Development and test Java stays free under OTN, but a single production host converts the whole estate to an employee-metric bill that priced one Oracle example at $2,268,000 a year
Oracle's OTN license expressly permits internal development, testing, prototyping, and demonstration at no cost, so dev and test installs are not what triggers a subscription. What triggers it is one host that crosses into staging or production, because the Java SE Universal Subscription then prices every employee and contractor, not every install. That asymmetry means your defensive work is boundary control and version control, not counting developer laptops.
Prepared by Redress Compliance · August 29, 2026 · Oracle Java advisory. Audit defense and renewal engagements, 2024 to 2026.
Executive summary
OTN grants exactly four free uses, and Development Use is one of them, covering internal work to develop, test, prototype, and demonstrate your applications.
Oracle's own JDK FAQ repeats the point for JDK 8, 11, and 17: personal use, development, testing, prototyping, and demonstrating are permitted at no cost, so a dev or test install of those versions is not, by itself, a licensable event.
The line Oracle draws is the environment, not the person, and it sits at the edge of staging.
Once an application built under Development Use moves to staging, UAT with real business data, or production, the OTN grant stops and the only priced product available is the Java SE Universal Subscription at $15 per employee per month at list for the 1 to 999 band.
Because the subscription is metered on headcount, one non-compliant production host costs the same as a thousand.
Oracle's published worked example prices 28,000 people (23,000 staff plus 5,000 contractors) at $6.75 per month, which is $2,268,000 per year, and deployment size never enters that formula.
The October 2026 Critical Patch Update is the date that reclassifies estates without anyone signing anything.
JDK 21 updates through September 2026 ship under NFTC, which permits production use free; from the October 2026 CPU onward, JDK 21 updates move to OTN, so a patch pipeline that keeps pulling Oracle builds converts free production hosts into licensable ones.
What OTN actually permits, and where the grant stops
The Oracle Technology Network license for Java SE grants exactly four things, and the list is exhaustive: Personal Use, Development Use, Oracle Approved Product Use, and Oracle Cloud Infrastructure Use.
Everything else is reserved, and Oracle says so in the agreement: all rights not expressly granted are withheld, and any other purpose requires a separate paid license from Oracle or a reseller.
The load-bearing text is the Development Use definition, which reads as "Your internal use of the Programs to develop, test, prototype and demonstrate Your Applications," with "to develop" expressly extended to running profilers, debuggers, and IDE tools where the primary purpose is profiling.
Debugging, and source code editing.
Two words in that sentence carry the audit risk. "Internal" means the grant collapses if the application is built for a customer, hosted for a third party, or distributed outside your organization. "Your Applications" means the code has to be yours, not a vendor's runtime you are merely operating.
Oracle's own JDK FAQ backs the plain reading, confirming that Oracle JDK 17, 11, 8, and JRE 8 under OTN permit personal use, development, testing, prototyping, and demonstrating at no cost.
In 25 years of arguing these clauses, I have never seen Oracle win an argument that a developer laptop running an IDE and a debugger is licensable. I have seen Oracle win, repeatedly, on the host that a team called "UAT" and that real customers were hitting.
| Environment | OTN (Java 8, 11, 17, and JDK 21 from Oct 2026) | NFTC (JDK 21 to Sep 2026, 22 to 25) | Subscription required |
|---|---|---|---|
| Developer workstation, IDE, debugger, profiler | Permitted, free | Permitted, free | No |
| Functional and unit test, CI build agents | Permitted, free | Permitted, free | No |
| Prototype and internal demonstration | Permitted, free | Permitted, free | No |
| Performance or load test mirroring production | Grey. Free only if genuinely testing Your Applications | Permitted, free | Contested |
| Staging or pre-production serving real transactions | Not permitted | Permitted, free | Yes, under OTN |
| Production, disaster recovery, customer-facing | Not permitted | Permitted, free | Yes, under OTN |
| Java running a Schedule A or B product (SQL Developer, EBS, WebLogic) | Permitted for that product's use | Permitted | No |
The Approved Product Use path is the most commonly forfeited free right on this table. Schedule A products, including SQL Developer and OCI agents, may run on Oracle Java SE for any use, and applications developed with Schedule B products such as E-Business Suite, JD Edwards.
