Analysis
Establish Scenarios That Require an Oracle Java SE Subscription
The first step in managing your exposure is to determine what scenarios require an Oracle Java SE subscription. The practical output to the “what is required” question for any given organization depends on which Java products you use. However, you must begin by establishing how relevant products are licensed, which can later be reconciled against which products have been downloaded and deployed into your environment.
If anyone in your organization has downloaded any Oracle Java SE updates since April 2019, you probably need a subscription — and you may have a compliance risk. You may determine that you want an Oracle Java SE subscription if you want a commercial support agreement, particularly if you are using a very old or new release of Java, such as Java 7 or 21.
If you use Oracle Java SE runtimes, you probably need an Oracle Java SE subscription.
Oracle’s commercial Java SE products are called Oracle JDK, which distinguishes the commercial products from the open-source reference implementation, OpenJDK (see Note 1). OpenJDK is free, but updates from Oracle are available only for the latest release. Oracle JDK typically requires a support subscription for production workloads. Oracle provides quarterly updates for the current and long-term support (LTS) releases, including Java 8, 11, 17 and 21.
The Oracle JDK products include the Java development kit (JDK) and the Java runtime environment (JRE). The subscription licensing requirement applies to the runtime environment. You are not required to purchase a subscription for development, testing and demonstration activities. However, developers often use production development tooling as part of their work and, therefore, typically must be licensed.
Oracle has different licensing requirements for different releases of Oracle JDK. See Note 2 for more specific information about these releases and their licensing requirements.
Java 17 and Later Releases
Starting in September 2021 with the release of Oracle JDK 17, Oracle began licensing new releases under the NFTC license.4 Oracle allows free use of these releases and will provide free updates for LTS releases until one year after the next LTS release. New LTS releases are published every two years. For example, Oracle provided free updates for Oracle JDK 17 until September 2024 and will provide free updates for Oracle JDK 21 until September 2026.5
Future Java 17 Updates, Java 11 and Java 8 Updates Since April 2019
The NFTC license has expired for Oracle JDK 17, and all releases starting with Oracle JDK 17.0.12, released in October 2024, are licensed under the Oracle Technology Network (OTN) license agreement for Java SE. Oracle also licenses Oracle JDK 11 and all quarterly updates for Oracle JDK 8 that have been released since April 2019 under the OTN license. The OTN allows free use for development and testing but requires the purchase of an Oracle Java SE subscription for production workloads.6 The first Oracle JDK 8 update that requires a subscription is JDK 8u211. All releases of Oracle JDK 11 require a subscription.
Java 8 Updates Before April 2019
Oracle previously licensed Oracle JDK 8 under the Oracle Binary Code License (BCL) agreement, which was free to use, with some exceptions.7 Oracle provided free quarterly updates until January 2019. The last free Oracle JDK 8 update was JDK 8u202, released in January 2019.
As of October 2024, Oracle has released 213 security patches since the last free update.8
Bundled Oracle JDK Licenses
Oracle includes a restricted-use license to use Oracle JDK with all licensed Oracle applications and middleware that require Java — although that license applies exclusively to Oracle applications. The bundled license applies to applications running on Oracle Fusion Middleware and Oracle’s stand-alone middleware products. Oracle also includes a restricted-use license for all releases of Oracle JDK for software deployed on Oracle Cloud Infrastructure (OCI) and a restricted-use license for Oracle JDK 8 for software deployed on Oracle Private Cloud Appliance (PCA). A handful of third-party vendors have redistribution agreements with Oracle and provide a restricted-use license to use Oracle JDK exclusively with their products.9,10
The best way to eliminate your need to purchase an Oracle Java SE subscription is not to use Oracle JDK. If you use Oracle JDK (even if you have bundled licenses) or if anyone in your organization has downloaded a Java update since April 2019, Oracle will pressure you to purchase a subscription. The exceptions that allow free use of Oracle JDK include:
Running Java workloads on OCI or PCA
Running Java applications that include a bundled license to use Oracle JDK
Using Oracle JDK for development use only
Using Oracle JDK 8 versions released before April 2019 — JDK 8u202 or an earlier version
Using Oracle JDK 17 versions released before October 2024
Using Oracle JDK 21 or a later release
If you have any Java applications that use Oracle JDK and aren’t included in this exceptions list, then Oracle requires you to purchase an Oracle Java SE subscription.
