Now openThe whole vendor lifecycle in one workspace. Benchmarking, negotiations, contracts, invoices, renewals. Free 30 day trial, no card.Start the trial →
Now openThe whole vendor lifecycle in one workspace. Benchmarking, negotiations, contracts, invoices, renewals. Free 30 day trial, no card.Start the trial →
Two negotiators comparing proposals on a conference table
Oracle · Database Security Options · Pillar Guide

Oracle Database Security Options Licensing: The Packs You Pay For

Compliance mandates quietly force you into paid Oracle security options, and a single encrypted column can cost $15,000 per processor. This guide names every separately licensed security feature, what triggers the bill, and how to close the exposure before Oracle finds it.

Contact Us Oracle Hub
500+Enterprise clients
$2B+Under advisory
Industry Recognized
500+ Enterprise Clients
$2B+ Under Advisory
11 Vendor Practices
100% Buyer Side Independent

Compliance mandates quietly force you into paid Oracle security options, and a single encrypted column can cost $15,000 per processor. This guide names every separately licensed security feature, what triggers the bill, and how to close the exposure before Oracle finds it.

Oracle sells the perception that Enterprise Edition is a complete, secure database. It is not, at least not for the security controls your auditors, your regulators, and your CISO now require. Encryption at rest, data redaction, mandatory access control, privileged-user isolation, and centralized audit collection are all separately licensed. Every one of them lists at five figures per processor, and most of them switch on with a single command, a single configuration setting, or a single compliance mandate handed down by someone who has never heard the phrase 'Advanced Security Option.'

In 25 years of negotiating Oracle contracts on the buyer side, I have watched the same pattern repeat: a security team enables Transparent Data Encryption to satisfy PCI DSS, a DBA turns on Data Redaction to hide account numbers, and eighteen months later Oracle's License Management Services team produces an audit finding worth several hundred thousand dollars. The features cost nothing to enable. They cost a fortune to have used. This article is the definitive map of which security controls are free, which are paid, what quietly triggers the paid ones, and how to defend the position before it becomes a line item in a settlement.

Enabling an Oracle security option costs nothing. Having used one costs $15,000 per processor plus 22 percent every year forever.

The Six Security Options You Actually Pay For

Oracle bundles its database security capabilities into a set of separately licensed options and one adjacent product family. Every one of these is Enterprise Edition only. None of them is available on Standard Edition 2, regardless of your compliance requirements or your architecture. Here is the full inventory, with list prices grounded in current pricing research. Treat all figures as list, before any negotiated discount and before the roughly 22 percent annual support that attaches to every perpetual license.

Security Option Processor List Price Named User Plus Annual Support (~22%) Metric Rule
Advanced Security (ASO)$15,000~$300 (25 NUP/core min)~$3,300Matches DB metric 1:1
Database Vault$11,500 (sources conflict; see note)~$230~$2,530Matches DB metric 1:1, no mixing
Label Security (OLS)~$11,500~$230~$2,530Matches DB metric 1:1
Audit Vault & Database Firewall~$20,000 per monitored source processorBy quote~$4,400Licensed on monitored targets, not AVDF server
Key VaultPer OKV server install (no per-processor fee)N/AN/ARestricted-use stack license
Enterprise Edition (base, for context)$47,500$950~$10,450Anchor for all option math

Note the Database Vault price dispute. One pricing source lists it at $11,500 per processor; another calls it Oracle's most expensive standalone option at $47,500 per processor. We have seen both figures quoted in live deals depending on price list vintage and how the sales rep is bundling. Verify against the current Oracle Technology Price List for your exact SKU before you sign anything, and never accept a rep's verbal number. Our detailed comparison in Oracle Label Security vs Database Vault walks through both scenarios.

The critical structural fact: these options do not license independently. Each one follows the metric of the database beneath it, one to one. If your database is licensed on 16 processors, the option is licensed on 16 processors. You cannot license Advanced Security on a subset. This is where the money lives, and it is where most buyers get hurt.

The One-to-One Rule: Why Options Multiply Your Bill

Oracle Database options and packs are add-ons that inherit the metric and the quantity of the underlying database license. If the database is licensed per processor, the option is licensed per processor at the same count. If the database is licensed per Named User Plus, the option is licensed per NUP with the same 25-users-per-core minimum. There is no partial licensing. You cannot license two cores of a four-core server for TDE and leave the other two unlicensed. Any server that uses an Advanced Security feature must be fully licensed for that option across every processor, exactly as the database itself is.

