Oracle verifies seven third-party tools for general discovery but only four for Java SE, and none of them can produce the employee count that now drives your largest Java line item
Oracle's own License Management Services tooling page splits verified vendors into two lists: seven for general Oracle verification and a narrower four for Java SE. That gap, plus the fact that Java is now priced on contractual headcount rather than installed JVMs, means the tool-versus-spreadsheet-versus-advisor decision is not one decision but three, made per product family. Choose wrong and you hand Oracle the data collection path on a $47,500 per Processor product or a $1.26M Java band.
Prepared by Redress Compliance · August 20, 2026 · Oracle advisory. ELP builds, audit defense, and renewal engagements 2024 to 2026.
Executive summary
Oracle's verification list is scoped per product family, not per vendor, and the Java SE list is 43% shorter than the general list: four vendors versus seven.
Certero, Eracent, Flexera, Lime Software, ServiceNow, Snow Software, and USU appear for general verification, while only Flexera, Lime Software, Matrix42, and USU appear for Java SE.
So a tool you already own may be verified for Database and useless for the Java conversation that now dominates your spend.
Verified status buys you procedural control, not immunity, and it does not warrant accuracy.
A verified tool means you supply the data rather than Oracle deploying its own scripts under a roughly 45 day notice window, but Oracle GLAS retains the right to deploy a range of its own tools and never endorses a third party's output as 100% accurate.
So configuration and interpretation remain your liability.
No discovery tool can build the Java line of your ELP, because the metric is contractual employee headcount, not JVM installs, and the list ladder runs from $15.00 to $5.25 per employee per month across seven bands.
Oracle's definition sweeps in contractors, agents, outsourcers, and consultants supporting internal operations, with a floor set at headcount on the order effective date, and the band cliff is arithmetic: 9,999 employees lists at $1,259,874 while 10,000 lists at $990,000.
So one more employee removes $269,874.
Across 60 to 80 quote and renewal reviews, the discount percentage was the only number in the approval pack while the post-core-factor Processor count, which multiplies everything, was almost never restated or verified.
That is a spreadsheet failure, not a tool failure, and it is why the method question is really about who owns arithmetic accountability on a product listing at $47,500 per Processor with 22% support at $10,450 per year.
The three methods, side by side, and where each breaks on Oracle specifically
There are only three ways to build an Oracle license position, and none of them covers the estate end to end. A SAM tool gives you repeatable discovery and, if it appears on Oracle's verified list, a procedural argument for supplying your own data during an audit.
A spreadsheet gives you full control of the arithmetic and zero collection capability. An advisor gives you interpretation and contract reconciliation but still needs a data source. The failure points are product-specific, which is why this is three decisions rather than one.
ServiceNow's verification, per Oracle's LMS and GLAS engagement, is scoped to Database, Database Options, and Fusion Middleware, so a ServiceNow-centric estate still has no verified path for Java SE.
Standard Edition 2 is not licensed against the Core Factor Table at all: it is per occupied socket, capped at two sockets, which means a tool that dutifully applies a 0.5 Intel factor produces a number that is not just wrong but structurally wrong.
And Java SE is now priced on the contractual Employee definition, including contractors and outsourcers, with a minimum pegged to headcount at the order effective date. No JVM scan produces that figure.
Your contract-to-deployment reconciliation remains manual work in all three methods, because entitlements live in ordering documents, not in agents.
| Dimension | SAM tool | Spreadsheet | Advisor |
|---|---|---|---|
| Oracle verification status | 7 vendors general, 4 for Java SE | None, not applicable | None, but can propose equivalent methodology |
| Database Options detection | Strong, feature-usage based | Not possible without a feed | Interprets the feed, does not create it |
| Fusion Middleware coverage | Partial, ServiceNow limited to DB, Options, FMW | Manual inventory only | Depends on supplied data |
| Core factor and virtualization | Automated, frequently misapplied to SE2 | Fully auditable, error-prone | Best judgment on partitioning disputes |
| SE2 socket rule (max 2 sockets) | Often modelled as processors | Correct if you code the rule | Correct, and defensible |
| Java Employee metric | Not derivable from discovery | HR extract, monthly tracking | Defines the counted population |
| NUP floors (25 per proc EE, 10 per server SE2) | Rarely enforced in output | Enforced by formula | Enforced and challenged |
| Audit defensibility | Data collection concession only | Weak alone | Strongest on methodology and scope |
| Typical annual cost | Five to six figures, per market experience | Internal labour only | Project fee, no recurring licence |
The table's rows on verification are the ones most often misread in board packs. Verification governs who collects the data, not whether the resulting number is correct.