Figure 2 provides a decision tree to help you determine when an Oracle Java SE subscription is required.
Figure 2: When Is an Oracle Java SE Subscription Required?

Inventory Oracle Java SE to Determine Your Exposure
Start your preparation for negotiations by creating an inventory of your current usage (see Figure 3). To determine your exposure, you must understand where you have Oracle JDK deployed, which applications are using it, which versions of Oracle JDK those applications are using and whether you are using Oracle JDK for development or production use.
Work with your software asset management (SAM) function, applications and operations leaders to create this inventory. If possible, your documentation should show evidence of when the software was deployed or removed. Don’t regard this inventory process as a single-point-in-time exercise. You will need to regularly maintain the inventory to ensure compliance.
If you currently have an Oracle Java SE subscription, you can use the Oracle Java Management Service (JMS) to create your inventory. Oracle states that it does not have access to the data collected by this service. If you don’t have a current subscription, you can identify where Java is deployed by using a SAM tool, SAM managed services provider or an endpoint management tool.
You can also analyze your application and server configurations. If you don’t have SAM tooling, you may need to identify Java installations by searching for filenames. There’s no definitive method to identify the applications that use Oracle JDK without the Oracle JMS.
Figure 3: Inventory Your Current Oracle JDK Usage

Capture specific details about your Java applications:
Java applets: Do you have any web applications that contain Java applets? The Java Plug-In that supports applets is proprietary software in Oracle JDK 8, and it’s not included in the open-source OpenJDK codebase. You must deploy Oracle JDK on each desktop that accesses an applet application. Note that applets can run only in Microsoft Edge in Internet Explorer mode. You should prioritize the modernization of these applications.
Server virtualization: Do you use a virtualization system other than Oracle Linux Virtualization Manager? If so, Oracle typically requires you to count every physical core in the virtualization estate to calculate the Processor license count, regardless of the number of virtual cores running Oracle JDK or the number of applications using Java.11
Third-party applications: In the past, many application vendors would bundle Oracle JDK with their products. The 2019 licensing change prohibits third parties from distributing Oracle JDK 8 and 11 unless they obtain a redistribution agreement. The NFTC license allows redistribution of Oracle JDK in free software, but for-fee software vendors must also obtain a redistribution agreement. Only a handful of vendors have secured this type of redistribution agreement. Some application vendors now distribute one of the third-party OpenJDK products, while others make Java the SPVM leader’s responsibility. Check with your application vendors to determine what their Java licensing position is. You may need to renegotiate your support agreements to ensure support for a third-party Java product.
If you are running Oracle JDK, it is your responsibility to ensure that you are properly licensed, even if the product was installed via a third-party application.
Calculate Your Annual Subscription Fees
Oracle revised its subscription model in January 2023. The current Oracle Java SE Universal Subscription is sold under an Employee metric, which requires licensing all employees in an organization, regardless of whether they are using Oracle JDK. Employees are defined as full-time, part-time and temporary, including all agents, contractors, outsourcers and consultants that support your internal business operations. See Note 3 for Oracle’s definition of the Employee metric and the legacy licensing metrics: Processor and NUP.
The list price for an Employee license is $15 per month, with published tiered discount pricing rates.12 Oracle prefers to offer the subscription in annual increments and often offers better terms for multiyear contracts (see Note 4). The subscription covers usage across desktops, servers, containers and third-party cloud deployments — although it imposes a limit of 50,000 licensed processors (see Note 3). Desktops and laptops are excluded from the processor calculation. Organizations that exceed that limit must obtain supplemental Processor licenses. Oracle does not publish a price list for these supplemental Processor licenses.