This is not a technicality. It is the entire economic model. Consider a 16-core Intel server running Enterprise Edition. Applying Oracle's standard 0.5 core factor, that is 8 processor licenses of Enterprise Edition at $47,500, which is $380,000 in base database license. Add Advanced Security at $15,000 per processor across the same 8 processors, and you have added $120,000 in license plus roughly $26,400 per year in support, all triggered by encrypting a single column. A fully optioned Enterprise Edition processor (Database plus RAC plus Partitioning plus Advanced Security plus Advanced Compression plus Diagnostics plus Tuning plus Active Data Guard) lists at $122,000 per processor with $26,840 annual support. That same 16-core server, fully stacked, lists at $976,000 plus $214,720 per year in support.

There is no partial licensing. Encrypt one column on a 16-core server and you owe Advanced Security on all eight processors, not the one that touched the data.

Database Vault carries an additional trap: you cannot mix metrics between the database and the option. If the database is on processor licensing, Database Vault must be on processor licensing. Perfect one-to-one matching is required, and any mismatch is treated as non-compliance in an audit. For the mechanics of how any option's count is derived from the database beneath it, our Oracle Database Options and Management Packs licensing guide lays out the full processor-count math.

Advanced Security Option: TDE, Redaction, and the Compliance Trap

The Advanced Security Option is the single most consequential security license in the Oracle catalog, and the one most buyers trip over. It lists at $15,000 per processor, roughly one-third of the base Enterprise Edition license, or approximately $300 per Named User Plus with the 25-users-per-core minimum in effect. Annual support runs about $3,300 per processor per year. ASO bundles two capabilities that regulated organizations almost always need: Transparent Data Encryption (TDE), which encrypts data at rest, and Data Redaction, which masks sensitive data at query time.

Here is the trap. GDPR, PCI DSS, and HIPAA all effectively require encryption of data at rest. Your compliance team reads the mandate, hands the DBA a requirement to encrypt cardholder data or protected health information, and the DBA enables TDE because it is the native, supported way to do it in Oracle. Nobody in that chain checks the price list. Oracle charges $15,000 per processor for the feature your regulator forced you to use, and the enablement is a one-line command with no license gate.

Advanced Security non-compliance shows up in approximately 40 percent of the Enterprise Edition environments reviewed at audit, making it the third most common option-compliance gap behind the Diagnostic Pack and the Tuning Pack. The trigger threshold is brutally low: if you encrypt any part of the database (a single column, a tablespace, or the entire database) using TDE, the entire database requires an Advanced Security license. One encrypted column on one server exposes every processor on that server.

The exposure extends beyond live data. Creating encrypted RMAN backups triggers ASO. Encrypting Data Pump exports triggers ASO. So a security-conscious backup policy, encrypting backups because that is obviously good practice, silently creates a license obligation across the source database. We treat this option in full detail in Oracle Advanced Security Option: When TDE and Redaction Start Costing You, including the query paths that flag usage in the DBA_FEATURE_USAGE_STATISTICS view Oracle harvests during an audit.

What Became Free (and What Stayed Paid)

There is one piece of genuinely good news, and buyers frequently misunderstand its scope. Historically, network encryption (encrypting data in transit, including native encryption and TLS) required Advanced Security. From Oracle Database 19c onward, basic network encryption is free with Enterprise Edition and no longer requires ASO. If your only encryption requirement is protecting traffic between the client and the database, you may not need Advanced Security at all.

But the boundary is precise. Encryption of data at rest (TDE) and Data Redaction still require Advanced Security licenses. Network encryption is free; data-at-rest encryption is not. Do not let a rep blur this line to justify an ASO purchase you can avoid, and do not let your own team assume that because TLS is free, TDE must be too. The distinction is worth $15,000 per processor. We map the compliant-encryption paths, including which mandates can be met with the free capabilities, in Meeting Encryption Mandates Without Overbuying Oracle Security Options.

TDE on Oracle Cloud: Included, but Only Where You'd Expect

Oracle's cloud licensing story for TDE is a deliberate incentive to move workloads onto its managed services. TDE is included and enabled by default in OCI managed database services, including the Base Database Service and Autonomous Database. It is also included on Oracle Database@Azure. On those platforms you get encryption at rest without a separate Advanced Security license line.

The exclusions matter more than the inclusions. Standard Edition does not include TDE anywhere. And Enterprise Edition under Bring Your Own License (BYOL) can use TDE only if you have licensed the Advanced Security Option, whether that BYOL runs on-premises, on OCI Compute, on Azure IaaS, or anywhere else you carry your own EE license. In other words, the 'free TDE' benefit is tied to the managed service, not to the cloud. If you lift your EE database into a cloud VM and run it yourself, you owe ASO exactly as you would on-premises. Model this carefully before any migration, because the cloud-versus-BYOL decision changes the security-option bill materially.

