Oracle JDK 25 is free in production for roughly 36 months, until September 2028, not for the eight years of support Oracle advertises alongside it
Oracle's own download page grants free production use and free redistribution of JDK 25 under the No-Fee Terms and Conditions, but only until September 2028, one year after Java 29 ships. Support runs to 2033; the free grant runs three years, and the first post-window quarterly patch converts the estate to Java SE Universal Subscription terms at $15 per employee per month list. That gap between the support clock and the free clock is the whole decision.
Prepared by Redress Compliance · August 26, 2026 · Oracle Java advisory. NFTC and Universal Subscription engagements 2024 to 2026.
Executive summary
Java 25 is genuinely free for commercial production use and free to redistribute, but the grant expires in September 2028, roughly 36 months after the September 2025 release.
Oracle's JDK 25 download page and the JDK License General FAQs both state that updates continue under the NFTC until September 2028, one year after Java 29, and that subsequent updates move to the Oracle Technology Network License, where production use beyond narrow free grants requires a fee.
Oracle markets eight years of support and 2033 extended support dates in the same breath as "free," and buyers routinely conflate the two clocks: the support horizon is eight years, the free horizon is three.
Premier support runs to September 2030 and extended support to September 2033, but every build released after September 2028 is planned under OTN terms through at least September 2033, which means paid.
Nothing breaks on the cliff date; exposure begins the first time an engineer applies a post-window quarterly patch, because that specific build carries the paid licence.
Oracle keeps download URLs stable across update releases explicitly so scripts keep working, so an unmanaged CI pipeline or patching tool converts hosts to subscription terms one automated update at a time, with no purchase order anywhere in the chain.
The alternative to free is the Java SE Universal Subscription at $15 per employee per month list, counted against total headcount plus contractors, not against Java users.
A 5,000-employee organisation faces roughly $900,000 per year at list before volume tiering, which is why the 36-month window should be spent on an exit architecture rather than on a budget line.
The 2028 date is not fixed by contract; it floats with a release Oracle controls, because the grant is defined as one year after the next LTS.
If Java 29 slips from September 2027, the JDK 25 free window moves with it, and that dependency belongs in your risk register rather than in a spreadsheet cell marked "confirmed."
What the NFTC actually grants for Java 25, and when each grant stops
Read Oracle's own download page for JDK 25 and the grant is unusually generous by Oracle standards: free use for all users, explicitly including commercial and production use, and free redistribution of the binaries provided you charge nothing for the distribution.
The No-Fee Terms and Conditions cover runtime images produced by jlink, which matters if you ship trimmed custom runtimes rather than a full JDK.
And Oracle's own licensing FAQ treats hosted use, including third parties who consume a service without ever obtaining a copy, as use for internal business operations and therefore inside the grant.
That is the ceiling.
Below it sit restrictions that survive the word "free": included source code is reference-only and may not be modified, you may not reverse engineer, disassemble or decompile, you may not remove Oracle's or a licensor's proprietary markings, export control and sanctions compliance is yours.
Commercial Features remain outside the grant and attract fees, and there is no support guarantee at all.
NFTC is a licence, not a support contract. The single number that governs the whole decision is the expiry: JDK 25 receives quarterly updates under the NFTC until September 2028, after which subsequent updates move to the Java SE OTN License, planned to run until at least September 2033.
Support and free are two different clocks, and Oracle publishes them side by side without ever drawing the contrast.