Oracle's own tooling language is clear that GLAS continues to develop in-house tooling and can deploy a range of tools during an audit, so verified status buys you a seat at the collection table, not a safe harbour on the conclusion.
Read the cost row against the exposure it protects. At $47,500 per Processor for Database Enterprise Edition, a single miscounted socket pair on a 16-core box is a six-figure error, and on Java a 9,999 versus 10,000 employee band boundary moves $269,874 of annual list in one direction.
Tooling spend is trivial against those numbers; the risk is buying a tool that cannot see the metric that drives the largest line.
What Oracle verification actually means, and what it does not
Verification is a procedural concession about data collection. It is not an accuracy warranty and it is not a licensing safe harbour.
Oracle publishes two lists on its License Management Services tooling page: a general list (Certero, Eracent, Flexera, Lime Software, ServiceNow, Snow Software, USU) and a separate, narrower Java SE list (Flexera, Lime Software, Matrix42, USU).
Scoping is per product family, and vendors do not carry blanket status across the portfolio. ServiceNow's SAM module is verified for Database, Database Options, and Fusion Middleware only.
Oracle also retains its own collection path in parallel, which means verified output is an input to the audit conversation rather than the end of it.
In our experience the practical benefit is real but bounded: you supply the data set, you control the timing, and you argue interpretation from your own numbers instead of from Oracle's scripts.
Treat vendor verification claims as unverified until you check them yourself. At least one 2026 advisory guide lists Snow, ServiceNow, and Certero as Java SE verified, which does not match Oracle's live page (no Snow, no ServiceNow, no Certero; Matrix42 present). That discrepancy is not academic.
If you buy a tool on the strength of a Java SE claim that Oracle does not publish, you have paid for a capability you cannot invoke when the audit letter arrives.
Before you rely on any verification statement, open Oracle's tooling page, screenshot it with a visible date stamp, and file it with your license position baseline.
Oracle's contracts rarely mandate specific tools or methodology, so your documented evidence of what was verified, on what date, for which product family, is the foundation for proposing an equivalent method later.
Avoid the Oracle Exadata core license trap
Oracle Exadata can lock you into full core licensing across X9M, X10M, and Cloud at Customer. The buyer side strategy to size the platform and cut the bill.
Get the white paper →Why the Java line proves the tooling model is broken, not just incomplete
Before January 2023, Java SE was a discovery problem, and discovery tools were reasonably good at it.
You counted processors running server-side JVMs, counted desktops with a JRE, applied the core factor table, and reconciled to whatever Java SE Advanced or Java SE Desktop entitlements sat in your contract file.
An agent on a host could find a JDK, read its version string, and tell you whether it came from Oracle or from an OpenJDK build. The question was technical, the answer lived on the machine, and a competent scan closed most of the gap. That world is gone, and it is not coming back.
The Employee metric in Oracle's Java SE Universal Subscription price list does not ask what you installed. It asks how many people you have.
The definition captures all full-time, part-time, and temporary employees, plus the employees of your agents, contractors, outsourcers, and consultants who support internal business operations.
And it states explicitly that quantity is determined by the number of Employees "and not just the actual number of employees that use the Programs," with a contractual minimum equal to headcount at the order effective date.
Read that carefully. A company with three developers using Java and 12,000 staff licenses 12,000. The population lives in HRIS, payroll, procurement records, vendor master data, and the statements of work sitting with your outsourcing partners.
No agent on a server has ever seen any of it, and none ever will.
Most tool vendors shipped Java modules through 2024, and the better ones do useful work: they distinguish Oracle binaries from Adoptium or Corretto, they flag which versions fall inside the paid support window, and they build the deployment picture you need for a migration case.