And WebLogic may also run for any use.
Organizations buy subscriptions to cover SQL Developer estates that were already free.
The catch is precise, and Oracle states it: the Approved Product Use list is the exclusive list for that definition, and the OTN agreement grants no right to use those products themselves. You still need your EBS or WebLogic entitlement.
What you do not need is a Java subscription layered on top of it. Before you accept any counted install, cross-check it against the restricted-use Java rights you may already hold inside Oracle products, then check the counting logic against the scoping mistakes that inflate exposure.
The version clock: NFTC, OTN, and the September 2026 cliff
The license attaching to a given install is a function of version and patch date, not of environment alone. Two installs of "Java 21" on identical hosts can sit under different agreements if one has taken the October 2026 Critical Patch Update and the other has not.
Oracle introduced the No-Fee Terms and Conditions in September 2021, and NFTC is materially more generous than OTN: it permits free use for all users, including commercial and production use, on any host supporting internal business operations.
That is why version strategy, not environment labelling, is the real cost lever. Moving an estate from Java 8 or 11 onto a current NFTC release converts production hosts from licensable to free without buying anything, and it is the single most reliable saving available to a Java buyer today.
The dates are hard. Oracle JDK 21 updates through and including September 2026 are NFTC. Beginning with the October 2026 Critical Patch Update, further JDK 21 updates are planned to move to the OTN license, the same agreement governing Java 8, 11, and 17.
The final NFTC-licensed JDK 21 update ships in July 2026, and java.com Java 21 builds remain free until 16 September 2026. Non-LTS releases 22, 23, and 24 are NFTC for their full six-month support life.
JDK 25 is the current safe harbour: free in production, free to redistribute, with NFTC updates until September 2028, one year after the next LTS, Java 29, planned for September 2027.
The failure mode is mechanical, not deliberate. A pinned patch pipeline that keeps pulling JDK 21 updates after September 2026 quietly reclassifies every production host onto OTN, where production is not a permitted free use.
Advisers have described this as a silent conversion running through September 2026, and the phrase that fits my own case files is that an unmanaged estate buys subscriptions one automated update at a time.
Read how a patch pipeline licenses an estate without anyone raising a purchase order, then freeze your update sources before the CPU calendar does it for you.
Oracle Java Licensing: A Complete CIO Playbook
Everything CIOs need to govern Oracle Java in 2026. Universal Subscription mechanics, the OpenJDK exit path, audit defense, and the 3 year plan that contains
Get the white paper →Why free dev and test is the least valuable thing you own
Most Java compliance projects I review open with the wrong question. Someone has spent six weeks building an inventory of developer laptops, IDE installs, and CI containers, and the deliverable is a spreadsheet proving that 1,400 of the 1,600 Java installations sit in non-production.
That work is accurate, it is defensible, and under the Java SE Universal Subscription it is worth almost nothing. The subscription is not priced per install.
It is priced per employee, and Oracle's own worked example in the Global Price List puts a 28,000-person organization (23,000 staff plus 5,000 contractors) at $6.75 per month, or $2,268,000 a year. Whether that estate runs 1,600 installs or 16, the invoice is identical.
The inventory told you nothing about the number that matters.
Oracle's generosity in non-production is not an oversight and it is not a concession you negotiated. The OTN license grants Development Use in plain terms: internal use to develop, test, prototype, and demonstrate Your Applications, including profilers, debuggers, and IDE tooling.
That grant is cheap for Oracle to give because it costs Oracle nothing and buys distribution. Free dev and test keeps Oracle JDK the default in your build pipelines, your Dockerfiles, your Jenkins images, and your onboarding documentation.
It ensures that when a service is promoted to production, the binary that goes with it is Oracle's. The free grant is not a compliance win handed to buyers. It is the acquisition funnel, and it works.