Database Vault and Label Security: Two Options, Two Bills

Database Vault and Label Security are the access-control pair. They solve different problems, and organizations frequently conflate them and buy the wrong one, or buy both when they needed one. Both are Enterprise Edition only. Both follow the database metric one to one. Both list in the same neighborhood on the processor metric (Label Security at approximately $11,500 per processor with roughly $2,530 per year in support; Database Vault in the same range on the lower of the two disputed figures) and roughly $230 per Named User Plus.

Database Vault isolates privileged users. Its headline use case is preventing a DBA, or anyone with the DBA role, from reading application data they administer but should not see. It enforces separation of duties inside the database, which is a common finding in SOX and PCI audits. Oracle positions it as a premium feature available only in the highest edition, which forces a licensing decision: an organization that requires Database Vault must license Enterprise Edition for the entire database, not merely for the schemas needing protection. If you are on Standard Edition 2 and a control mandate lands requiring privileged-user separation, you are not buying an $11,500 option, you are buying an edition upgrade that starts at $47,500 per processor and only then adds the Vault license on top.

Label Security implements row-level, label-based mandatory access control. Its natural home is government, defense, and classified-data environments where records carry sensitivity labels and users carry clearances. It is the wrong tool for simple privileged-user isolation, and it is over-licensed for most commercial compliance requirements. Buying OLS when you needed Database Vault, or vice versa, is a five-figure-per-processor mistake. Our side-by-side breakdown in Oracle Label Security vs Database Vault: Two Options, Two Bills maps each control mandate to the correct (and cheapest defensible) option, and flags where you can satisfy the requirement with free Enterprise Edition features instead.

On Standard Edition 2, a Database Vault mandate is not an $11,500 option. It is a $47,500-per-processor edition upgrade you did not budget.

Audit Vault and Database Firewall: Priced on What You Watch

Audit Vault and Database Firewall (AVDF) is the odd one out in Oracle's security lineup because it does not follow the standard option-inherits-database-metric rule, and it is easy to underestimate. AVDF centralizes audit-trail collection and provides a database firewall that inspects and can block SQL traffic. It is licensed separately, cited at approximately $20,000 per processor, with Named User Plus available by quote.

The critical distinction: AVDF is licensed on the processors of the monitored source targets, not on the AVDF server that does the collecting. There is no separate license fee for the servers where AVDF itself is installed. You pay based on the databases and targets you are watching. Every processor on every monitored target counts. In a Real Application Clusters environment, every node on the target must be licensed, so an AVDF deployment across a large RAC cluster scales its cost with the full node count of everything under surveillance.

This pricing model catches buyers who deploy AVDF to satisfy a centralized-logging control (common under SOX, PCI DSS, and various data-protection regimes) and assume the license attaches to the single AVDF appliance. It does not. If you point AVDF at 40 databases spanning 200 processors, you owe on all 200. Scope the monitored footprint deliberately before deployment, because expanding coverage later expands the license bill target by target. We break down the full model, including the free network-monitoring modes and how to scope collection to control cost, in Oracle Audit Vault and Database Firewall Licensing Decoded.

Oracle Key Vault: The One That's Actually Reasonable

Oracle Key Vault (OKV) is the rare Oracle security product with a sane, buyer-friendly license model, and it is worth understanding precisely because it is the exception. OKV is a centralized key-management appliance, typically deployed to hold and manage the TDE master encryption keys that Advanced Security uses. Its licensing is per OKV server installation with no per-processor cost. There are no restrictions on the number of endpoints connecting to the OKV server, and the license includes restricted-use licensing for the entire Key Vault stack (the underlying database and OS that run the appliance).

Read the boundary carefully. The restricted-use license covers the Key Vault stack only. It does not license your production databases, and it does not license Advanced Security on the databases whose keys OKV manages. Buyers occasionally assume that centralizing keys in OKV somehow relieves the ASO obligation on the databases using TDE. It does not. You still need Advanced Security on every database that encrypts data at rest, and OKV is a separate, additional (if modestly priced) product. We settle the 'is Key Vault free or extra' question definitively in Is Oracle Key Vault Free or a Separate License, including where the restricted-use grant ends and full licensing begins.

How Oracle Detects Security-Option Usage at Audit

The reason security-option non-compliance is so common, and so expensive, is that Oracle can prove usage from data your database records automatically. During a License Management Services audit, Oracle runs scripts against the DBA_FEATURE_USAGE_STATISTICS view, which the database populates on its own whether or not you licensed the feature. This view records that TDE was used, that Data Redaction was invoked, that Database Vault was enabled, and the high-water mark of that usage over time. You cannot un-see a feature that has been used. Even disabling it today does not erase the historical usage flag.

