HomeOracle HubJava Data Requests
Oracle Java  |  Java Audit Buyer Guide 2026

Oracle's typical Java audit data request covers nine record categories, but only two of them are contractually owed under Schedule P

Oracle's LMS and GLAS teams request install inventories, download histories, patch logs, HR headcount extracts, and virtualization maps as if all of it were one obligation. Schedule P obliges reasonable assistance within the scope of the applicable order and Master Agreement, and the billing metric is employees, not installs, so most install-side production increases your exposure by 100% and your bill by nothing. Decide record by record before you send anything.

Prepared by Redress Compliance · August 31, 2026 · Oracle Java advisory. Audit-defense engagements 2024 to 2026.

Executive summary

Install counts do not set the price, so producing them serves Oracle's narrative and not your bill.

The 2023 Universal Subscription is priced per employee, from $15.00 per month at 1 to 999 down to $5.25 at 40,000 to 49,999, and a 4,000-install environment costs exactly the same as a 400-install one at the same headcount.

Only two of the nine standard asks have a contractual hook: a defensible employee count and, above 50,000 processors, an install-side processor count.

The Employee definition in the Oracle Java SE Universal Subscription Global Price List permits installation on up to 50,000 processors excluding desktops and laptops, which is the single place install data becomes contractually relevant.

Oracle usually opens with download logs it already holds, and downloads are not deployments.

Oracle has no agent on your estate and cannot remotely scan servers, so it works from download records retained up to seven years, typically asserted across a 2 to 4 year look-back, and every gap you fill voluntarily converts circumstantial evidence into an admission.

The most damaging single question is "when was Java first installed," because it sets the back-fee start date and Oracle anchors to January 2019.

Answering it with patch-management records rather than a scoped statement can extend a claim by six or seven years of retroactive subscription at list, which on 4,000 employees at $10.50 per month is $504,000 per year multiplied out.

2 of 9
Standard Oracle Java data asks with a genuine contractual hook under Schedule P
50,000
Processor ceiling in the Employee metric: the only place install counts contractually matter
$269,874
Annual list swing between 9,999 and 10,000 employees, so headcount precision beats install precision
7 years
Maximum Oracle download-log retention, against a 2 to 4 year look-back typically asserted
1.

The nine standard asks and what each one is actually worth to Oracle

Oracle's LMS and GLAS teams send a single data request template and treat all of it as one obligation. It is not.

Under the 2023 Universal Subscription the billing metric is Employee, defined in Oracle's own price list as all full-time, part-time and temporary employees plus those of your agents, contractors, outsourcers and consultants supporting internal business operations. Installs do not price the deal.

That single fact reorders the entire request: the only install-side number with contractual pricing consequence is the 50,000-processor ceiling inside the Employee definition, and almost no organization approaches it. Everything else on the install side is narrative fuel.

Oracle's evidence base before you send anything is thin and circumstantial: download logs tied to your IP ranges, support records, and whatever a soft audit persuaded someone in your infrastructure team to email. Oracle has no agent on your estate and cannot scan it remotely.

Your production is what converts a download log into a deployment claim, and a deployment claim into a first-install date that anchors back fees, frequently to January 2019.

Record asked forWho it helpsCompelled by Schedule P?Defensible response
Install inventory (host-level)Oracle. Builds volume narrative and back-fee anchoringOnly as output of Oracle's own measurement tool, within order scopeProduce scoped: counts by version and license basis, no hostnames
Download history from your sideOracle. Corroborates its logs and extends the periodNo. It is Oracle's record, not yoursRefuse to reconstruct; ask Oracle to produce its log first
Patch and update logsOracle. Proves post-NFTC updates (17.0.13+, JDK 21 after Sept 2026)Not named in the clauseRefuse as a standing feed; answer specific version questions only
Virtualization and cluster topologyOracle. Only relevant near 50,000 processorsNo, unless processor ceiling is genuinely in playRefuse until Oracle states the ceiling theory in writing
HR headcount extractYou. This is the priceYes, in substance. It is the metricProduce well: one governed number, your definition, your date
Contractor and outsourcer rostersMixed. Definition is broad but bounded by "support internal business operations"Partially. Aggregate onlySummarize: counts by category, no per-person rosters
Entitlement and PO recordsYou. Legacy and free-use coverYes, and to your advantageProduce fully
LMS script outputOracleYes, expressly named in the clauseProduce, run by you, reviewed before release
First-install datesOracle. Sets the retroactive clockNoRefuse. State no reliable record exists

Read the table left to right and the pattern is unmistakable: seven of the nine asks price nothing and date everything. A flattering install inventory is still a liability, because Oracle does not use it to compute a fee.

It uses it to establish that Java ran in production, on which hosts, and since when, which is exactly what it needs to convert a subscription conversation into a retroactive one.

Under a headcount metric, a clean 400-install answer and a messy 4,000-install answer generate the same invoice and materially different back-fee arguments.

The corollary is that the two records genuinely worth investing in, employee count and entitlement proof, are the ones most buyers produce worst.

Build your own governed source of truth for the employee count before Oracle asks, and assemble the entitlement file showing which installs are already licensed or free. Those two documents shrink the bill. The other seven expand the claim.

2.

What Schedule P actually obliges: reasonable assistance, not open discovery

The clause is short and buyers routinely concede more than it says. Oracle may audit on 45 days written notice, limited to use of the Programs under the applicable order and Master Agreement, and the audit shall not unreasonably interfere with normal business operations.