Quality varies significantly between them, and Oracle's own verified list for Java SE runs to four vendors (Flexera, Lime Software, Matrix42, USU) against seven for general verification. But even the strongest Java module answers the wrong question.
Not one of them can pull an HR extract, reconcile it against a contractor register, decide whether an offshore managed services team of 400 counts as agents supporting internal business operations, and defend that decision to an Oracle GLAS reviewer.
That is not a maturity gap that will close in two release cycles. It is a category error.
The band structure makes precision non-negotiable. The published ladder runs seven tiers from $15.00 per employee per month at 1 to 999 down to $5.25 at 40,000 to 49,999. At 9,999 employees, annual list is $1,259,874. At 10,000, it is $990,000.
One additional employee removes $269,874 from your bill. That is a cliff, not a curve, and it means the headcount number has to be defensible to the individual, with a documented methodology, a named owner, and an audit trail from source systems.
A tool output cannot carry that weight because the tool never touched the source.
The commercial evidence points the same direction.
Benchmarked negotiated rates for organizations between 1,000 and 10,000 employees land at $9.50 to $12.80 per employee per month against a $15.00 list top band, and reductions of 28 to 44 percent are documented where the buyer arrived with a credible OpenJDK migration plan.
Average cost increases versus pre-2023 processor licensing run around 340 percent, and there is no 22 percent support line to negotiate separately and no credit for legacy perpetual Java SE Advanced holdings.
The input that moves the price is a dated migration roadmap with named applications and owners, not an install inventory. Discovery data feeds that roadmap; it does not replace it. Our own engagement pattern is consistent: the buyers who cut Java spend most sharply brought an exit plan, not a scan.
So stop asking which tool covers Java. Ask who signs the headcount number, on what methodology, with what evidence behind the contractor population, and who defends it in an audit. That is a person and a governance process, not a license.
Then generalize the lesson, because Java is the loudest case, not the only one.
Any Oracle metric defined by contract population rather than technical deployment sits permanently outside the reach of discovery: Employee, Application User, legacy Named User Plus where the counted population includes non-human operated devices and third-party users you cannot instrument.
Build that split into your Oracle license position baseline from day one, and route the population-metric products to a different owner than the technical estate. The share of Oracle spend priced on contract population is rising, not falling, and your tooling budget should stop pretending otherwise.
The arithmetic layer that no method automates: core factors, NUP floors, and SE2
The expensive mistakes we see are not discovery misses. They are arithmetic errors in the layer between raw inventory and priced position, and every method (tool, spreadsheet, advisor) can get them wrong.
Across 60 to 80 quote and renewal reviews, the discount percentage was the only figure in the approval pack, while the post-core-factor Processor count, which multiplies everything else, was almost never restated or independently verified by the buyer.
A 0.5 Intel core factor misapplied as 1.0 doubles a $47,500 per Processor line before anyone argues about discount. Then come the floors.
Named User Plus prices at exactly one fiftieth of Processor on Enterprise Edition, $950 against $47,500, so Processor becomes the cheaper metric past 50 genuine users per Processor. Below that, the minimums bite: EE requires 25 NUP per Processor, SE2 requires 10 NUP per server.
A 16-core Intel box under NUP is 16 x 0.5 x 25 = 200 NUP, or $190,000 at list, even where only 50 humans touch the database. NUP is also unavailable outright where the population cannot be counted: web-facing portals, multi-tenant systems, and databases fronted by third-party applications.
SE2 sits outside the core factor table entirely, licensed per occupied socket to a two-socket maximum. These rules interact, and the interaction is where money leaks. Test each one during entitlement reconciliation, not after the quote arrives.
| Rule | Arithmetic | Buyer consequence |
|---|---|---|
| Intel core factor | Cores x 0.5 = Processors | Post-factor count almost never restated in approval packs |
| NUP crossover (EE) | $950 vs $47,500 = 1/50th | Processor is cheaper past 50 real users per Processor |
| EE NUP floor | 25 NUP per Processor | 16 cores x 0.5 x 25 = 200 NUP = $190,000 list at 50 users |
| SE2 NUP floor | 10 NUP per server | Small servers priced on the floor, not on usage |
| NUP eligibility | Countable users only | Web-facing, multi-tenant, third-party-fronted systems must use Processor |
| SE2 licensing | Per occupied socket, max 2 | Core factor table does not apply; socket count drives price |
Reconciling the position to a price list that moved twice in 2026
An unpriced ELP is a compliance exercise, not a negotiation asset. Until every reconciled quantity carries a dated unit price, you cannot tell your CFO what a gap costs, what a settlement should cost, or whether Oracle's proposal is discount or repackaging.