The commercial event is the first production host. Everything before it is free, everything after it is a full-estate employee bill, and there is no intermediate step. That structure is what makes the audit conversation different from the one buyers prepare for.
Oracle's LMS team does not need to enumerate your estate. It needs one artifact: a download log tied to a production hostname, a support ticket referencing a live server, a patch record showing a post-October 2026 JDK 21 update on a system that serves customers.
One host proves the entitlement gap, and the gap is priced against headcount. If you have 28,000 employees and 50 Java developers, you are still being quoted for 28,000, which is the arithmetic we unpack in only 50 developers use Java, so why license 10,000 employees.
This inverts the normal audit reflex. In most Oracle audits, volume is the battleground: how many cores, which virtualization boundary, whether a cluster counts. Under the employee metric, volume is settled the moment the metric applies, so the entire defense collapses into a boundary question.
Can Oracle demonstrate a single Oracle-licensed binary running outside the four OTN grants? Your evidence has to be about environment classification, promotion controls, and version provenance, not about how many machines you can list. A 400-page install inventory is not a defense.
A documented, enforced rule that no Oracle-licensed build reaches a production namespace is.
The correct strategic posture follows from that. Treat free non-production use as breathing room to engineer Oracle out of production entirely, not as a compliance result to report to the audit committee.
Keep the OTN builds where they are genuinely free, in developer workstations and isolated test benches, and standardize every production path on OpenJDK distributions with no Oracle license attached.
Where you must stay on Oracle binaries, keep them on NFTC-covered versions and track the clock, because JDK 21 moves to OTN at the October 2026 Critical Patch Update, and JDK 25 carries NFTC coverage through September 2028.
Version control is a licensing control, not a platform-engineering preference, and in my experience it is the single highest-return activity in a Java program.
So the asymmetry is worth stating plainly. Proving your dev estate is free saves you exactly zero dollars, because that estate was never billable. Keeping every production host off Oracle-licensed builds saves you the entire subscription.
The effort is not symmetric either: boundary control touches maybe a dozen pipelines and a promotion policy, while inventory reconciliation consumes months and produces a document Oracle will not dispute because it does not need to. Spend the budget where the money is.
How dev and test installs actually become licensable
Conversion is almost never a decision. It is a pipeline behaviour, a data classification, or a base image nobody re-examined, and each mechanism leaves a distinct evidentiary trail that Oracle knows how to request.
The six patterns below account for the large majority of what we see in engagements, and they matter because each one produces an artifact that survives in logs long after the engineer who caused it has moved teams.
| Conversion mechanism | What actually happens | Evidence it leaves |
|---|---|---|
| Patch pipeline drift | Automated updater pulls a post-October 2026 JDK 21 patch onto a production host, moving that host from NFTC to OTN | Package manager logs, Oracle download account records, build timestamps on the installed JDK |
| UAT with live customer data | Business insists on production data for acceptance testing; Oracle classifies data-bearing UAT as production, not Development Use | Data masking exceptions, DPIA records, connection strings pointing at production databases |
| Externally exposed demo | Sales or partner demo reachable by non-employees, which falls outside "Your Applications" and internal-only use | Reverse proxy configs, public DNS entries, external firewall rules, CDN logs |
| Build agents and CI runners | Runner compiles and packages artifacts that ship into production, so the toolchain becomes part of the production supply chain | Pipeline definitions, artifact repository provenance, signed build metadata |
| Disaster recovery copies | Standby or cold DR clone of a production host, identical binary, treated as "not live" internally but licensable as production | Replication configs, DR test reports, backup catalogs listing the JDK path |
| Cloned golden images | Developer workstation image promoted into a server farm, carrying an OTN-licensed JDK into hundreds of hosts | Image lineage in the hypervisor or container registry, identical install fingerprints across servers |
Read the right-hand column first, because that is the column Oracle reads. In every one of these mechanisms the licensable act is invisible in your CMDB and fully visible in operational logs that nobody classifies as licensing data.
