A German automotive manufacturer ran a heavy VMware estate under an expiring Oracle ULA. Oracle moved to count every host in the cluster. Here is how the buyer side defended the certified number and protected the saving.
A German automotive manufacturer faced an Oracle ULA certification with VMware virtualization in scope. Oracle moved to count every host in two data centers. The buyer side defended the host count, certified favorably, and protected a saving of 30 to 45 percent, and the certified position now serves as the audit defense for years to come.
Most ULA coverage treats certification as paperwork and audits as a separate subject. This case argues they are the same subject: the certification is the one audit every ULA customer must face, and the posture built for it decides every Oracle inspection that follows.
An Oracle Unlimited License Agreement grants unlimited deployment of a named product set for a fixed term, usually three years, and ends with the customer certifying how much was deployed. That certification is, in substance, an audit you invite: Oracle reviews your declaration, tests it, and the agreed number becomes permanent.
The certified quantity converts into perpetual licenses, fixed for the life of the deployment. Oracle sets out the model in its Software Investment Guide. Everything in this case turned on what that one number would be.
During the term the customer deploys without counting. Most buyers treat this as a quiet phase. The buyer side view is the opposite: the term is when you build, document, and bound the certified position you will live with permanently.
At expiry the customer declares deployed quantities. Oracle reviews the declaration through its licensing review function, Global Licensing and Advisory Services, formerly known as License Management Services. The number that survives review becomes the permanent entitlement.
Treat the review as adversarial even when the tone is cordial. The reviewers' opening questions are drawn from the same playbook a formal audit uses, and the answers you give here carry the same weight.
Once signed, the certification letter cannot be reopened in your favor. Under count and you lose deployment headroom forever. Over count into contested territory and you hand the next audit team a declaration it can attack.
At three moments: during the unlimited term, at certification, and in the years after certification. The ULA changes what each audit can find, not whether Oracle can look, because the standard audit clause survives the agreement with its 45 days written notice intact.
The three ULA audit moments and what each one tests
| Moment | What Oracle tests | Your defense |
|---|---|---|
| During the term | Products outside the ULA set, options never included, entities and territory beyond the signed scope | A live register of what the ULA actually covers |
| At certification | The declared quantities, and every host the software could allegedly reach | Dated deployment evidence and the contract's scope language |
| After certification | Current deployment against the certified entitlement | The certification file, kept current as the estate changes |
The most common misreading of a ULA is that nothing can go wrong while it runs. The unlimited grant covers only the named products, for the named entities, in the named territory. Anything outside those three fences is ordinary licensable use, auditable at any time.
Three out of scope patterns account for most mid term ULA disputes we see:
A during term audit letter arrives like any other: from GLAS, under the audit clause, with 45 days written notice. The response discipline is identical to any Oracle audit, but the checklist starts with the ULA's definitions, because the dispute will live inside them.
Certification review needs no audit notice because the customer initiates it by declaring. That is precisely why posture matters: you choose the timing, you assemble the record, and you decide how much of the estate is contestable before Oracle ever looks. This manufacturer treated the declaration as a litigation grade filing, not a form.
Post ULA audits test today's deployment against the certified entitlement. A defensible certification makes those audits short, because the baseline is documented and was accepted by Oracle in writing. A sloppy certification does the opposite, inviting a fresh dispute over a number that can no longer be corrected.
Audit teams allocate effort where records are weak, because weak records settle. A certification accepted after evidence based review signals the opposite: this customer documents, contests, and does not pay anchors. In our benchmark file, cleanly certified estates saw notably less post ULA audit attention than estates that certified under deadline pressure.
Deterrence is not immunity. It is a change in expected value that moves your file down the list, and it is earned entirely during the term, when the evidence is cheap to capture.
On a VMware estate the certified number is not driven by how many database instances run. It is driven by which physical hosts Oracle argues the software could run on across the cluster, which is why cluster design decides more than deployment volume.
How Oracle and the buyer count Oracle on VMware
| Counting position | What it counts | Buyer side response |
|---|---|---|
| Every host in vCenter | All ESXi hosts the vMotion fabric can reach | Segment the cluster and pin Oracle to a defined host group |
| Cluster of record | Hosts in the cluster running Oracle | Document affinity rules and confirm in the contract |
| Contractual boundary | Only hosts named in the agreement | Hold the line on the signed product and territory scope |
Oracle does not recognize VMware as a hard partition. Its public partitioning policy treats soft partitioning as non binding for licensing, so the review team counts every reachable host by default. The full argument, and its weaknesses, are laid out in our guide to Oracle licensing on VMware in the Broadcom era.
The signed agreement, not the policy document, governs the certified number. Where the contract names a product set and a territory, that language caps the count. The processor core factor table then converts physical cores into licensable processors.
Broadcom's VMware repricing is pushing estates toward cluster consolidation and denser hosts, and every such redesign moves the boundary Oracle will count at certification. A consolidation that saves VMware subscription cost can widen the Oracle reachable fabric mid term without anyone noticing.
Any VMware redesign during a ULA term should be checked against the certification boundary first. Our UK media dual vendor case study shows what happens when the two vendors' decisions are sequenced deliberately instead of separately.