Before January 2023, Oracle offered two separate Oracle Java SE subscriptions — one for desktops and the other for servers. Subscribers were required to purchase both subscriptions if they deployed Oracle JDK on desktops and servers. Although Oracle no longer offers the legacy subscription model to new customers, existing customers can renew under the legacy terms. Oracle no longer publishes the price list for the legacy model, and prices may vary (see Note 5):
The Oracle Java SE Desktop Subscription was sold under the NUP metric (see Note 3). It requires licensing all users permitted to access a physical desktop or Amazon WorkSpace with Oracle JDK installed. Virtual desktops are licensed via the server subscription. The list price for an NUP license was $2.50 per month, with defined tiered discount pricing rates.
The Oracle Java SE Subscription was sold under the Processor metric (see Note 3). It requires licensing all physical cores where Oracle JDK is or may be installed or executed. Using server virtualization typically requires licensing every physical core of the physical hosts in your virtualization estate. The list price for a Processor license was $25 per month, with defined tiered discount pricing rates. The discount rates for the Oracle Java SE Desktop Subscription and the Oracle Java SE Subscription were calculated separately.
When preparing for a negotiation, you should calculate the subscription cost using both the old and new metrics.
The legacy subscription model required clients to conduct extensive inventories to determine where Oracle JDK was deployed and to count all desktop NUPs and server processors. The new subscription model is supposedly simpler because you only need to count employees. However, counting agents, contractors, outsourcers and consultants can also be a burden. Large organizations will still need to calculate Processor license requirements because of the processor cap.
Many clients are not happy with the simplicity-versus-price trade-off. Organizations with few employees will benefit from the new subscription model. However, most clients that Gartner has spoken to since the subscription model change indicate that the new subscription model is two to five times more expensive than the legacy model.13 Regardless of which subscription model you choose, you should prepare detailed documentation about where and how you use Oracle JDK.
If you use server virtualization, you may be able to reduce your processor count by creating an isolated cluster partition that doesn’t share any compute, storage or networking with other clusters. This partitioning can reduce subscription fees for organizations purchasing the legacy Oracle Java SE subscription or those purchasing the Oracle Java SE Universal subscription if they have more than 50,000 Processors (see Note 6). Oracle approves partitioning on a case-by-case basis. Most clients tell Gartner the isolation requirements are untenable. Also, the approval becomes invalid and must be renegotiated if any changes are made to the documented environment.13
Oracle Vigorously Pursues License Compliance
According to Gartner client interactions, Oracle actively targets organizations on Java compliance — with existing Oracle customers and companies without other Oracle products — and deploys its global Java licensing team to enforce compliance.14 However, most of this activity is in the form of compliance tactics and threats versus official audits. For example, Oracle may notify clients of Java licensing changes or compliance issues and request time to discuss the matter.
Under the legacy Oracle Java SE subscription, clients may be asked to provide Java deployment information, run Oracle scripts or provide hypervisor environment specifics. Under the Oracle Java SE Universal Subscription, Oracle may assert compliance issues based on publicly available employee counts.14 Oracle has emphasized strong growth rates in Java, which could be an incentive for continued monetization of Java compliance.15,16 If no official audit or compliance review letter has been provided, validate your information-sharing obligations in the applicable Oracle agreement. Treat soft audits as you would an official audit. If Oracle has contacted you about Java, see Avoid These Licensing and Pricing Pitfalls When Negotiating Oracle Deals. Evaluate Your Options
Now that you have a sense of what an Oracle Java SE subscription will cost, you need to decide what to do. Your options are:
Revert to the last free update — that is, JDK 8u202. This option is simple, inexpensive and very risky.
Upgrade to free-to-use Oracle JDK 21. This option requires a significant amount of software engineering work, and it’s unlikely that you will be able to upgrade all your applications.
Upgrade and migrate to the latest release of OpenJDK. This option requires a significant amount of software engineering work, and it’s unlikely that you will be able to upgrade all your applications.
Switch to a third-party Java product. This option requires a bit of testing but, generally, no reprogramming, and it is quite viable.
Move all your Oracle JDK workloads to OCI or PCA. This option requires porting, configuration and testing. Still, it is quite viable.
Purchase an Oracle Java SE subscription. This option is simple but expensive.
