendor already owns something else in your stack. That rule resolves most decisions, because it puts the Java security backport calendar inside a support relationship you already manage and already pay for.
- Amazon Corretto for AWS. AWS states that an existing AWS Support plan covers Corretto on the same basis as its other services. There is no separate Corretto contract to buy.
- Microsoft Build for Azure. Commercial support is limited to customers with an Azure support plan running Java on Azure, Azure Stack or Azure Arc, and only while they stay on the latest quarterly update.
- Red Hat build where RHEL runs. OpenJDK entitlements are included in the RHEL subscription, and the build works with RHEL's FIPS mode. Java on Windows needs a separate OpenJDK subscription unless it runs with Red Hat middleware.
- Temurin as the neutral default. Use it where no vendor tie exists, and wrap commercial support around it where a workload needs a 2am escalation path.
- Azul Zulu for retired versions. Azul is the closest commercial analog to Oracle's own offering. Its Legacy Production Support option covers Java 6 and 7 through December 2029, though builds in that period are not TCK tested. That matters when a 2011 application cannot be decommissioned before 2028.
- Liberica for desktop and small footprints. Its Full edition bundles JavaFX for desktop applications, and BellSoft ships builds for ARM devices and minimal container images.
The head to head on the commercial analog is in our Azul Zulu comparison. If you are still deciding whether to leave Oracle at all, start with the six options beyond Oracle JDK, two of which need no runtime change.
When does running two builds make sense?
Two builds are reasonable when workloads split cleanly, for example Corretto on AWS and Temurin in your own data centers. Each extra build adds a patch calendar and a set of base images to maintain, so stop at two unless Java 6 forces a third.
Java SE renewal exit brief
How to choose a build, plan the waves and keep audit exposure closed while you leave the Oracle subscription.
Get the white paper →How does Oracle's per employee price compare with an OpenJDK build?
Oracle prices the whole organization, and an OpenJDK build prices only the servers you choose to support. Since January 23, 2023, the Java SE Universal Subscription has counted every employee, and for most enterprises that raised the Java bill three to five times.
The metric captures full time, part time and temporary staff, plus agents, contractors and outsourcer personnel who support internal operations. Finance staff who never open a JVM are counted the same as developers.
- Rate. Pricing starts at $15 per employee per month at the smallest tier and steps down by band. Oracle's published tiers go as low as $5.25, and it says pricing can be lower above 50,000 employees.
- Usage does not matter. A company running 40 JVMs and one running 4,000 JVMs pay the same if their headcount is the same.
- Growth is billed automatically. Acquisitions, insourcing and changes to your outsourcing model all raise the counted population at the next true up without a single new Java install.
The band arithmetic is set out in our employee tier pricing analysis. How contractors end up in the count is covered in contractor and outsourcer headcount.
Worked example: 25,000 staff running 800 Java instances
A manufacturer with 25,000 badged employees ran Java in about 800 instances and paid roughly $850,000 a year on the legacy processor metric. Once contractors and outsourcer staff were included, the per employee count reached near 55,000.
| Option | Annual cost | Cost per instance per year |
|---|---|---|
| Legacy processor licenses (what they paid) | $850,000 | $1,062.50 |
| Universal Subscription quote at about 55,000 counted | $4.45M | $5,562.50 |
| Free certified build, paid support on production only | $240,000 | $300 |
Divide the numbers and three findings stand out.
- The band. The quote works out at about $6.74 per employee per month ($4,450,000 divided by 55,000, divided by 12). That matches the $6.75 list rate for 20,000 to 29,999 employees, yet a count of 55,000 sits above the $5.25 band for 40,000 to 49,999. Check which band a quote uses before you negotiate anything else.
- The contractors. About 30,000 of the 55,000 counted people held no company badge, so more than half the quote priced contractors and outsourcer staff.
- The gap. The $240,000 alternative is about 28 percent of what the company already paid and about 5 percent of the quote, before the one time migration project is costed in.
What breaks when you move from Oracle JDK to OpenJDK?
The application almost never breaks. Applications ran unchanged on the same long term support line in roughly nine of ten migrations, and about nine in ten failures came from configuration, fixed in hours. The usual causes:
- Startup flags. Start scripts carry Oracle specific options, such as the commercial features flag once used to enable Flight Recorder on Oracle JDK 8. Some OpenJDK builds reject these and the JVM does not start.