The manufacturer ran a large VMware estate across two data centers, and Oracle opened by counting every host in both vCenters. The buyer side narrowed that opening position to the hosts the contract actually covered, in three deliberate steps.
The three decision points that shaped the outcome
| Decision | The tempting option | What was chosen, and why |
|---|---|---|
| Disputed hosts | Concede them to close quickly | Contest from the contract, because the clause did not cover them |
| Declaration timing | Wait until the 30 day window | Prepare 270 days out, so the evidence predated the dispute |
| Renew or certify | Renew the ULA and defer the problem | Certify, because the defensible number was already built |
We pulled dated host inventories, affinity rules, and database deployment maps. The evidence showed Oracle ran on a defined host group, not the whole fabric.
Two properties made this evidence decisive. It was contemporaneous, captured during the term rather than reconstructed at the deadline, and it was independently verifiable from vCenter exports Oracle could not dismiss as narrative.
White Paper ยท Oracle
How to Exit an Oracle ULA Without Overpaying
The certification trap, the support reset, and the timing that protects your leverage. Read it free.
We mapped the certification clause against the deployment. The signed scope did not extend to hosts that never ran an Oracle workload. That reading removed the disputed hosts from the count.
This is the step most internal teams skip, because it is legal work rather than technical work. Yet in this engagement it carried more of the saving than any infrastructure change, since the clause, once read closely, simply did not say what the opening count assumed.
We drafted the certification letter to state the defended number precisely, with the supporting evidence attached. Oracle accepted the declaration after one review cycle.
Expect resistance at this stage and plan the response before it comes. Oracle routinely pushes back on declarations that shrink its expectations, a pattern we document in how Oracle tries to stop your certification.
The standard advice is to deploy as widely as possible before certification so the perpetual number is large. We disagree. In roughly three out of five VMware estates we certified, the wide deployment created audit exposure that cost more than the extra licenses were worth. The buyer side move is to deploy with intent onto a controlled host group, document the boundary as you go, and certify a clean defensible number. A smaller certified number you can prove beats a larger one Oracle can attack at the next audit. The certification is a legal event, not a land grab.
Source: Redress Compliance advisory engagement file, 2024 to 2025.
On VMware the certified number is decided by cluster design and contract language, not by how many databases you run. Win the boundary and you win the certification.
The manufacturer certified the defended number, protected a saving in the 30 to 45 percent band against Oracle's opening count, and converted the certification file into a standing audit defense. The perpetual entitlement matches the real deployment, and the record proves it.
Just as important is what did not happen. No hosts were conceded to buy goodwill, no renewal was signed to escape the deadline, and no side agreement complicated the entitlement. The close was a clean conversion of evidence into a permanent number.
The disputed hosts came out of the count. The certified processors reflected the dedicated Oracle host group, confirmed by the contract scope.
Measured against Oracle's opening position, the defended certification protected a saving in the 30 to 45 percent band. The number held at the following annual support review.
The saving also compounds quietly. The certified quantity feeds the support baseline, so a defended count protects the annual support line every year the estate runs, not just the certification event itself.
The failure modes are asymmetric, which is why preparation dominates. Each has a distinct price:
The engagement closed with the evidence bundle archived as a unit: inventories, affinity exports, the contract mapping, and the accepted letter. When a routine Oracle audit arrives years later, with its 45 days of notice, that file is the opening response.
The discipline that matters afterward is change control. Every cluster expansion or host refresh gets checked against the certified boundary before it happens, so the shield never silently drifts out of date.
If your ULA has 12 months or less to run, the certification clock is already consuming your leverage. Here is what to do next, sequenced from today.
An Oracle ULA certification is the declaration of deployed quantities at the end of the unlimited term. Oracle reviews the declaration and the agreed number converts into perpetual licenses for the life of the deployment.
Yes. The unlimited grant covers only the named products, entities, and territory, and the audit clause stays in force throughout. Products outside the set, options never included, and acquired entities are all auditable mid term with the standard 45 days written notice.
Yes, under the surviving audit clause, and the audit tests current deployment against the certified entitlement. A well documented certification makes that audit short. This is why the certification file should be archived and maintained, not filed and forgotten.
VMware matters because Oracle counts the physical hosts its software could run on, not the database instances actually running. On a shared cluster that can pull the count far above the real deployment.
No. Oracle treats VMware as soft partitioning under its public partitioning policy, so it does not limit the licensable scope. Buyers limit scope through cluster design and contract language instead.
No. The certification letter is permanent once signed. Under count and you lose deployment headroom forever, so the declaration must be accurate and defensible before it goes to Oracle.
Certification work should begin about 270 days before the ULA expiry. That window allows time to inventory the estate, capture affinity evidence, and model the defended number against Oracle's likely position.
A saving of 30 to 45 percent against Oracle's opening position is realistic on a well defended VMware estate. The exact figure depends on cluster design and the contract scope language.
Oracle ULA exit moves, certification framework, support reduction posture, and the buyer side moves across the Oracle Database, Java, and EBS estate.
Used across more than five hundred enterprise engagements. Independent. Buyer side. Built for procurement leaders running the next renewal cycle.