You can implement a combination of these options. For example, you can switch most workloads to a third-party Java product and move all remaining workloads to OCI. However, to avoid purchasing an Oracle Java SE subscription, you must ensure that you have removed all unlicensed Oracle JDK workloads from non-OCI or PCA systems.
Suppose you have a mix of licensed Oracle JDK workloads and other Java applications using a third-party OpenJDK running in the same virtualization estate. In that case, Oracle may assert that other Java applications could use Oracle JDK — and, therefore, must be licensed. If you are in this situation, you will either need to fully isolate the Oracle JDK cluster from other applications or deploy all Oracle JDK workloads to OCI to avoid purchasing an Oracle Java SE subscription (see Note 6).
If you have just one unlicensed application using Oracle JDK, you must purchase an Oracle Java SE subscription.
Figure 4 illustrates critical criteria for the available options.
Figure 4: Evaluate Options

Option 1: Reverting to the Last Free Update
This option is very risky. It has no subscription fees and requires modest effort by the organization to remove all deployments of Oracle JDK after JDK 8u202. However, your chief information security officer (CISO) should veto this option. As of the October 2024 update, the OpenJDK project has fixed 213 critical bugs and security vulnerabilities since JDK 8u202, which was released in January 2019. Nearly all these vulnerabilities can be exploited over a network without authentication. Also, there’s a risk that some application vendors won’t support their products on this vulnerable release.
This option should be used only as a short-term solution while implementing an alternative solution. To mitigate the risk, consider deploying a virtual patching system. However, virtual patching will impact performance.
Option 2: Upgrading to Free-to-Use Oracle JDK 21
Upgrading to Oracle JDK 21 could eliminate the requirement to purchase an Oracle Java SE subscription, but it requires a significant amount of time and effort to upgrade your applications so they can run on JDK 21. You will probably need to purchase an Oracle Java SE subscription while you implement the upgrades. The amount of effort depends on how many applications you have, which versions those applications use now and whether those applications are homegrown or purchased. An upgrade from JDK 8 to JDK 21 requires source code modifications and comprehensive testing. If you have purchased applications, your vendors will probably require you to upgrade them to the latest versions to get support for JDK 21. Also, there’s a risk that some application vendors don’t yet support their products on JDK 21.
Also, this option requires frequent future upgrades. You will need to upgrade to Java 25 by October 2026 to continue to get free quarterly updates. You may discover that you will need to upgrade to JDK 25 before you’ve completed the upgrade to JDK 21.
Upgrading to free-to-use Oracle JDK 21 requires significant software engineering work and probably isn’t a viable option for eliminating the requirement for an Oracle Java SE subscription in the short term. It may be a reasonable long-term solution if you are prepared to implement a continuous upgrade practice.
Option 3: Upgrading and Migrating to the Latest Release of OpenJDK
Upgrading your applications to the latest release of Java (currently JDK 23) and then migrating to OpenJDK could eliminate the requirement to purchase an Oracle Java SE subscription, but it requires even more time and effort than Option 2. In addition to upgrading all applications so they can run on JDK 23, you will need to remove all copies of Oracle JDK from your environment and replace them with the OpenJDK distribution. You will probably need to purchase an Oracle Java SE subscription while you implement the upgrades and migrations.
As with Option 2, the effort required to implement the upgrades depends on how many applications you have, which versions those applications use now, and whether those applications are homegrown or purchased. This option is less viable than Option 2 if you use purchased applications, because application vendors rarely support their application on short-term releases of Java.
This option also requires frequent future upgrades. You will need to upgrade to the next release of Java every six months. (OpenJDK 24 will be released in March 2025.)
Upgrading and migrating to the latest release of OpenJDK requires significant software engineering work, and it probably isn’t a viable option for eliminating the requirement for an Oracle Java SE subscription in the short term. This option is only viable if you have only homegrown applications and have implemented a continuous upgrade practice.
Option 4: Switching to a Third-Party Java Product
One popular alternative to purchasing an Oracle Java SE subscription is switching to a third-party Java product. It’s highly unlikely that you would be able to migrate all your Java applications to Java 21, but it’s relatively easy to switch to a third-party Java product of the same release. You must remove Oracle JDK from all your desktops and servers and replace it with a third-party Java product to avoid buying an Oracle Java SE subscription. Individual applications can use different JDKs.
