Oracle Java licensing, explained.
Oracle Java SE licensing has changed twice in significant ways — in 2018, the BCL (Binary Code License) moved to the Oracle Technology Network License (OTN), meaning Oracle could audit usage under the 30-day rule. Then in 2023, the change impacted the way users were counted: Processor and NUP (Named User Plus) metrics became unavailable, and Oracle began charging by all employees, contractors, and anyone accessing their systems, company-wide, under a subscription license. This page covers where things actually stand.
Am I using Oracle Java?
Work through this in order. Most organisations get stuck at the first question, because "Java" and "Oracle Java" aren't the same thing — OpenJDK, Azul Zulu, Amazon Corretto, and Eclipse Temurin are all Java too, and none of them carry an Oracle licensing obligation on their own.
Oracle now prices Java SE by employee, not by install.
Since January 2023, the Java SE Universal Subscription is priced per employee across your whole organisation — full-time, part-time, temporary, and contractor staff, regardless of how many of them actually touch Java. This is the detail that catches most organisations out: a handful of Java installations can mean the whole employee headcount is technically in scope, not just the machines running it.
Before 2023, licensing was based on processor counts or named users on the systems actually running Java — a much narrower exposure. The shift to a company-wide metric is the single biggest reason Java licensing risk has grown for most organisations, independent of anything else changing.
Free updates for JDK 21 end with the September 2026 patch cycle.
Oracle's NFTC licence gives free commercial use of an LTS release for about a year after the next LTS ships. JDK 25 shipped in September 2025, so free NFTC updates for JDK 21 run through the September 2026 patch cycle. From the October 2026 update onward, further JDK 21 updates move to Oracle's standard commercial licence terms, which don't permit free production use.
This doesn't affect organisations that have already moved to JDK 25, or that are running non-Oracle distributions. It's a genuine deadline for anyone still on Oracle JDK 21 in production — but it's a point-in-time trigger, not the whole picture. The 2023 per-employee metric is the bigger, permanent change underneath it.
If you don't migrate off Oracle JDK 21 before free updates stop — or you keep any other unlicensed Oracle JDK running in production past its NFTC window — the subscription you then need is priced per employee, company-wide. It isn't a per-machine cost for the handful of servers still on JDK 21. Continuing to run it, even on a small number of systems, can put your entire employee headcount in scope for the Universal Subscription.
These require a subscription, on any version.
Independent of NFTC status, using any of the following with Oracle JDK requires a Java SE subscription — these were historically part of "Java SE Advanced" and are still checked for in any proper licensing review.
| Feature | Requires subscription |
|---|---|
| Java Flight Recorder | Yes |
| Java Mission Control | Yes |
| Java Advanced Management Console | Yes |
| MSI Enterprise JRE Installer | Yes |
| JRockit Flight Recorder / Mission Control | Yes |
| JRE Usage Tracker | Yes |
Common questions
We already have Java SE Advanced or Java SE Suite licences — does anything change?
Existing Java SE Advanced, Advanced Desktop, and Suite licences continue as-is under their original terms. You don't need to do anything related to the newer per-employee subscription unless you choose to move to it.
We use OpenJDK, not Oracle JDK — are we affected?
Not by Oracle's Java SE subscription terms. OpenJDK, Azul Zulu, Amazon Corretto, and Eclipse Temurin are separate distributions without Oracle's licensing obligations. Worth confirming this is actually what's deployed, though — mixed estates are common, and it's easy to assume OpenJDK when a machine is actually running Oracle's build.
If our version isn't patched, is that also a security problem, not just a licensing one?
Yes — an unpatched, out-of-NFTC Oracle JDK is both a licensing exposure and a genuine security risk. Worth treating as two separate conversations: one with your licensing/procurement side, one with whoever owns patching.
What happens if Oracle audits us and finds unlicensed use?
Oracle can typically assess back fees for up to the 3 preceding years of unlicensed use, on top of the current year and a forward commitment for the year ahead — so a settlement can span up to 5 years of fees, not just one year's subscription. Try the cost calculator to see the scale for your own headcount.
How do we actually find out what's running across our estate?
This is what a Risk Review is for — a scoped scan using Oracle-verified tooling, deployed via your own SCCM/endpoint management/login scripts, with an analyst-reviewed report at the end.
Download the guide as a PDF.
Same content, saved or shared internally.
Download PDF