Four licences in seven years, each with a date attached. This is the version by version map of what Oracle actually gives away, what it charges for, and what to verify before you build a business case on it.
Java the language is free, OpenJDK is free, and every mainstream non Oracle build is free in production with no clock attached. What costs money is one vendor's build outside one licence window, and the price is set against your entire headcount rather than your Java usage.
The question sounds simple and the honest answer has a date attached to almost every part of it. Oracle has changed the licence terms on its Java builds three times since 2018, and each change applied to new downloads rather than to what you already had.
So the useful version of the question is not which Java is free. It is which build, at which patch level, downloaded on which date, under which licence, for which kind of use.
Every mainstream build except Oracle's own, and Oracle's own only inside a bounded window. The distinction is the licence file that shipped with the binary, not the version number on the box.
Each one grants a different set of rights, and all four are still live somewhere in a typical estate. Identify the licence before you argue about the version.
The four licences, what they allow, and where they still apply
| Licence | Applies to | Commercial production use | The catch |
|---|---|---|---|
| Binary Code Licence | Oracle Java 8 up to and including 8u202, January 2019 | Free | Closed to new builds in April 2019, so the estate is frozen at an old patch level |
| Oracle Technology Network licence | Java 8 from 8u211, Java 11 through 16, and Java 17 from 17.0.13 | Not free | Permits only personal use and development use, both narrowly defined |
| No Fee Terms and Conditions | Oracle JDK 17 and later, from September 2021 | Free inside the window | The window closes about a year after the next long term support release ships |
| GPL version 2 with Classpath Exception | OpenJDK source and every mainstream build of it, including Oracle's own | Free, permanently | Oracle publishes updates to its own GPL builds for about six months per release |
These are distributions of OpenJDK under the GPL with the Classpath Exception. There is no employee metric, no download log to reconcile and nothing for Oracle to audit.
Choosing between them is a separate exercise, and the criteria that matter are support windows, platform coverage and patch cadence rather than price. The distribution choice guide covers how to write that as a standard.
Oracle publishes GPL licensed builds of OpenJDK at jdk.java.net. They are genuinely free for any purpose, including commercial production, and they carry no subscription risk.
The catch is the update tail. Oracle stops publishing updates for these builds roughly six months after the release, when the next feature release ships.
An estate standardized on them has to move release to release every six months to stay patched. That is a valid strategy for a small, well automated estate and a poor one for anything else.
At a specific, published date per release. This is the map, and every row has a date because every row changed on one.
Oracle JDK free commercial use, release by release, as at July 2026
| Release | Last free build for commercial use | Free window ends | Status today |
|---|---|---|---|
| Java 8 | 8u202 | April 2019 critical patch update | Any build from 8u211 onward needs a subscription |
| Java 11 | None from Oracle | Never opened | Oracle builds were paid from general availability in September 2018 |
| Java 17 | 17.0.12 | September 2024 | Closed. Builds from 17.0.13 carry the paid terms |
| Java 21 | The July 2026 update | 16 September 2026 | Closing. The next quarterly update is the paid one |
| Java 25 | Not yet reached | September 2028 | Open. Free for commercial production use today |
| Non long term support releases | The final update of each | About six months after release | Free but unsuitable as an estate standard |
JDK 21 leaves the No Fee Terms on 16 September 2026, and the July 2026 quarterly update was the last free build. That makes this a live problem rather than a planning problem for anyone running Oracle JDK 21 in production.
The trap is the shape of it. Nothing breaks on 17 September, and nothing on your estate changes. The exposure only starts when someone applies the October critical patch update, which is the fix your security policy will require.
You therefore have two lawful positions after the window: run the July 2026 build unpatched, or stop running Oracle's build. Only one of those survives a security review.
Oracle does not need you to buy anything on the day the window shuts. It needs your security team to apply the next patch, which they will, because that is their job.
Every date above is a published Oracle position, and Oracle has revised its Java terms three times since 2018. Verify against the primary sources and keep the evidence.
Both are narrower than the words suggest, and both are defined by Oracle rather than by ordinary English. This is where most accidental exposure is created, because the words sound generous.
Oracle's Java licensing material gives worked examples, and they are usefully blunt. Running Java for homework or a personal tax return is personal use. Running it for business accounting is not.
The test is the purpose of the activity, not the ownership of the device or the identity of the person. A finance analyst using a Java based tool on a home computer for company work is commercial use.
The Oracle Technology Network licence permits developing, testing, prototyping and demonstrating applications. It does not permit running the application for your own internal business operations.
That argument is winnable in places and expensive to lose everywhere. The safe answer is that development use is a licence for building the thing, not for running the business.
A Java install on a company issued laptop is commercial use in every practical scenario, because the laptop exists for company work. The personal use grant does not travel with the person.
