Now openThe whole vendor lifecycle in one workspace. Benchmarking, negotiations, contracts, invoices, renewals. Free 30 day trial, no card.Start the trial →
Now openThe whole vendor lifecycle in one workspace. Benchmarking, negotiations, contracts, invoices, renewals. Free 30 day trial, no card.Start the trial →
Editorial photograph of an enterprise boardroom interior
Oracle Java · Entitlement Proof · Sub

Documenting Which Java Installs Are Already Free or Licensed

Under the employee metric, installs do not drive the bill, but they decide which uses you must never concede to Oracle. This is how you assemble the proof file that keeps NFTC, bundled, and legacy-covered installs out of the paid count.

Contact Us Oracle Hub
500+Enterprise clients
$2B+Under advisory
Industry Recognized
500+ Enterprise Clients
$2B+ Under Advisory
11 Vendor Practices
100% Buyer Side Independent

Under the employee metric, installs do not drive the bill, but they decide which uses you must never concede to Oracle. This is how you assemble the proof file that keeps NFTC, bundled, and legacy-covered installs out of the paid count.

Why the Proof File Exists at All

Since the 2023 Java SE Universal Subscription moved to an employee-based metric, a common misconception has taken hold: that because you now pay per employee rather than per install, the install list no longer matters. That is half right and dangerously so. A high install count does not increase your subscription cost, but every install you fail to attribute to a free or already-licensed basis becomes a data point Oracle uses to argue that your entire population is deployed and therefore should be subscribed. The purpose of the proof file is not to reduce a per-install charge. It is to remove specific installs from the conversation entirely, so they never appear in the paid population that Oracle tries to anchor the employee count against.

In 25 years negotiating Oracle Java positions, the single most expensive error we see is a company buying a subscription for deployments that were already covered, either by the No-Fee Terms and Conditions (NFTC), by bundled restricted-use rights inside another Oracle product, or by a legacy perpetual or subscription entitlement. Redress Compliance's own entitlement reviews consistently identify six-figure overspend from exactly this failure to map deployments to their license basis. The proof file is the artifact that prevents it. It sits alongside your audit-defensible install inventory and your broader Java evidence file, but its focus is narrow: proving a specific install is free or covered.

Installs do not drive the bill. But an undocumented install is an install Oracle counts as deployed, and deployed is the word that anchors your employee number.

The Three Bases That Keep an Install Out of the Paid Count

Every Oracle Java install on your estate falls into one of four categories: paid (subscription required), NFTC-free, bundled restricted-use, or legacy-covered. The proof file exists to move installs out of the first category and into one of the other three, with evidence that survives an audit. Each basis has a different evidentiary standard, and the version-string trap means you cannot prove any of them without full build numbers, not just a marketing version like "Java 8" or "Java 17."

Basis What it covers Proof required in the file Expiry risk
NFTC (No-Fee)Oracle JDK 17 and later, inside the free windowFull build number, install date, capture that build predates the NFTC cutoff for that versionHigh: windows close ~1 year after next LTS ships
OTN / legacy free buildOracle JDK 8 up to 8u202; personal/dev-only use post-8u211Exact build number (8u202 vs 8u211), usage-type evidence (dev vs production)Fixed: 8u202 is free forever, later builds are not
Bundled restricted-useJava used only within WebLogic, EBS, PeopleSoft, JDE, Fusion MiddlewareProduct license, LMS/Support note quoting the bundled grant, proof the Java use stays inside the app boundaryVoided the moment Java runs anything outside the host product
Legacy subscription / perpetualPrior NUP, Processor, or perpetual Java SE Advanced/SuiteOriginal ordering document, renewal proof, entitlement countsRenewal conditional on Oracle usage validation

Proving an Install Is NFTC-Free

The NFTC permits free use of Oracle JDK 17 and later, including commercial and production use, but it expires on a published schedule. JDK 25 shipped in September 2025; versions 21 through 24 remain free under the NFTC until September 2026, after which hosts still running those versions fall outside the no-fee grant. JDK 25 updates are planned to remain under the NFTC until September 2028, roughly one year after Java 29 ships in September 2027, at which point Oracle intends to move JDK 25 updates to the OTN license.

The critical proof point most companies miss is that NFTC coverage is per build, not per version line. For Oracle Java 17, the free-patch window ended in September 2024, and the last no-cost update was 17.0.12.0.2 released in August 2024. Any 17.x build downloaded before that date remains under the NFTC and is documentably free. Any 17.x build after it does not. So your proof file for a Java 17 install must capture the exact build number and, ideally, the download or install date, demonstrating the build predates the cutoff. Our full version-by-version map lives in which Java versions are free, and the free-versus-paid line detail sits in which Java versions trigger a bill.

  • Capture the full build string (for example 17.0.12.0.2), never just "Java 17."
  • Record install or download date to prove the build predates the NFTC cutoff for its version.
  • Flag any host on a version approaching a window close (JDK 21 to 24 by September 2026) as a future liability, not current spend.
  • Keep the Oracle JDK License FAQ text quoting the roadmap dates, dated on capture, so the free window is not just your assertion.

