A systems integrator's statement of work assumes your Oracle entitlement is clean and portable. This review surfaces the gaps while you still hold leverage, before the migration locks them in and an audit prices them.
A systems integrator's statement of work assumes your Oracle entitlement is clean and portable. This review surfaces the gaps while you still hold leverage, before the migration locks them in and an audit prices them.
Every migration statement of work you receive from a systems integrator (SI) makes two silent assumptions: that your Oracle entitlement is accurate, and that it moves cleanly to the target platform. Neither is safe. The SOW prices labor, cutover windows, and testing. It does not price the license shortfall you carry into the new environment, and it does not warrant that Oracle agrees your workloads are portable under the terms you signed.
In 25 years across the table from this vendor, the pattern is consistent. The migration completes, the source estate gets decommissioned, and then Oracle's Global Licensing and Advisory Services (GLAS) team, the group formerly branded License Management Services (LMS), arrives to "verify compliance" on the way out. By then your leverage is gone. You have already spent the migration budget, you have already changed your deployment topology, and Oracle knows it. The average initial Oracle audit demand against a Fortune 500 enterprise runs about $2.7M (Redress Compliance advisory data, 2026), and migration events are one of the most reliable triggers.
This review is the work you do before signing. It is not the SI's job, and no reputable SI will accept license liability in the SOW anyway. Run it yourself, or have independent buyer-side counsel run it, and you convert a downstream audit surprise into a pre-project line item you can budget, negotiate, or engineer around.
An SI SOW is a services contract. It covers what the integrator will do, not what you are entitled to run. Read the boilerplate: liability for third-party license compliance sits with the customer, always. If the SI's target architecture puts 16 vCPUs of Enterprise Edition where you only hold licenses for 8, the SOW still gets signed, the work still gets done, and the gap is yours.
Migrating off Oracle, or even choosing a competitor's target, is itself a documented audit trigger. Saying "no" to Oracle sales, declining a renewal, or moving a workload to a rival cloud can prompt a verification review before you fully depart (Oracle Licensing Experts, July 2025). GLAS exists to convert unlicensed usage into license, support, or cloud revenue. Every finding in its report is an opening negotiation position, not a neutral fact.
The SI prices the migration. Oracle prices the license gap the migration exposed. Only one of those two contracts protects you, and it is neither.
Our recommendation: treat the license review as a gate on the SOW, not a parallel activity. Do not sign until the entitlement baseline, the portability analysis, and the compliance posture are all documented. If you have not yet run an internal baseline, start with our guidance on internal Oracle license audits and the Oracle Cloud migration readiness assessment.
You cannot validate portability against entitlement you have not counted. The baseline is a reconciled statement of what you own (Processor licenses, Named User Plus counts, options, ULA status, Java subscriptions) against what you actually deploy. The reconciliation is where the exposure lives.
In our advisory files, unlicensed Database options accounted for 40 to 60 percent of the asserted shortfall in a typical audit finding (Redress Compliance, March 2026). These are the features Oracle's own scripts capture whether or not you deliberately turned them on: Partitioning, Advanced Compression, Diagnostics and Tuning Packs, Advanced Security. A feature used once counts. Run the scripts yourself first, read the output before Oracle does, and understand what our guide to Oracle license compliance scripts means for your estate. Doing this in-house typically cuts exposure 25 to 50 percent because you remediate before the finding is on paper.
Deployment size is not a proxy for exposure. We have defended customers running just two Oracle database instances against an alleged non-compliance figure of US$3M (Rythium Technologies, 2025). Small estates carry seven-figure risk because the options and the backdated support penalties, not the raw core count, drive the number. Backdated support and penalty terms add 20 to 35 percent on top of the raw license gap (Redress Compliance, March 2026).
If you hold an Unlimited License Agreement, a migration is the worst possible time to let the certification clock run out unmanaged. Certification freezes your ULA deployment into a permanent, perpetual license count, and the window is short: often 30 to 90 days around term end (Redress Compliance, February 2026). Miss it and you lose the ability to lock in your peak deployment. Rush it and your count comes in wrong.