| Clock or comparison | Date | What it means for you |
|---|---|---|
| JDK 25 NFTC free updates end | September 2028 | Last free production build; roughly 36 months from GA (September 2025) |
| JDK 25 premier support ends | September 2030 | Paid subscription only, two years after free ends |
| JDK 25 extended support ends | September 2033 | The "eight years of support" Oracle advertises, all of it paid after 2028 |
| JDK 25 OTN tail | Planned to at least September 2033 | Updates exist, but OTN's limited free grants exclude most production use |
| JDK 17 (precedent) | NFTC ended September 2024; 17.0.12 (July 2024) last free build | Every later 17.x release requires a subscription for production |
| JDK 21 (live example) | NFTC ends 16 September 2026; July 2026 last free build | October 2026 CPU is the conversion event happening now |
| JDK 26 (non-LTS) | Free under NFTC only to September 2026 | Six-month window, superseded by JDK 27 |
| Java 29 (next LTS) | Targeted September 2027 | The release that sets JDK 25's free expiry |
The table hides two things worth more than the dates themselves. First, September 2028 is not a fixed contractual date: it is derived, one year after Java 29, which Oracle currently targets for September 2027. If Java 29 slips six months, the free window moves.
You are planning a fleet-wide upgrade programme against a date Oracle can shift unilaterally, which is exactly why the deadline belongs in your internal roadmap as a range, not a milestone. Second, the restrictions are not cosmetic.
Breach one, decompile a class file to debug a vendor library, strip a proprietary notice during a repackaging step, ship a jlink image inside a product you sell, and you do not merely lose support. You lose the licence grant, and the installation becomes unlicensed rather than unsupported.
Those are different audit conversations with different price tags. Our 2026 Java version support cliff guide maps which builds fall off in which quarter.
"Free to redistribute" has a hard limit that catches ISVs
The redistribution grant is the clause most often misread, and the misreading is expensive.
Oracle's Donald Smith, announcing the NFTC in October 2021, stated that the licence "includes commercial and production use" and that "redistribution is permitted as long as it is not for a fee." That final conditional is the whole limit.
The Register's September 2021 analysis reached the obvious conclusion: because the NFTC forbids redistribution for a fee, it satisfies neither the Free Software Definition nor the Open Source Definition, both of which require that fee-based distribution be permitted.
So an ISV that embeds Oracle JDK 25 in a product sold for money is not covered by the free grant, regardless of how many end users would themselves qualify for free use if they downloaded the JDK directly.
The remedy is separate paper, an Oracle Binary License and Redistribution Agreement plus an Oracle Trademark License, required wherever your commercial distribution falls outside the relevant Java licensing manuals, negotiated bilaterally and priced accordingly.
Add to that the Commercial Features carve-out: no NFTC grant covers those, and a host running them owes fees whatever the base licence says.
The practical exposure is straightforward to identify and rarely identified. Any appliance image, container base layer, installer bundle, or on-premises deliverable that ships an Oracle JDK and carries a price tag sits outside the grant.
In our experience Oracle's audit teams find this in partner-facing collateral and support matrices long before they find it in a download log, and the counterparty is the vendor, not its customers.
If you are the buyer of that software, ask for the redistribution paper in writing before you renew, because Oracle's remedy against your supplier tends to arrive as a repricing of your own contract. Our note on which audit clause Oracle cites sets out how that claim gets framed.
What Oracle ERP Cloud really costs per employee
Oracle prices Fusion ERP Cloud per employee, not per user, which inflates true cost. The buyer side guide to module economics and the modernization discount.
Get the white paper →The patch pipeline is the licensing event, and Oracle designed it that way
Read the NFTC as a commercial instrument rather than a licence and its purpose becomes obvious: it is not a discount on Java, it is a version-migration mechanism.
Oracle's own licensing FAQ says the free grant on an LTS release runs one year past the next LTS, which means the grant is not calibrated to your estate's needs, it is calibrated to how fast Oracle wants the installed base to move forward.
The company has said as much in substance, and the advisory reading of it is consistent: Oracle's interest in the NFTC is moving customers onto newer Java versions. That reframing matters because it tells you where the enforcement surface sits. It is not the calendar.
Nothing in your environment changes on 15 September 2028. The binaries you already deployed keep running under the terms they were downloaded under. The licensing event is the next patch you apply.
The delivery mechanism is documented on Oracle's own download page: the download URLs remain the same for update releases to allow their use in scripts. That single design choice is what converts the estate.