Proving a Legacy Build Is Free (The 8u202 Line)

Java 8 is where the proof file earns its keep, because a Java 8 install reports its version as 1.8 whether it is free or licensable. Only the exact build number answers the question. Oracle JRE 8u202 and earlier remain free for commercial use under the old Binary Code License. From 8u211 onward, the same installer carries the OTN license, free for personal and development use but chargeable for business use. That means two servers that both report "1.8" can have completely different license outcomes, and the only distinguishing evidence is the build number your inventory captured.

A Java 8 install reports 1.8 whether it is free or billable. The build number is the entire case. If you did not capture it, you have no proof, and Oracle knows it.

For post-8u211 builds you claim under OTN as development or personal use, the proof file needs a second layer: evidence of the usage type. A build number alone shows the license, but OTN's free grant is conditional on non-production use. So for those hosts you need to document that the environment is genuinely development or test, not production serving business operations. Combine that with your reconstructed download history so that where Oracle cites its own download logs, you can match a specific download to a specific, documented free build.

Proving Bundled Restricted-Use Rights

Oracle products including WebLogic Server, E-Business Suite, PeopleSoft, JD Edwards, and Fusion Middleware components all include Java SE rights as part of their standard entitlements. But these are restricted-use rights: they cover Java use only within the specific application boundary of the licensed product. WebLogic Server EE, for example, includes a restricted-use license for Oracle Java SE Advanced, and Oracle's own documentation states that Java SE and all associated components are restricted for use with WebLogic Server. This is a real and valuable basis, and it removes a meaningful slice of installs from the paid count, but only if you prove both the entitlement and the boundary.

The trap that voids the bundled defense is that WebLogic and EBS servers are rarely dedicated. They also run scripts, agents, monitoring tools, batch processes, and sometimes standalone Java applications. Every one of those that uses the Oracle JDK sits outside the WebLogic restricted-use right and needs its own Java SE entitlement. So a bundled-rights proof entry is not just "this server runs WebLogic." It is: the product license, the Oracle Licensing Information manual or Support note quoting the bundled grant, and evidence that the Java on that host is used only by the covered product. Keep a snippet on hand such as "a restricted-use license of WebLogic Server Standard Edition is included with product X," because during an audit you may need to demonstrate that Java usage on a server is covered by your EBS or WebLogic license, and Oracle will not volunteer that language for you.

One documented exception is worth flagging in the file: Oracle Coherence uniquely provides a full-use Java SE license, entitling you to use Java SE not just for Coherence but for general purposes. Most bundled grants are restricted-use; Coherence is the outlier. If you hold Coherence, capture that entitlement, because it is materially more valuable than a WebLogic-style restricted grant.

Proving Prior and Legacy Subscription Coverage

Oracle removed NUP and Processor SKUs from its price list, so new Java subscriptions must use the employee-based metric. But organizations with existing legacy subscriptions were grandfathered and may renew under legacy terms, and older perpetual entitlements (Java SE Advanced or Java SE Suite) that some companies still retain do not vanish because Oracle prefers the new model. If you have them, they are leverage, and they belong in the proof file with original ordering documents and entitlement counts.

Two cautions must be documented alongside any legacy claim. First, Oracle's FAQ states legacy customers may renew "subject to confirmation that current usage is reflective of license counts in such existing order," which in practice means Oracle attaches a usage-validation requirement, effectively an audit trigger, to each legacy renewal. Second, that same FAQ is not contractually binding; the renewal right lives in your ordering document, not in a marketing PDF. So your proof file should reference the contract language that grants the right, not the FAQ. The reason this matters commercially is that Gartner reports most clients find the new subscription two to five times more expensive than the legacy model, so a defensible legacy position is often worth more than any single install-level saving.

How the Proof File Interacts With an Audit

The reason to build this file pre-emptively, not during an audit, is that Oracle often has far less evidence than it implies. Download logs are not deployment evidence: a download record shows a binary left Oracle's server, not that it is installed, running, or used for business operations. When Oracle leads with download data, your proof file lets you answer install by install: this build is NFTC-free, this build is 8u202 and free forever, this host is covered by WebLogic, this deployment sits under a legacy subscription. Each answered install is one Oracle cannot fold into the deployed population it uses to justify a headcount subscription.

Keep the proof file organized so that entries are self-contained and legally defensible. Where possible, hold the working analysis under privilege rather than in an open shared drive, following the approach in keeping Java audit records under privilege. And be deliberate about what leaves your organization: the proof file is your internal ammunition, not a data dump for Oracle, so pair it with a clear line on what to provide and what to refuse when Oracle sends a data request.

Download logs prove a binary left Oracle's server. They do not prove deployment. Your proof file is what turns their inference into your evidence.