The specific migration trap: cloud deployments do not count toward your certified total by default. You need explicit contractual language confirming that cloud instances count, and most ULAs do not have it (Oracle Licensing Experts, March 2026). Do not assume. When cloud and disaster recovery instances get swept in late, certified counts have come in 1.5 to 2.5 times higher than the buyer expected (Redress Compliance, May 2026), and rushed certification errors reliably favor Oracle. Start the software asset management review roughly six months before term end, not at cutover.
A ULA that certifies mid-migration, under time pressure, with cloud instances swept in late, is Oracle's ideal outcome. Sequence certification before the SOW, never during it.
This is the single most expensive misunderstanding in Oracle migrations. Oracle Database in a public cloud is counted by vCPU, not by physical core, and the Processor Core Factor Table does not apply (Redress Compliance, 2026). On-premises, a factor of 0.5 for x86 cores can halve your license requirement. In an Authorized Cloud Environment, that discount vanishes. The same workload can require materially more licenses purely because of the counting rule change.
Oracle's policy lists four Authorized Cloud Environments: Amazon EC2, Amazon RDS, Microsoft Azure, and Google Cloud Platform. Under the policy, two vCPUs count as one Processor license when hyperthreading is on, and one vCPU counts as one license when it is off. The critical caveat: this rule sits in a policy document, not in your signed contract, and Oracle can update it (Redress Compliance, April 2026). Pin the policy version in force at deployment and document every instance against it.
| Counting basis | On-prem (x86) | AWS / Azure vCPU | OCI OCPU (BYOL) |
|---|---|---|---|
| Metric | Physical core x core factor | vCPU | OCPU |
| Core factor applies | Yes (typically 0.5) | No | No |
| Licenses per unit (HT on) | 2 cores = 1 license | 2 vCPUs = 1 license | 4 OCPUs = 1 license |
| Relative license need | Baseline | Higher than on-prem | ~2x more generous than AWS/Azure |
BYOL terms differ sharply by destination. OCI BYOL applies one Enterprise Edition Processor license to four OCPUs, where AWS and Azure BYOL apply the same license to only two vCPUs (Atonement Licensing, February 2026). That is roughly a 2x difference in license efficiency depending purely on where the SI lands your workload. If the SOW names a target platform, that choice has a direct, quantifiable license cost. Before you sign, model it against our analysis of which cloud makes the same Oracle workload cheapest to license and the mechanics in the Oracle Authorized Cloud Environment core counting policy.
Edition ceilings also break silently in cloud. Any Standard Edition 2 instance above eight vCPUs needs immediate attention (Redress Compliance, 2026), because SE2 has a hard socket and vCPU limit that a naive lift-and-shift will violate. Check every SE2 instance against the ceiling before the SI provisions it.
The three canonical migration patterns (rehost, replatform, refactor) carry different license consequences. A rehost preserves your architecture and, usually, your license shape, but it inherits every option you were accidentally consuming. A refactor to a managed service or a non-Oracle database can eliminate license liability entirely, but only if the SOW actually retires the Oracle dependency rather than leaving a shadow instance running. Our breakdown of how rehost, replatform, or refactor changes your Oracle license bill should inform which path the SOW commits to.
Two timing controls belong in the SOW itself. First, dual-running: during cutover you will run the source and target in parallel, which means you are, however briefly, deployed on both. That can double your license requirement for the overlap window unless the SOW bounds it and you have entitlement to cover it. Read our guidance on avoiding paying twice during a cloud cutover and insist the SOW specifies the maximum parallel-run duration.
Second, decommission timing. Source licenses do not stop generating support cost the moment the target goes live. You keep paying Oracle support on the old estate until you formally terminate, and premature termination can strand you if the migration slips. Sequence the decommission deliberately using our note on when to decommission source licenses after a migration, and make the decommission a named SOW milestone with acceptance criteria.
Migrations touch application servers, middleware tiers, and desktop tooling, all of which may carry an Oracle Java runtime. The Java SE Universal Subscription is licensed by total employee count, not by the number of people or machines that run Java. Oracle's contract obligates you to license every full-time, part-time, temporary, agent, contractor, and outsourcer supporting the operations of the company, whether or not that person ever installs Java (Redress Compliance, June 2026).