Your automation, your golden images, your Ansible role, your Dockerfile base layer, all of them point at a stable URL and pull whatever Oracle has published there. In September 2028 that URL serves an NFTC build.
In October 2028, when the quarterly critical patch update lands, the same URL serves a build governed by the Java SE OTN License, under which production use beyond narrow free grants requires a fee. There is no licence prompt, no click-through, no procurement gate, no purchase order.
A host that patches in October 2028 has accepted paid terms without anyone in the organisation making a decision, and the acceptance is evidenced by an install log your own tooling produced.
This is not hypothetical, and buyers should stop treating it as a forecast. JDK 17 is the completed precedent: build 17.0.12, published July 2024, was the last free update, and every JDK 17 release after the NFTC window closed is licensed under OTN and requires a subscription for production use.
JDK 21 is the live example running right now. Its no-fee window closes 16 September 2026, the July 2026 quarterly update was the last free build, and the October 2026 CPU is the conversion event.
Anyone who wants to see how JDK 25 plays out in 2028 should watch what happens to JDK 21 estates this autumn, which we track in the JDK 21 free-update cutoff analysis. The pattern repeats because the mechanism is structural, not situational.
The structural consequence is harsher than the two-year LTS cadence suggests. To stay free, an organisation must complete a fleet-wide LTS upgrade, every host, every container image, every embedded runtime, every vendor appliance, inside twelve months of each new LTS shipping.
Certero states the rule the way Oracle's own licensing manuals imply it: where a v17-or-higher installation is not upgraded to the newest LTS within twelve months of that release, the host requires licensing under the Universal Subscription.
So the cadence is two years but the actual project window is one. In my experience, large enterprises do not complete Java runtime upgrades across 100% of an estate in twelve months.
They complete 85 to 95%, and the residue (test rigs, appliances, an ISV product whose vendor certifies only the older LTS) is exactly what Oracle's audit team asks for.
There is a second-order effect worth naming. The one-year overlap also means you are always exposed on two versions at once during the transition, and the fastest way to fail the test is not laziness, it is an ISV dependency you do not control.
If a third-party application supports only JDK 25 and its vendor certifies JDK 29 eighteen months late, your compliance depends on someone else's roadmap. That risk belongs in ISV contracts as a certification commitment with dates, not in your Java project plan as an assumption.
Leverage sits with the buyer who can prove two things: version control and removal capability.
If you can reconstruct exactly which build is installed where, which URL fetched it, on what date, and demonstrate that you can pull non-compliant runtimes out of the estate inside a patch cycle, then any Oracle claim shrinks to a defined, bounded population and a defined period.
The conversation becomes a negotiation. If you cannot reconstruct what patched when, Oracle's position is that your whole estate is subscribed, priced per employee, and you have no factual basis to dispute it.
That is not an audit outcome, it is an evidence outcome, and it is decided years before the letter arrives.
The practical test is simple and most estates fail it: pick any three production hosts and produce, in under an hour, the exact JDK build string, the source URL, the download date, and the change record.
If you cannot, you do not have a licensing position, you have a negotiating disadvantage that compounds every quarter until the CPU that converts you.
Treat patch automation as a licensing control, not an operations task. Pin versions explicitly, mirror approved builds internally, and put a hard block on any pipeline that fetches Java from a stable Oracle URL without a version pin.
That single change is the cheapest insurance in the entire Java estate.
What the paid path costs if you let the window close
If the window closes and the estate keeps patching, the price is not a per-server figure you can contain, it is the Java SE Universal Subscription, listed at $15 per employee per month with volume tiers stepping down to $5.25 and below above 50,000 employees, on a one-year standard term.
The metric is the whole problem. Oracle's Employee definition covers full-time, part-time and temporary staff plus agents, contractors, outsourcers and consultants supporting internal operations, counted at the order effective date, and it is entirely independent of who touches Java.