What to Do Now

  • Inventory with full build numbers. Any tool that reports "Java 8" or "Java 17" without the build string is useless for proof. Rebuild the inventory to capture 17.0.12.0.2, 8u202, 8u211, and equivalents.
  • Tag each install to one of the four bases (paid, NFTC, OTN/legacy-free, bundled, legacy subscription) and file the specific evidence for each non-paid claim.
  • For bundled claims, prove the boundary. Confirm no scripts, agents, or standalone Java run on the covered host outside the product entitlement.
  • For NFTC claims, flag expiry. Any JDK 21 to 24 host is free only until September 2026; treat that as a scheduled decision, not a settled fact.
  • For legacy claims, reference the contract, not the FAQ, and model whether Oracle's renewal validation condition is worth triggering.
  • Hold the file under privilege and decide in advance which fragments, if any, ever reach Oracle.

Done properly, the proof file does not lower a per-install rate, because there is no per-install rate. It does something more valuable: it shrinks the population Oracle can credibly call deployed, and a smaller defended population is the direct lever on your employee count and your bill. Build it before the audit letter arrives, because reconstructing this evidence under a 30-day audit clock is exactly the scenario Oracle counts on.

Frequently asked questions

If the employee metric ignores installs, why document which installs are free?

Because the install list is what Oracle uses to argue your population is deployed, which is the word that justifies subscribing your whole headcount. Documenting free and already-licensed installs removes them from the deployed count Oracle anchors against. It does not change a per-install price, because there is not one; it protects the employee number that actually drives the bill.

Is a Java 17 install free under the NFTC?

Only if the specific build predates the version's NFTC cutoff. For Java 17, the last free build was 17.0.12.0.2 released in August 2024, and any 17.x build after that falls outside the no-fee grant. Your proof file must capture the exact build number and install date, not just "Java 17," or you cannot demonstrate the coverage.

How do I prove a Java 8 install is free?

By the exact build number. Oracle JRE 8u202 and earlier are free for commercial use under the old Binary Code License; 8u211 and later carry the OTN license, free only for personal and development use. Both report as version 1.8, so the build number is the entire case. For post-8u211 builds you must also document non-production usage.

Do my WebLogic or E-Business Suite licenses cover all Java on that server?

No. Bundled Java rights are restricted-use: they cover Java only within the licensed product's boundary. Scripts, agents, monitoring tools, batch jobs, and standalone Java on the same host sit outside the grant and need their own entitlement. Your proof file must show both the bundled right (from an Oracle manual or Support note) and that Java use stays inside the product.

Can I still renew a legacy Processor or NUP Java subscription?

Oracle grandfathered existing legacy subscriptions and permits renewal under legacy terms, but its FAQ attaches a usage-validation condition, effectively an audit trigger, to each renewal. The renewal right lives in your ordering document, not the non-binding FAQ, so reference the contract. Since the new model is typically two to five times more expensive, a defensible legacy position is often worth protecting.

What evidence does Oracle actually have before an audit?

Usually less than it implies. Oracle's download logs show a binary left its server, not that it is installed, running, or used for business. That gap is precisely why a pre-built proof file matters: it lets you answer each install with its license basis and prevent Oracle from converting a download inference into a deployment claim.

Free White Paper

Avoid the Oracle Exadata core license trap

Oracle Exadata can lock you into full core licensing across X9M, X10M, and Cloud at Customer. The buyer side strategy to size the platform and cut the bill.

Gated with a work email on the download page. No sales follow up you did not ask for.

Get the White Paper →
Independent, buyer side. We never share your details with vendors.
Run a software spend health check against your Oracle Java estate in under five minutes.
Open the Tool →
Deep Library

More on this topic.

Oracle Hub →
Building the Java Evidence File: What Records to Keep Before and During an Oracle Audit
Oracle Java · Guide
Building the Java Evidence File: What Records to Keep Before and During an Oracle Audit
The full guide this article belongs to.
Guide
Reconstructing Your Java Download History When Oracle Cites It
Oracle Java · Deep dive
Reconstructing Your Java Download History When Oracle Cites It
Another angle on the same decision.
Guide
Making Your Java Install Inventory Audit-Defensible, Not Just Complete
Oracle Java · Deep dive
Making Your Java Install Inventory Audit-Defensible, Not Just Complete
Another angle on the same decision.
Guide
Which Java versions are free? And which ones bill your whole headcount.
Oracle Java
Which Java versions are free? And which ones bill your whole headcount.
OpenJDK and most vendor builds are free in production. Oracle JDK is free only inside the
Guide
Which Audit Clause Is Oracle Citing? OTN License vs Master Agreement
Oracle Java
Which Audit Clause Is Oracle Citing? OTN License vs Master Agreement
Oracle cites different Java audit clauses depending on your contract vehicle. Compare OTN
Guide
Which Java Versions Are Free and Which Trigger a Bill
Oracle Java
Which Java Versions Are Free and Which Trigger a Bill
Oracle JDK 8u211+, 11, and 17 post-July 2024 bill your whole headcount. OpenJDK is free fo
Guide
Editorial boardroom interior

The advisor your vendors do not want.

500+ enterprise clients. 11 vendor practices. Industry recognized. One conversation can change what you pay for the next three years.

Stay ahead of Oracle licensing changes.

One buyer side briefing a week. Renewal signals, audit moves, and the levers that work. No vendor spin.