A patch record and a DNS entry are stronger evidence of production use than any environment tag you apply yourself, and Oracle will weight the artifact over the label every time. Where an environment tag and a firewall rule disagree, expect the firewall rule to decide the outcome.
The practical control is to make each of these six trails produce evidence in your favour rather than Oracle's: pin production JDK versions and block automatic Oracle updates, mask data in UAT and document the masking, keep demo systems behind employee authentication.
Standardize CI runners on non-Oracle builds, and include DR in scope from the outset.
This is the same discipline covered in how a patch pipeline can license your estate without anyone raising a purchase order, and it is cheaper to enforce than to argue.
Pricing the failure: what one production host costs
The reason boundary control matters more than install counting is that the penalty for crossing the line is not proportional to the crossing.
One host that moves from test into staging or production on an OTN-licensed build (Java 8, 11, 17, and JDK 21 after the October 2026 Critical Patch Update) does not create a one-host liability.
It creates a Java SE Universal Subscription obligation priced on the Employee metric, and Oracle's own definition of Employee sweeps in all full-time, part-time, and temporary staff plus the employees of your agents, contractors, outsourcers, and consultants supporting internal business operations.
Quantity is determined by headcount, not by who touches Java. Oracle's published worked example makes the arithmetic plain: 28,000 total (23,000 staff plus 5,000 contractors) at $6.75 per month equals $2,268,000 per year.
List runs from $15.00 per employee per month in the 1 to 999 band down to $5.25 in the 40,000 to 49,999 band, with lower rates negotiable above 50,000.
Three pricing details are worth committing to memory before you sit down with Oracle. First, there is no separate 22 percent support line item, because the subscription rate is all-in, so any comparison against a perpetual-plus-support model must be done on the total, not the license fee.
Second, the employee metric carries a 50,000-processor ceiling, excluding desktop and laptop processors, and breaching it requires additional licenses (see the Oracle Java 50,000-processor cap).
Third, the band arithmetic is discontinuous: at list, 10,000 employees at the next tier down can cost less than 9,999 at the tier above, so a headcount that sits just under a break point is worth restating in writing rather than accepting Oracle's count.
In our negotiation experience, buyers who accept the vendor's employee figure without reconciling it against payroll and vendor master data routinely overpay by a full band.
What the evidence base shows across engagements
Oracle's standard entry stance assumes production use absent documentary evidence to the contrary, shifting the burden to you.
The Illinois manufacturer engagement shows how far an opening demand sits from a defensible number.
Across audit defense and renewal work, four patterns repeat with enough consistency that you should plan around them rather than react to them. The first is that Oracle's opening position treats any detected install as production.
There is no default presumption of development use in a soft audit letter, and no auditor volunteers the OTN development grant on your behalf. The second is that download telemetry from oracle.com accounts is by far the most common trigger.
Oracle knows which corporate email domains pulled which binaries and when, and that data, not a formal inventory, is what starts most conversations.
The third is that non-production claims collapse where the supporting record is inconsistent: an environment named PROD-DR in the CMDB, a change ticket describing a business go-live, a monitoring dashboard showing end-user sessions, or a load balancer entry.
Any one of those beats a verbal assurance that the host is "only UAT."
The fourth pattern is the one that returns money. Oracle's counts routinely ignore Schedule A and Schedule B restricted-use entitlements that you already hold, so installs supporting E-Business Suite, JD Edwards, WebLogic, SQL Developer, or OCI agents get billed as if they were unlicensed.
Reclaiming those is often the single largest line-item reduction available before any commercial discussion begins.
On evidence types, what has held in our engagements is contemporaneous and system-generated: CMDB environment classification maintained before the audit, change management records, deployment pipeline configuration, and firewall or network segmentation showing no external user path.
What has not held is retrospective spreadsheets, hostname conventions alone, and email from a developer asserting a box is non-production. Build the record now, while it is still contemporaneous, because it cannot be manufactured once the letter arrives.