- Fonts. Oracle JDK 8 shipped its own fonts. OpenJDK builds rely on the operating system's fonts, so a headless server can render reports and PDFs with substitute fonts or fail outright.
- Java Web Start. Oracle JDK 8 included it and the OpenJDK builds do not. Desktop applications launched from JNLP files need an open source replacement such as OpenWebStart.
- Monitoring agents. APM agents are often loaded from paths inside the old JDK directory, or certified only against named JVM vendors and versions.
We also check every wave for certificates imported into Oracle JDK's cacerts truststore. They do not carry over to a new JDK, and outbound TLS calls fail until they are imported again.
Where do the real exceptions sit?
They cluster in desktop Java, reporting engines and vendor packaged stacks. That tenth of the population needs real testing before a migration wave commits it, and packaged software also needs the vendor's written word that the new build is supported. Our compatibility testing guide covers how to scope those tests.
Why we would not run the migration as a development program
The usual advice is to run a Java migration as a development program, with full regression testing of every application and waves ordered by code risk. We think that wastes months, because the failures we see are configuration.
Duration follows change windows instead. A 200 JVM population closes in 6 to 10 weeks, while a 5,000 JVM regulated one runs 12 to 20 months on the same technical work. Schedule it like an operating system patch cycle and save deep testing for the exception clusters.
Which Java workloads should stay on Oracle JDK?
JVMs inside Oracle product stacks should stay. WebLogic, Oracle Enterprise Manager and the Oracle packaged applications are certified on Oracle JDK, and moving them to Temurin or any other build loses Oracle product support, not just Java support.
Those JVMs remain covered by the products' own licenses, so they do not need a Java SE subscription. Inventory them and exclude them on day one, then migrate everything else around them. Our note on restricted use entitlements explains which Oracle products carry these rights.
What does a paid non Oracle support contract cover?
It covers the Java runtime only. Buyers routinely assume more, so read the scope before you rely on it:
- It does not extend your ISV certifications. The application vendor still decides which builds it supports.
- It does not patch CVEs in the third party libraries your applications bundle, such as logging or XML libraries.
- It does not replace Oracle product support for anything running on WebLogic or other Oracle middleware.
Is Oracle JDK still free under the No Fee Terms and Conditions?
Oracle JDK is free for production only on the current LTS release, and only for a limited window. Oracle JDK 21 updates were free under the NFTC until September 2026, one year after JDK 25 shipped. Updates released after that come under the OTN license, which does not allow production use without a subscription.
JDK 25 is now the free release, planned to stay under the NFTC until September 2028. Versions already downloaded keep their original license but receive no further patches, so use the NFTC deliberately and diary each expiry date. Our note on JDK 21 updates ending covers what to do if you are on 21 today.
What have we seen in Oracle Java exits in 2024 and 2025?
Across roughly 35 to 45 Oracle Java engagements that I worked through in 2024 and 2025, the migration question came up in nearly every one. Once a certified free build was on the table, the subscription rarely survived a clean cost model.
- Cost. Annual Java cost fell 70 to 92 percent on a free certified build, net of the one time migration project.
- Duration. Full cutover at large enterprises took 9 to 14 months, gated by release governance and pipeline discipline.
- Boundaries. The exits that went cleanly excluded the Oracle certified JVMs on day one and documented every NFTC install with its expiry date.
- Audit timing. The exit period is exactly when Oracle's Java outreach letters tend to arrive, so audit readiness has to hold throughout.
The binding constraint on a Java exit is the number of change windows you get. Code volume barely changes the finish date.
Keep dated removal records for every host as each wave closes. If Oracle asks about historical use, our Java audit defense guide covers how to respond during the exit period, and proof of removal covers the evidence.
What will Oracle say when you plan to leave, and how should you answer?
Expect the account team to question the migration's safety, cost and timing. These are the lines we hear most, with replies that hold up.
| What Oracle says | What to say back |
|---|---|
| "OpenJDK builds are not supported or secure enough for production." | "The build we chose passes the same TCK as Oracle JDK and ships the same quarterly security backports, under a support contract we already hold." |
| "Moving off Oracle JDK will void support for your Oracle products." | "The WebLogic, Enterprise Manager and packaged application JVMs stay on Oracle JDK under their product licenses. Only the rest migrates." |
| "Your contractors and outsourcer staff count as employees." | "Only those who support our internal operations count. Show us the source of your number and which contractor groups you included." |
| "The migration will cost more than the subscription." | "We have modeled it wave by wave. Send a written quote and we will compare it with the project cost line by line." |
If you need Oracle coverage while the waves run, ask for a single 12 month term sized to the exit. The employee metric still applies to that year, so the saving comes from the later years you never commit to.