Fifty developers running JDK 25 in one product team produce a bill sized by headcount across the entire organisation, a dynamic we quantify in the 50-developers, 10,000-employees breakdown. Below is the arithmetic at three common sizes, at list, before discount.
| Employee count | List rate per employee/month | Annual list cost | 3-year list exposure |
|---|---|---|---|
| 1,000 | $15.00 | $180,000 | $540,000 |
| 5,000 | $15.00 (tier dependent) | $900,000 | $2,700,000 |
| 25,000 | tiered, below $15 | $2,000,000 to $4,500,000 range | $6,000,000 to $13,500,000 |
Two readings matter. First, the delta between a 50-seat technical footprint and the invoice is not marginal, it is two to three orders of magnitude, which is why the subscription is best understood as an organisational tax triggered by a technical event.
Second, the one-year standard term looks like flexibility and is not: Oracle prices multi-year commitments better, and a one-year term hands the vendor a renewal negotiation annually against an installed base that has already deployed.
Buyers who convert under audit pressure sign the worst version of this deal, at list, on Oracle's paper, with backdated exposure folded in.
The alternative costs are real but bounded: an OpenJDK migration, or a commercially supported non-Oracle build, generally lands in the low hundreds of thousands for a large estate. Price both before September 2028, not after the first post-window CPU has already answered the question for you.
The evidence base: what Oracle publishes, where sources conflict, and the recurring patterns
Build your file in this order, because Oracle's own documents outrank every commentary including ours.
Tier one is Oracle's Java Downloads page, which states JDK 25 is free to use in production and free to redistribute under the NFTC and receives NFTC updates until September 2028, and the JDK License General FAQs, which explain why: September 2028 is one year after Java 29.
Currently planned for September 2027.
Tier two is the 16 September 2025 launch press release, which pairs the September 2028 NFTC cutoff with OTN-licensed updates planned to at least September 2033.
And the Java SE Support Roadmap, which confirms the two-year LTS cadence and the premier/extended support dates (September 2030 and September 2033).
Tier three is the Java SE Universal Subscription price list PDF at $15 per employee per month list, the only defensible source for what the paid path costs.
Tier four is third-party corroboration: Azul on the JDK 21 July 2026 last free build, BellSoft on JDK 17's 17.0.12 as the last free update, Certero on the redistribution-for-fee limit and the twelve-month upgrade rule.
And InfoQ quoting Oracle's Donald Smith in October 2021 that redistribution is permitted only where it is not for a fee.
Sources conflict, and you should expect Oracle's field teams to exploit that.
At least one advisory places the JDK 25 free window near September 2029, which contradicts Oracle's own September 2028 statement.
And the JDK 17 precedent is quoted variously as September 2024 or September 2025 depending on whether the writer means the last free build or the last NFTC-eligible update.
There is also a genuine floating element: the 2028 date is defined relative to Java 29, a release Oracle controls, so a slip in the LTS cadence moves your cliff. Do not cite advisories in your internal decision paper. Cite Oracle's page, capture the URL, and record the retrieval date.
Oracle advertises eight years of Java 25 support while the NFTC grant runs roughly three, from September 2025 to September 2028.
One post-window quarterly patch moves the estate onto Java SE Universal Subscription terms priced on total employee count, not Java users.
Three patterns recur across engagements. First, support dates quoted as free dates: architecture teams read "supported to 2033" in a vendor deck and plan a five-year standardization on JDK 25 that has a licensing cliff in year three.
Second, unmanaged patch automation, because Oracle keeps download URLs stable across update releases specifically so scripts keep working, which means the same pipeline that patched you free in July patches you paid in October.
Third, estates that cannot reconstruct which build ran when, which is fatal in an audit because the whole defense rests on proving no post-window build ever landed.
If your version-by-version free versus paid mapping lives in someone's head rather than in evidence, you do not have a defense, you have an assertion.