- Percentile standing for your exact deal size and industry, from real closed transactions
- Scenario simulation before the call: test alternative terms and see the financial impact of each
- A negotiation playbook, talking points, and a two page executive brief on day one
Your first five moves
- Inventory by version and patch date, not by install count, because the only fact that matters before the October 2026 Critical Patch Update is whether each Oracle JDK 21 through 24 host sits on a build shipped under NFTC or one pulled after the license flip, and in our engagements the patch pipeline, not procurement, is what moves an estate across that line, as we set out in how a patch pipeline licenses an estate without a purchase order.
- Tag every host with an environment classification backed by a change record, so that when Oracle asks whether a machine is development, test, staging, or production, you answer from a CMDB entry and a dated ticket rather than from a hostname convention that an auditor will read against you.
- Pin or migrate any JDK 21 host that must remain Oracle, either freezing it on the final NFTC update distributed in July 2026 with patching suspended by written decision, or moving it to JDK 25, which carries NFTC coverage for production use with updates through September 2028.
- Extract Schedule A and Schedule B entitled installs from any Oracle-supplied count, because SQL Developer, OCI agents, E-Business Suite, JD Edwards, and WebLogic runtimes are routinely counted as unlicensed when they are not, a correction we detail in the restricted-use rights you may already hold.
- Answer download-history questions in writing, quoting the OTN Development Use text, confirming that internal use to develop, test, prototype, and demonstrate your applications is a granted free right, and refuse to concede that a download record is evidence of production deployment.
Frequently asked questions
Do I need an Oracle Java subscription for development and test environments?
No, not for the development activity itself. The OTN License Agreement grants free Development Use, defined as internal use to develop, test, prototype, and demonstrate your applications, and Oracle's JDK FAQ confirms this covers JDK 8, 11, and 17 at no cost.
The subscription becomes necessary when an application moves to staging or production, or when the use is not internal.
Is UAT considered production for Oracle Java licensing?
Oracle will generally treat it as production if it runs live business data or serves external users. The OTN grant covers testing your applications, but the practical boundary advisers observe is that once software leaves the build and test cycle and enters staging, the grant no longer applies.
Document your UAT data sources and user population before you rely on a non-production claim.
Can developers use Oracle JDK 8 or 11 for free in 2026?
Yes, for Development Use under OTN, which explicitly covers running profilers, debuggers, and IDE tools where the primary purpose is profiling, debugging, and source code editing. Those same JDK 8 and 11 builds require a paid subscription in production.
The version is not what makes it free; the use is.
What changes for Oracle JDK 21 in September and October 2026?
JDK 21 updates through and including September 2026 ship under the No-Fee Terms and Conditions, which permit free production use. From the October 2026 Critical Patch Update, further Oracle JDK 21 updates are planned to move to the OTN license, the same one that governs Java 8, 11, and 17.
After that date, dev and test remain free but production use of those updates requires a subscription.
If only 50 developers use Java, why would Oracle bill for 10,000 employees?
Because the Java SE Universal Subscription is metered on employee count, not usage.
Oracle defines Employee to include full-time, part-time, and temporary staff plus employees of agents, contractors, outsourcers, and consultants supporting your internal business operations, and states that quantity is determined by employee count rather than by who actually uses the programs.
Oracle's own example prices 28,000 people at $2,268,000 a year.
Does Oracle SQL Developer require a Java subscription?
No. SQL Developer sits on Oracle's Approved Product Use list (Schedule A), so Oracle Java SE may be run for any use in support of it. This is one of the most commonly miscounted items in vendor-supplied deployment reports. Note the schedules license the Java use only, not the products themselves.
Is switching to JDK 25 a way to avoid the subscription entirely?
For now, largely yes. JDK 25 binaries are free to use in production and free to redistribute under the NFTC, with updates under NFTC until September 2028, a year after the next LTS (Java 29, planned for September 2027).
The exposure returns if you stay on JDK 25 past that date and keep taking Oracle updates, so treat it as a dated position, not a permanent exit.