This is why 'we turned it off already' is not a defense. The audit script reports the first-usage date and the detected-usage count, and Oracle builds its finding from that record. A single encrypted backup taken two years ago and long since deleted still shows in the feature-usage statistics. The mechanics of reading this data yourself, before Oracle does, are covered in how to check Oracle license information the three reliable ways. Running that self-assessment quarterly is the single most effective control against a surprise security-option finding.

There is also an accidental-enablement pathway specific to security options. Certain features get toggled by DBAs testing capabilities, by database migration assistants, or by cloning a production database that had a feature enabled into a lower environment that then inherits the usage flag. Cloning a TDE-enabled production database into three test environments can multiply your ASO exposure across four servers from one act of enablement. We document the accidental-enablement patterns and the strip-and-prove remediation in Accidentally Enabled Security Options: The Audit Finding You Didn't Buy.

The Standard Edition 2 Squeeze

Every option in this article is Enterprise Edition only. That fact is the pivot point of Oracle's entire security-licensing strategy, and it is where the pressure lands hardest on cost-conscious buyers. If you run Standard Edition 2 (list $17,500 per processor, or $350 per NUP) specifically to control Oracle spend, you cannot license Advanced Security, Database Vault, Label Security, or the option-based security controls at all. Standard Edition 2 does not even include TDE.

When a compliance mandate requires encryption at rest or privileged-user separation on an SE2 database, Oracle's answer is not 'buy the option.' It is 'upgrade the whole database to Enterprise Edition, then buy the option.' That is a jump from $17,500 to $47,500 per processor for the edition, plus the option on top. For a shop that deliberately standardized on SE2 to avoid EE economics, an encryption mandate can multiply the per-processor cost by three or four in a single procurement cycle.

There are legitimate alternatives that do not require the EE upgrade, and you should exhaust them before conceding. Application-tier encryption, storage-level encryption below the database, third-party key management, and OS or filesystem encryption can each satisfy an at-rest mandate without triggering Oracle's option requirement, because they encrypt outside the database engine and therefore never touch DBA_FEATURE_USAGE_STATISTICS. The trade-offs (performance, key management, auditor acceptance) are real, but so is the seven-figure edition-upgrade avoidance. We lay out what you can and cannot do on SE2 in Security Options on Standard Edition 2.

Where the Leverage and the Risk Actually Sit

The risk sits with your DBAs and your security team, who can enable a $15,000-per-processor obligation with a one-line command and no license prompt, and with your compliance team, who hand down encryption mandates without knowing the Oracle price tag attached to native implementation. The gap between 'we must encrypt this data' and 'we have licensed Advanced Security' is where 40 percent of EE environments fail an audit.

The leverage sits in three places. First, in the free capabilities: native network encryption is free from 19c, several access-control patterns can be built without paid options, and non-database encryption paths can satisfy at-rest mandates on SE2. Use them and refuse the upsell. Second, in the audit timeline: because usage is self-reported by the database, you can find your own exposure before Oracle does, remediate or true up on your terms, and remove the surprise premium Oracle charges when it discovers the gap first. Third, in the negotiation: security options are frequently bundled into larger deals and ULAs, where the incremental cost of an option can be negotiated to a fraction of list, or where you can push back on including options you will never use. Our CIO playbook for optimizing Oracle Database licensing and options covers option rationalization as a renewal lever.

Find your own security-option usage before Oracle does. Self-reported feature statistics mean the audit finding is knowable, and therefore preventable, months in advance.

What to Do Now: The Buyer's Action List

Do not wait for an audit notice. Take these steps in order, starting this quarter:

  • Run DBA_FEATURE_USAGE_STATISTICS across every Enterprise Edition database and identify every security feature showing usage: TDE, Data Redaction, Database Vault, Label Security. Treat any first-usage date as a live exposure until proven licensed.
  • Reconcile detected usage against your certificate of licenses. Any security feature used but not licensed is a finding waiting to happen. Quantify the processor exposure per server at list before you decide how to respond.
  • Check your backup and Data Pump policies. Encrypted RMAN backups and encrypted exports trigger Advanced Security on the source database. If your backup policy encrypts by default, you may already owe ASO on databases you never intended to encrypt.
  • Separate free from paid. Confirm whether your network encryption is genuinely just TLS or native encryption (free from 19c) versus data-at-rest TDE (paid). Do not carry an ASO liability for a capability that became free.
  • Model cloud versus BYOL for any migrating database. TDE is included on OCI managed services and Database@Azure but not on BYOL Enterprise Edition. The security-option bill can vanish or persist depending on which path you choose.
  • For SE2 databases facing new encryption or access-control mandates, price the non-database alternatives (storage encryption, application-tier encryption, third-party key management) before accepting an Enterprise Edition upgrade you did not budget.
  • Scope AVDF deployments deliberately, remembering that you license the monitored targets and every RAC node on them, not the AVDF server.
  • Bring option exposure into your next renewal or ULA discussion as a negotiation item, not a compliance surprise. Discovered-by-you always beats discovered-by-Oracle.