This matters more than it sounds, because desktop installs are the least governed part of most estates. They are also the easiest for Oracle to evidence, since the update check phones home.
By vendor and patch level, not by version number. A Java 8 install tells you nothing on its own, because 8u202 is free and 8u211 is not, and both report as version 1.8.
Capture all four before you remove anything. Deleting a binary before you record its install date and patch level destroys the evidence that limits how far back a claim can reach.
Because Oracle can see the downloads. Update requests and downloads tied to your corporate domain are matched against subscription records, and the soft outreach that follows is the opening of an audit funnel.
The pattern is consistent enough to plan against. If your security team has been diligently patching Oracle Java 8 or Java 17 past the boundary builds above, assume Oracle already knows.
Standardize on one non Oracle HotSpot build, replace wave by wave, and close the door behind you. The runtime swap itself is rarely the hard part.
The mechanics of the swap, including what genuinely differs between two builds of the same release, are set out in the Oracle Java versus OpenJDK binary comparison. The timeline and the governance gates are in the migration timeline guide.
Isolate them and ask the vendor for a written position on a HotSpot OpenJDK build of the same release. In our file they were a small minority of workloads.
Remember what isolation does not fix. Because the subscription is priced per employee, one isolated Oracle workload still prices your whole workforce, so isolation buys time rather than money.
The standard advice is to stay inside the No Fee Terms window and simply upgrade to each new long term support release as it lands, keeping Oracle's build for free forever. We disagree. In roughly 30 to 40 Java reviews Fredrik Filipsson advised in 2024 and 2025, not one client managed to move an entire estate inside a window on Oracle's schedule, because the window is set by Oracle and your change freeze calendar is not. What actually happens is that ninety percent of the estate moves, the last ten percent slips past the date, someone applies a patch, and the per employee subscription attaches to the whole workforce anyway. The free window is a real grant and a bad foundation. If you would not accept a supplier setting your upgrade calendar, do not accept this one.
Three cuts of the advisory engagement file frame the size of the problem and the size of the fix.
Source: Redress Compliance advisory engagement file, 2024 to 2025.
White Paper · Oracle
Oracle Java Audit Defense 2026
Oracle now audits Java SE on employee count, not installs, which can multiply the bill several times over. Read it free.
OpenJDK and every mainstream build of it are free in production with no window, including Eclipse Temurin, Amazon Corretto, Azul Zulu builds, BellSoft Liberica and the Microsoft Build of OpenJDK. Oracle's own JDK is free only inside the No Fee Terms window, which currently covers JDK 25 until September 2028 and JDK 21 until 16 September 2026.
Only up to update 8u202, released in January 2019. From the April 2019 critical patch update Oracle moved Java 8 to the Oracle Technology Network licence, and commercial users have needed a subscription for updates since then. Oracle continues to offer free Java 8 updates through java.com for personal and development users only.
Not from Oracle. Java 11 shipped under the Oracle Technology Network licence at general availability in September 2018, so Oracle's builds have never been free for commercial production use. OpenJDK builds of Java 11 from Temurin, Corretto, Zulu and others are free and always have been.
On 16 September 2026, and the July 2026 quarterly update was the last free build. Nothing breaks on that date, but the next security patch carries the paid terms, which is why the exposure usually starts with a routine patch rather than a decision.
No. Oracle's own examples of personal use are homework and a personal tax return, not business accounting, and a company issued laptop exists for company work. The personal use grant follows the purpose of the activity, not the ownership of the machine.
Partly, and less than most teams assume. The Oracle Technology Network licence covers developing, testing, prototyping and demonstrating applications, but not running an application for your own internal business operations. A build agent producing production artifacts and a staging environment used to certify releases both fall outside it in Oracle's reading.
Yes, and permanently, because they ship under the GPL with the Classpath Exception. The limitation is not licensing but maintenance: Oracle stops publishing updates about six months after each release, so an estate standardized on them has to move release to release to stay patched.
Yes, because the Java SE Universal Subscription is priced per employee across the organization rather than per install or per user. One out of window Oracle install on one server prices your entire workforce, which is why partial cleanup delivers no saving at all. The mechanics are set out in the Oracle Java licensing pillar.
The Java audit funnel, the per employee metric, and the migration plan off paid builds.
Used across more than five hundred enterprise clients. Independent. Buyer side. Built for procurement leaders running the next renewal cycle.
One forgotten Oracle JDK install prices against your entire headcount. The inventory scan is the cheapest insurance in software.
500+ enterprise clients. 11 vendor practices. Industry recognized. One conversation can change what you pay for the next three years.
One buyer side briefing a week. Pricing moves, audit signals, and the levers that work. No vendor spin.