- Percentile standing for your exact deal size and industry, from real closed transactions
- Scenario simulation before the call: test alternative terms and see the financial impact of each
- A negotiation playbook, talking points, and a two page executive brief on day one
Your first five moves
- Pin the builds and freeze the patch source before October 2028, which means moving JDK 25 off Oracle's public download URLs onto an internal artifact repository with a named owner, so that no CI job, container base image, or configuration management run can pull a post-window build by default.
- Inventory by full build string, not by major version, capturing 25.0.x on every host, container image, jlink runtime, and developer laptop, with evidence retained for at least the audit lookback period, because the only durable defense against a post-2028 claim is proof of which build ran on which date.
- Set an internal decision deadline of September 2027 on upgrade-to-29 versus migrate-to-OpenJDK, twelve months ahead of the window, and give it to a single accountable owner with budget, because both paths need a fleet-wide project and a decision made in mid-2028 will default to buying the subscription.
- Screen every ISV and embedded runtime for redistribution-for-fee exposure, asking each vendor in writing whether their product ships an Oracle JDK, under which license, and whether they hold a BLRA and Trademark License, and keep the answers, since a supplier's non-compliance becomes your unlicensed installation.
- Capture Oracle's stated dates as dated evidence today, archiving the download page, the license FAQ, and the roadmap with retrieval timestamps in your contract file, so the floating September 2028 date cannot be quietly re-narrated later; pair this with the 2026 version support cliff analysis to see how the same mechanism is already converting JDK 21 estates.
Frequently asked questions
Is Java 25 free for commercial production use?
Yes. Oracle's JDK 25 download page grants free use in production, including commercial use, under the No-Fee Terms and Conditions, and also permits redistribution provided you do not charge for it.
The grant covers runtime images produced by jlink and hosted or SaaS use where third parties never receive a copy. The limit is time: updates continue under the NFTC only until September 2028.
When exactly does Java 25 stop being free?
Oracle states that JDK 25 updates are planned under the NFTC until September 2028, one year after Java 29, which Oracle currently targets for September 2027.
Updates released after that date are planned under the Oracle Technology Network License, which Oracle intends to maintain until at least September 2033. Because the date is derived from the next LTS, a slip in Java 29 moves the free window with it.
Doesn't Oracle say Java 25 is supported for eight years?
Oracle does say it will provide long-term support for at least eight years, with premier support to September 2030 and extended support to September 2033. Those are support dates, not free dates.
The free portion is roughly three years; everything after September 2028 is planned under paid OTN terms, so eight years of support means five years of paid support following three years of free.
What happens to my estate on the day the NFTC window closes?
Nothing breaks and nothing changes on the installed base. Builds you already downloaded under the NFTC remain under the terms you accepted.
Exposure starts when someone applies the first quarterly update released after the window, because that specific build carries the paid licence, and Oracle keeps download URLs stable across update releases so automated scripts pull it without any prompt.
Can I ship Oracle JDK 25 inside a product I sell?
Not under the NFTC alone. The redistribution grant applies only where you do not charge for the distribution, which is why the NFTC does not meet the Open Source Definition.
Commercial distribution outside the relevant Java licensing manuals requires an Oracle Binary License and Redistribution Agreement plus an Oracle Trademark License. If you sell software that embeds Oracle JDK 25, get that position confirmed in writing before shipping.
What does the paid alternative cost if I miss the window?
The Java SE Universal Subscription lists at $15 per employee per month, with published tiers falling to $5.25 and lower above 50,000 employees, on a standard one-year term.
Employee counts every full-time, part-time and temporary employee plus agents, contractors, outsourcers and consultants supporting internal business operations, regardless of who uses Java. At 5,000 employees that is roughly $900,000 per year at list.
Should I plan to stay on the free path indefinitely?
Only if you can commit to a fleet-wide LTS upgrade project roughly every two years, with the newest LTS deployed inside twelve months of its release. That is a standing programme cost, not a one-off.
Most estates with mixed versions and unmanaged patch automation find the OpenJDK distribution route cheaper and less time-boxed than repeatedly chasing Oracle's floating window.