Third-party Java products are based on the same source code as Oracle JDK — that is, OpenJDK. For the most part, these third-party Java products are drop-in replacements for Oracle JDK — although you should test your applications before making the switch. Most OpenJDK vendors support Java 8, 11, 17 and 21. Azul Platform also supports Java 6 and 7. All third-party OpenJDK products and quarterly updates are free. Some vendors also offer paid support subscription services (see Note 7). For more information about switching to third-party Java products, see Choosing a Java Runtime.
Two restrictions may limit your ability to use a third-party OpenJDK product:
One or more of your Java application vendors may stipulate that you must use Oracle JDK to conform to their support agreement. You may need to renegotiate your support contracts to ensure support for third-party Java products.
OpenJDK products do not support Java applets. If you have web applications that use applets, these applications require Oracle JDK on the desktop. Note that browser support for applets ended in June 2022. Applet applications can be converted into Java Web Start desktop applications, and most third-party Java products include a compatible implementation of Java Web Start. Applets can also be converted into WebAssembly components that run natively in a browser. Because applets are no longer supported, you should schedule those applications to be converted or modernized as soon as possible.
Free third-party Java products include:
Microsoft Build of OpenJDK — Commercial support subscriptions are available to Microsoft Azure customers with active Azure support plans. Red Hat build of OpenJDK — Available only to Red Hat customers. Red Hat includes a commercial support subscription for the Red Hat Enterprise Linux (RHEL) OpenJDK distribution with an RHEL subscription. Also, Red Hat includes a commercial support subscription for its Windows OpenJDK distribution with Red Hat middleware products. For use with non-Red Hat products, Red Hat requires a separate commercial subscription for Windows distribution.
All these products can support third-party and homegrown applications. The most popular third-party Java products are Eclipse Temurin, Amazon Corretto and Azul Platform.17, 18, 19, 20 IBM Semeru Runtimes and Red Hat build of OpenJDK are good alternatives if you use their OS, middleware or applications. Azul Platform, Eclipse Temurin and IBM Semeru Runtimes are good options if you intend to embed the JDK in an application for redistribution. Azul provides support for Java 6 and 7 with a paid subscription.
Option 5: Migrating All Oracle JDK Workloads to OCI or PCA
If migrating all your Java applications to Java 21 or a third-party Java product isn’t feasible, you can avoid purchasing an Oracle Java SE subscription by moving all unlicensed Oracle JDK workloads to OCI or PCA. OCI includes license and support for Oracle JDK for all workloads running on OCI infrastructure as a service (IaaS) and platform as a service (PaaS) solutions.10 Desktop applications can also be deployed in OCI using Oracle Virtual Desktop Infrastructure (VDI) or Kasm Workspaces for Oracle. PCA includes license and support for Oracle JDK 8 for all workloads running on the appliance.
If you have a mix of Oracle and non-Oracle applications running in a virtualized environment, you may need to move all Oracle JDK workloads to OCI or PCA to avoid a subscription.
Option 6: Purchasing an Oracle Java SE Subscription
Purchasing an Oracle Java SE subscription is the simplest option, but it will greatly impact your budget. Gartner has seen annual subscription fees typically top $1 million — and sometimes significantly more.13 Although purchasing an Oracle Java SE subscription will require you to inventory your use of Java, it’s much less work than Options 2, 3 or 4. The benefits that come with an Oracle Java SE subscription include:
License to use all releases of all commercial Oracle JDK products.
License to use Oracle GraalVM Enterprise Edition, a high-performance Java Virtual Machine.
License to use the Java SE Subscription Enterprise Performance Pack (EPP), which boosts Java 8 performance.
Quarterly updates for all Oracle JDK LTS releases — that is, Oracle JDK 8, 11, 17 and 21 — and the latest release.
Technical support for all Oracle JDK and GraalVM products.
License to use the Oracle JMS.
License to use the Java Advanced Management Console (AMC).