Oracle's security options are not optional in the ordinary sense. Regulation forces you toward them, and Oracle prices that regulatory pressure into every processor. The buyers who control the cost are the ones who know exactly which controls are free, exactly what triggers the paid ones, and exactly what their own databases have already recorded. Everything in this guide points to the same discipline: measure your usage, separate free from paid, and never let a compliance mandate become an Oracle audit finding you did not see coming.

Frequently asked questions

Does using TDE always require the Advanced Security Option?

On Enterprise Edition BYOL, yes. Encrypting any data at rest with TDE (even a single column, one tablespace, or an encrypted backup) requires Advanced Security across every processor on that database, at $15,000 per processor list. The only exceptions are OCI managed database services and Oracle Database@Azure, where TDE is included by default. Standard Edition 2 does not support TDE at all.

Is Oracle network encryption free now?

Basic network encryption, including native encryption and TLS for data in transit, is free with Enterprise Edition from Oracle Database 19c onward and no longer requires Advanced Security. However, this only covers data in transit. Data-at-rest encryption (TDE) and Data Redaction still require the paid Advanced Security Option.

Can I license a security option on just some cores of a server?

No. Oracle prohibits partial licensing. Any server that uses a security option feature must be fully licensed for that option across every processor, matching the underlying database license one to one. Encrypting one column on a 16-core server obligates you for Advanced Security on the entire processor count of that server.

How does Oracle find out I used a security option?

The database records feature usage automatically in the DBA_FEATURE_USAGE_STATISTICS view, whether or not the feature is licensed. During an audit, Oracle's scripts read this view and report the first-usage date and detected usage. Disabling the feature afterward does not erase the historical record, so 'we turned it off' is not a defense.

What are the security options if I run Standard Edition 2?

Every Oracle database security option (Advanced Security, Database Vault, Label Security) is Enterprise Edition only. Standard Edition 2 does not support any of them and does not include TDE. Meeting an encryption or access-control mandate on SE2 means either upgrading to Enterprise Edition (from $17,500 to $47,500 per processor plus the option) or using non-database alternatives such as storage-level or application-tier encryption.

Is Oracle Key Vault a separate license I have to pay for?

Key Vault is licensed per server installation with no per-processor cost, and it includes restricted-use licensing for the entire Key Vault stack. It is inexpensive relative to the other options. But it does not license Advanced Security on the databases whose keys it manages. You still need ASO on every database that uses TDE, regardless of whether Key Vault holds the master keys.

Free White Paper

Oracle Database Options & Management Packs: the accidental-use audit trap

The separately-licensed options and packs that ship enabled by default, get switched on with a single click, and become the single largest line item in most Oracle audit findings.

Gated with a work email on the download page. No sales follow up you did not ask for.

Get the White Paper →
Independent, buyer side. We never share your details with vendors.
Run a software spend health check against your Oracle estate in under five minutes.
Open the Tool →
Deep Library

More on this topic.

Oracle Hub →
Oracle Database licensing. Editions, options, packs, and the moves on every renewal.
Oracle
Oracle Database licensing. Editions, options, packs, and the moves on every renewal.
Reference on Oracle Database licensing. Editions, options, packs, metrics, virtualization
Guide
Oracle Database Options & Management Packs Licensing
Oracle
Oracle Database Options & Management Packs Licensing
A buyer-side guide to Oracle Database options and management packs — the accidental-use tr
Guide
Oracle Database Options & Management Packs: the accidental-use audit trap
Oracle
Oracle Database Options & Management Packs: the accidental-use audit trap
The separately-licensed options and packs that ship enabled by default, get switched on wi
Guide
Editorial boardroom interior

The advisor your vendors do not want.

500+ enterprise clients. 11 vendor practices. Industry recognized. One conversation can change what you pay for the next three years.

Stay ahead of Oracle licensing changes.

One buyer side briefing a week. Renewal signals, audit moves, and the levers that work. No vendor spin.