Published list pricing starts at $15 per employee per month and tiers down to $5.25 for very large populations (Oracle Java SE Universal Subscription FAQ). A 10,000-employee organization faces roughly $1.8M annually at list before discount. Renewals quoted by Oracle in 2024 and 2025 have routinely arrived at five to ten times the prior year's spend (Redress Compliance, June 2026). Gartner predicts that by 2026 at least 20 percent of organizations using Java will face an Oracle audit.
Two defensive facts. Oracle's quoted headcount runs 18 to 28 percent higher on average than the count a buyer can defend after a clean headcount audit, with contractors the single largest dispute (Redress Compliance, June 2026). And free OpenJDK distributions (Eclipse Temurin, Amazon Corretto, Azul Zulu, Microsoft Build of OpenJDK) cover most migration paths. If the SOW includes any Java runtime work, mandate an OpenJDK target unless a specific dependency genuinely requires Oracle's JDK. Migrating to OpenJDK during the project is far cheaper than subscribing after the fact.
Assume the migration will draw a verification review. Prepare the defense before the notice, not after. Expert audit defense typically achieves a 40 to 70 percent reduction against the initial demand (Redress Compliance, 2026), and that reduction is far larger when you have already run your own scripts, documented your entitlement, and pinned the cloud policy version in force at deployment.
Gate the SOW on four deliverables. One: a reconciled entitlement baseline that names every option in use and every ULA in flight. Two: a portability analysis that models the SI's named target platform under the correct cloud counting rule, including BYOL efficiency and SE2 ceilings. Three: a dual-running and decommission timeline written into the SOW as milestones with license entitlement mapped to each. Four: a Java strategy that defaults to OpenJDK. If any of the four is missing, the SOW is pricing your migration and pre-paying Oracle's next audit at the same time. Fix that before signature, while you still hold the leverage.
No reputable SI will accept it, and you should not expect them to. The SI contracts for services, not for your Oracle entitlement, and standard boilerplate places third-party license compliance squarely on the customer. Run the license review yourself or with independent buyer-side advisors, and treat it as a gate on the SOW rather than something the integrator owns.
On-premises, the Processor Core Factor Table typically halves your x86 core count. In an Authorized Cloud Environment, Oracle counts by vCPU and the core factor does not apply, so two vCPUs equal one Processor license with hyperthreading on. The same workload can require materially more licenses purely because of the counting rule change, which is why this is the number one budget surprise in cloud migrations.
Yes. Migrating off Oracle, declining a renewal, or choosing a competitor's platform are documented triggers for a verification review, because Oracle's GLAS team wants to confirm compliance before you depart. Gartner predicts at least 20 percent of Java users will face an Oracle audit by 2026. Prepare your defense before the notice arrives, since expert defense typically cuts the initial demand 40 to 70 percent.
Not by default. You need explicit contractual language confirming that cloud deployments count toward your certified total, and most ULAs lack it. When cloud and DR instances get swept in late, certified counts have come in 1.5 to 2.5 times higher than expected. Resolve certification before the migration, ideally starting the review about six months before term end, never during cutover.
Oracle's Java SE Universal Subscription is priced by total employee count, not by Java users, starting near $15 per employee per month. A 10,000-employee organization faces roughly $1.8M annually at list. If the SOW touches any Java runtime, mandate an OpenJDK distribution such as Temurin, Corretto, Zulu, or Microsoft's build unless a specific dependency truly requires Oracle's JDK.
Not the moment the target goes live. You keep paying support on the source estate until formal termination, and premature termination strands you if the migration slips. Make decommission a named SOW milestone with acceptance criteria, and sequence it deliberately so you neither double-pay support nor terminate before the target is proven stable.
Oracle Primavera P6 compliance. Named user counting, EPS access, the contractor trap, and the audit defense framework.
Gated with a work email on the download page. No sales follow up you did not ask for.
Get the White Paper →500+ enterprise clients. 11 vendor practices. Industry recognized. One conversation can change what you pay for the next three years.
One buyer side briefing a week. Renewal signals, audit moves, and the levers that work. No vendor spin.