What should a non Oracle Java support contract include?
A support contract for an OpenJDK build should name the versions, the metric and the patch timing in writing. Ask for these terms before you sign:
- Covered versions and end dates. List every Java version you run, with the support end date for each, so a roadmap change cannot shorten your coverage mid term.
- Patch timing. A stated window for delivering each quarterly security update after the OpenJDK release, and for emergency fixes.
- Metric and scope. Whether you pay per server, per core, per container or a flat fee, and whether test and development systems are included free.
- Response times. Severity one response around the clock for the production systems that need it.
- Renewal price cap. A cap on the renewal increase, and the right to reduce covered systems as applications retire.
Who needs paid support at all?
Buy it for production systems with an external obligation, such as a regulator, an ISV requirement or an internal SLA. Development, test and build servers can run the free build, patched quarterly by your own team. That split is what kept the alternative in the worked example so cheap.
How do you check which Java you run today?
Run "java -version" on each host. Oracle JDK reports "Java(TM) SE Runtime Environment", while OpenJDK builds report "OpenJDK Runtime Environment". In most builds, the "release" file in the Java home directory also names the vendor in its IMPLEMENTOR line.
Our guide to telling Oracle JDK from OpenJDK covers Windows installs, containers and bundled runtimes.
What to do next
- List the JVMs that must stay. Identify every WebLogic, Enterprise Manager and Oracle packaged application runtime, whose migration would lose Oracle product support, and exclude them first.
- Pick the build by existing vendor. Corretto on AWS, the Microsoft Build on Azure, Red Hat's build on RHEL, Temurin where no tie exists, Azul for Java 6 and 7.
- Price the free build against your headcount. Compare Oracle's written quote with the build's support cost for production only, plus the migration project.
- Plan waves by change window. Group systems by release calendar, fix the configuration issues in the first wave, and test the desktop, reporting and packaged exceptions in depth.
- Diary the NFTC dates and keep records. Note the expiry for each Oracle JDK release you still run for free, and keep dated removal evidence as waves close.
- Get help if Oracle is already asking. Our Oracle practice runs the migration and the Oracle negotiation together, for a fixed fee.
Frequently asked questions
Are OpenJDK builds really equivalent to Oracle Java?
Yes, for running applications. Each of the six mainstream builds comes from the same upstream code base as Oracle JDK and is certified against the same Java SE compatibility kit. In nine of ten migrations we reviewed, applications ran unchanged on the same LTS line.
How much does leaving Oracle Java save?
Across the companies we modeled, 70 to 92 percent of annual Java cost, after paying for the one time migration project. In one case a quote of $4.45 million a year under the employee metric compared with $240,000 for a certified free build, with paid support bought for production servers only.
Which OpenJDK build should we choose?
Choose the build from a vendor you already pay. AWS Support plans cover Corretto, Azure support plans cover the Microsoft Build for Azure workloads, and RHEL subscriptions include Red Hat's build. With no such tie, Temurin plus a partner support contract is the usual choice, and Azul fits where Java 6 or 7 must stay supported.
What breaks in a Java migration?
Mostly configuration: Oracle specific startup options, missing fonts on headless servers, Java Web Start launches and monitoring agents tied to the old JDK path. The harder cases are desktop Java, reporting engines and vendor packaged software. Project length follows your change windows, not code volume.
Which JVMs cannot move off Oracle JDK?
Those running Oracle products, including WebLogic, Oracle Enterprise Manager and Oracle packaged applications. Oracle certifies them on its own JDK, so switching builds costs you product support. Their product licenses already cover that Java use, so they need no Java SE subscription.
Is Oracle JDK still free for anyone?
Yes, for the newest LTS release within its No Fee Terms window. JDK 25 is planned to be free under those terms until September 2028. JDK 21 updates after September 2026 fall under the OTN license, which allows development and personal use but not production without a paid subscription.
Does Amazon Corretto cost anything to run outside AWS?
No. Corretto is free to use and distribute on premises and on other clouds under its open source license. Support is the part to check: confirm in writing how your AWS Support plan treats Corretto running outside AWS before you rely on it.