License to use the Microsoft System Installers (MSI) Enterprise JRE Installer.
If you plan to purchase a subscription, prepare detailed documentation to support your negotiations. Calculate and compare the subscription price based on new and legacy subscription models. Oracle rarely strays from its published tiered discount rates, and Oracle typically does not combine Java subscriptions with other product negotiations. Oracle asserts that clients with counts that exceed the published volume discount range — that is, more than 50,000 employees or 50,000 processors — have an opportunity for negotiation. However, Oracle rarely negotiates on the per-unit cost. Oracle will say what discount it will offer based on the number of employees and processors you need to license. Take it or leave it.
Prepare detailed documentation about your past, current and planned use of Oracle JDK before meeting with Oracle.
New Subscriptions
If you have not previously purchased a subscription, Oracle will pressure you to purchase the Oracle Java SE Universal Subscription, based on the Employee metric at the published tiered discount rate. If negotiations with Oracle took place before the 23 January 2023 metric change, insist on a quote under the legacy model if you determine that the legacy subscription is a better value. Even if you weren’t conducting negotiations at that time, request a quote under the legacy model — although the Java account executive will need authorization to offer that quote. Oracle reports to Gartner that the legacy subscription is not available to new customers.
If you have been using Oracle JDK without a subscription, expect Oracle to demand past usage fees based on the Employee metric dating back to April 2019. You can push back against these fees but may need to commit to multiple years to reduce or eliminate them.
Oracle offers annual and multiyear subscriptions. If you sign up for a multiyear subscription or port your Java workloads to OCI, Oracle may forgive a portion of your past use license liability and may be willing to offer higher discounts. You may be able to negotiate the start and end date of the subscription to gain an extra month or two, especially if you are signing up for a multiyear subscription.
Renewals
If you have previously purchased legacy subscriptions, Oracle should allow you to renew them based on the legacy metrics — that is, NUP and processor. However, Oracle has not specified how long these renewals will be permitted, nor what the renewal fees will be. According to Gartner client interactions, Oracle may state that any renewal of a legacy subscription requires an Oracle validation of your licensing requirements.13 Review the terms of your current subscription to validate renewal requirements. If your subscription lapses, Oracle will require past usage fees, although Gartner has no reports that Oracle charges additional penalties or reinstatement fees. Expect the account executive to resist offering a renewal based on the legacy metrics if your subscription has lapsed.
Oracle’s last published price list for the legacy subscriptions — the Oracle Java SE Subscription Global Price List, dated 2 August 2018 — is no longer available on Oracle’s site (see Note 5). Oracle has not specified the cost impact of legacy subscription modifications, such as increases or decreases in subscription quantities.
According to Gartner client interactions, Oracle is insisting on migration to the Oracle Java SE Universal Subscription for customers requiring additional legacy subscription quantities and customers with perpetual licenses for older Java products. For example, Java SE Advanced or Java SE Suite.13 If you are trying to reduce the number of NUPs or Processors in your subscription, carefully consider the impact this reduction may have on your negotiations in light of Oracle’s lack of detail on the cost impact. Also, expect Oracle to demand evidence to support that reduction. Before finalizing the quote, negotiate price holds, caps and renewals for the legacy model to optimize costs.
To reduce the NUP count, you must show evidence that some of your users have no access to desktops that have Oracle JDK installed. Remove Oracle JDK from as many desktops as possible before you start negotiations.
Server Virtualization
Server virtualization is a licensing consideration when negotiating the processor count for either the legacy Processor metric or the new Employee metric when the processor count exceeds 50,000. If you use server virtualization, Oracle requires you to count all processors in the entire virtualization estate. You may convince Oracle to allow you to partition the estate to reduce the number of processor licenses that must be purchased.
Oracle approves partitioning requests on a case-by-case basis. All requests must supply an isolation process document that is examined and approved by Oracle’s license management services (LMS) specialists. See Note 6 for the required information in an isolation process document. Alternatively, deploy all applications that use Oracle JDK on bare metal servers or OCI (see Avoid These Licensing and Pricing Pitfalls When Negotiating Oracle Deals).