And in 2026 the pricing base itself is unstable: Oracle's live Technology Global Price List PDF is headed August 3, 2026, while advisory analysis in circulation cites an April 16, 2026 effective date. Two dates, both defensible, different numbers behind them.
Database Enterprise Edition sits at $47,500 per Processor with 22% support at $10,450 annually, WebLogic Suite at $45,000, SOA Suite at $57,500.
Headline list movement on core Database stayed inside 0 to 8% year on year, which sounds benign until you notice the repackaging: options folded into suites, suites renamed, and the like-for-like comparison you built last renewal quietly stops working.
In my experience the repackaging, not the list increase, is where the money moves. On the support side, there is exactly one published lever on technology support, Oracle Support Rewards at 25 or 33 cents per OCI dollar, and it buys down support only by pushing spend to OCI.
Everything else is negotiated, undocumented, and revocable.
Put the price list version and effective date in the ELP header, on every page, next to the currency. When Oracle's rep quotes a number six weeks later, the first question is which list it came from, and the burden of proving the delta shifts to them.
Restate the post-core-factor Processor count in the same header, because that multiplier drives every dollar below it and, across the reviews behind this analysis, it was almost never verified by the buyer.
Then price the gap twice: once at list, once at your last achieved discount. The spread between those two figures is your negotiating room, and it is the only number your board actually needs. See the buyer-side baseline for an Oracle license position for the header structure.
What 2026 engagements show: recurring failure patterns by method
Across 40 to 50 pricing reviews, support consumed the majority of Oracle spend over a term, not the license line the approval pack focused on.
Across 80-plus Java contracts, the Universal Subscription averaged a 340% increase versus pre-2023 processor licensing.
The patterns repeat by method, not by industry. In 60 to 80 quote and renewal reviews, the discount percentage was the only verified number in the approval pack.
Nobody restated the post-core-factor Processor count, so a 40% discount was approved on a quantity that had never been audited by the buyer.
In the Java population, negotiated rates landed at $9.50 to $12.80 per employee per month against a $15.00 list ceiling, and organizations that arrived with a credible OpenJDK migration plan took 28 to 44% reductions. Separately reported signed outcomes show 22 to 41% off opening quotes.
The variable was never the tool. It was whether the buyer could defend an employee number and articulate an exit.
The 2026 GLAS letter format change sharpened this.
Letters now arrive addressed to a named CIO, CFO, or General Counsel rather than a procurement mailbox, signed by GLAS instead of the sales team, citing the specific OMA or OTN agreement that governed the original Java download, with a window commonly set at 45 days.
That construction assumes you cannot reconstruct the download event or the headcount definition inside 45 days. Most organizations cannot, because their SAM tool never held either fact.
The pattern across all three methods is blunt: buyers with a verified tool but no owned arithmetic lost the same amount as buyers with no tool at all. Tooling shortens data collection. It does not produce a defensible position, and Oracle prices the position.
Read how Oracle selects audit targets before assuming your quiet estate is uninteresting.
- Percentile standing for your exact deal size and industry, from real closed transactions
- Scenario simulation before the call: test alternative terms and see the financial impact of each
- A negotiation playbook, talking points, and a two page executive brief on day one
Your first five moves
- Date-stamp Oracle's live verification page before you trust any vendor claim, then confirm your tool sits on the correct product-family list, because the general list runs seven vendors (Certero, Eracent, Flexera, Lime Software, ServiceNow, Snow Software, USU) while the Java SE list runs four (Flexera, Lime Software, Matrix42, USU), and published third-party guides contradict Oracle on exactly this point.
- Split the ELP into three named workstreams with three named signatories, separating what discovery can answer (installed binaries, options usage, feature flags), what only arithmetic can answer (core factors, 25 NUP per Processor on EE, 10 per server on SE2, per-socket SE2 rules), and what only a population count can answer (the Java Employee definition), because one owner over all three produces a position nobody will defend in an audit room. Our buyer-side ELP baseline sets the structure.
- Produce and sign the Java Employee count from HR and vendor master data before Oracle asks, including full-time, part-time, temporary, agents, contractors, outsourcers and consultants supporting internal operations, and calculate your distance to the nearest band boundary: at 9,999 employees list is $1,259,874, at 10,000 it is $990,000, so one head decides $269,874.
- Restate the post-core-factor Processor count on every approval pack, next to the discount percentage, because across 60 to 80 quote and renewal reviews the discount was the only figure signed off while the multiplier underneath it went unverified, and it multiplies a $47,500 per Processor list line.
- Pin the price list version, its effective date, and a five-year support trajectory into the ELP header, noting that list moved twice in 2026 (April 16 and August 3) and that support at 22% of $47,500 is $10,450 per Processor per year, historically 55 to 70 percent of total term spend, so the position stays decision-grade inside Oracle's 45-day audit notice window.
Frequently asked questions
Which SAM tools are Oracle-verified in 2026?
Oracle's License Management Services tooling page lists Certero, Eracent, Flexera, Lime Software, ServiceNow, Snow Software, and USU for general verification. A separate and shorter list covers Java SE: Flexera, Lime Software, Matrix42, and USU.
Verification is scoped per product family, so confirm your tool appears on the list for the specific products in scope, and screenshot the live page with a date because third-party summaries of these lists do not always match Oracle's own page.
Does using an Oracle-verified tool prevent an audit?
No. Verification changes who collects the data, not whether Oracle exercises audit rights. In practice it lets you supply output from your own tool rather than running Oracle's scripts, which matters inside a notice window commonly stated as 45 days.
Oracle GLAS continues to develop in-house tools and reserves the right to deploy a range of collection methods during a review.
Can any SAM tool count Java licenses under the Employee metric?
Not on its own.
Since 2023 the Java SE Universal Subscription is priced per Employee, defined to include full-time, part-time, and temporary staff plus agents, contractors, outsourcers, and consultants supporting internal business operations, with a minimum set at headcount on the order effective date.
That population lives in HR, payroll, and vendor master systems, not in server-side discovery. Most vendors shipped Java modules in 2024, but they inventory JVMs, which is not the billing metric.
Is a spreadsheet ever an acceptable way to build an Oracle license position?
For entitlement reconciliation and the arithmetic layer, yes, and often it is the only place that work happens. Contracts, amendments, legacy metrics, core factor application, and NUP minimums are interpretation tasks that no agent performs.
Where spreadsheets fail is repeatability and virtualization-aware deployment capture, so the practical answer is a tool for discovery and a controlled, version-owned spreadsheet for the priced position.
What Oracle number is most often wrong in an approval pack?
The post-core-factor Processor count. Across 60 to 80 quote and renewal reviews, the discount percentage was the only figure anyone verified, while the Processor count that multiplies every other number was almost never restated.
On Database Enterprise Edition at $47,500 per Processor list, a single unverified core factor application moves the deal by six figures before any discount is discussed.
When does Named User Plus beat Processor licensing on Oracle Database?
NUP is priced at exactly one fiftieth of the Processor price, $950 against $47,500 on Enterprise Edition, so Processor becomes cheaper past roughly 50 real users per Processor.
Enterprise Edition also carries a 25 NUP per Processor floor: a 16-core Intel server at a 0.5 core factor requires 16 x 0.5 x 25 = 200 NUP, or $190,000 at list, even if only 50 users exist.
NUP is also unavailable where users cannot be counted, such as public web portals or multi-tenant applications.
Should we hire an advisor or build the license position in house?
Split the question by workstream.
Discovery is tool work, arithmetic and contract interpretation are in-house-ownable if you have someone accountable for signing the numbers, and adversarial interpretation (audit response, Oracle's methodology proposals, Java Employee scoping) is where independent buyer-side advice pays.
Most Oracle agreements grant audit rights on notice but rarely mandate Oracle's specific tools or methodology, so the right to propose an equivalent approach is only worth what your ability to defend it is worth.