You agree to cooperate and provide reasonable assistance and access to information reasonably requested, "including, but not limited to, the running of Oracle data measurement tools on Your servers and providing the resulting data to Oracle." That is the whole compulsion.

Note what is absent: no obligation to reconstruct download history, no obligation to date first installs, no obligation to hand over HR systems access, no obligation to build topology diagrams, and no obligation to answer interview questions.

Two levers do the work. First, "reasonably requested" is a qualifier, not a courtesy. A request that produces data with no bearing on the contracted metric is not reasonable, and you should say so in writing rather than silently comply.

Second, the order and Master Agreement scope limit confines the audit to the products and terms you actually signed. Where no subscription order exists, Oracle is auditing against a click-through license, and the audit clause it is quoting may not even attach.

Make Oracle identify the specific agreement and order it is auditing under, in writing, before you produce a single record.

The remaining mechanics all favor a slower, narrower posture. Audits run once per year and during normal business hours. Oracle bears none of your cooperation costs, which is precisely why unlimited production is a self-funded expansion of Oracle's case.

The confidentiality obligation on findings and reports runs both ways, so Oracle's numbers are not free to circulate to your account team as a sales instrument.

And the 30-day remedy trigger only starts on written notice of identified non-compliance, meaning delay in that notice is delay you own, not the other way round. Route everything through counsel and keep the working analysis under privilege and off Oracle's desk.

Free white paper

Oracle Database Options & Management Packs: the accidental-use audit trap

The separately-licensed options and packs that ship enabled by default, get switched on with a single click, and become the single largest line item in most Oracle audit findings.

Get the white paper →
3.

Why every install record you produce is an argument for a bill you do not owe

The Oracle Java audit playbook runs on a metric mismatch, and after 25 years across the table from this vendor I no longer believe it is accidental. The LMS or GLAS script counts installations, JRE and JDK, servers, desktops, embedded runtimes, dormant copies in application bundles.

The Universal Subscription contract charges by Employee. Those two numbers are unrelated. Nothing in Oracle's price list converts an install into a dollar, with one narrow exception, and no negotiator on Oracle's side will ever tell you that unprompted.

The gap between the number the script produces and the number the contract prices is precisely where the negotiating theater happens.

Picture the standard sequence. You run the script because it felt easier than arguing. Six weeks later Oracle presents a finding: 12,000 Java installations, unlicensed, across four business units.

That number lands in a room with your CIO and CFO in it, and it does emotional work no arithmetic supports. Everyone in the room instinctively multiplies.

But the actual subscription for a 10,000-employee organization is $990,000 per year at list, and it would be $990,000 whether the script found 12,000 installs or 200. The install figure is an anchor with no denominator behind it. It exists to make the eventual quote feel like relief.

Oracle's own published example settles the point better than any consultant can. The price list works through an organization at 28,000 total: 23,000 employees plus 5,000 agents, contractors and consultants, at $6.75 per employee per month, arriving at $2,268,000 per year.

Read that example again and notice what is absent. There is no install count in it. No processor count, no server list, no virtualization map. Oracle documented its own pricing arithmetic and the only input was headcount. That is the vendor's own admission about which number moves money.

The single place install data becomes contractually relevant is the 50,000-processor ceiling embedded in the Employee definition, which excludes desktops and laptops. Almost no organization approaches it, and the ones that do already know.

Outside that ceiling, install records serve exactly two functions in an Oracle audit: they generate an anchor, and they establish a start date for back-fee claims.

The auditor question "when was Java first installed on these systems?" exists for the second purpose, and it typically anchors to January 2019. That question is not about your subscription price. It is about building a retroactive claim from records only you can supply.

This is why the diligent team loses. I have watched IT asset management functions spend 200 hours reconciling discovery output, deduplicating bundled runtimes, mapping virtual hosts, chasing down a Java 8 install on a decommissioned test box.

They arrive at the negotiation with immaculate data and materially worse leverage than the team that produced nothing. They have handed Oracle a defensible install baseline, a first-installed date per system, and a patch history showing which machines pulled updates after the OTN cutover.

Better data, worse position. The effort was real; it was spent building the other side's case. If you must build an inventory, build it internally and keep it that way, per making your Java install inventory audit-defensible rather than merely complete.

The discipline is straightforward and it holds up under pressure. Answer the metric question with metric-relevant records. Refuse the rest in writing, citing scope rather than convenience, and make Oracle articulate why a given category is reasonably necessary to verify a headcount-based metric.

Oracle cannot compel a category it cannot connect to the billing basis, and its analysts are not accustomed to being asked. Keep the internal workpapers under counsel where privilege protects your Java audit records.

Let Oracle carry the burden of relevance on every category beyond the two that are actually owed.

Watch the briefing · 4:12What a ULA Actually IsSession 1 of the Oracle ULA Series. Unlimited deployment of a defined product set, for defined entities, in defined territories, for a fixed term, ending in a certification that fixes your position for a decade. Every word in that sentence is a limit.Open the full page, with the transcript →
4.

The employee count is the one number worth producing well

If you are going to invest effort anywhere, invest it here.

The price list definition is the whole battleground and you should quote it verbatim in your response: all full-time, part-time and temporary employees, plus the full-time, part-time and temporary employees of your agents, contractors.

Outsourcers and consultants that support your internal business operations, with quantity determined by number of Employees, not actual users, and at minimum equal to headcount as of the order effective date.

Three phrases do the work: "support your internal business operations" scopes the contractor population, "as of the order effective date" makes this a point-in-time measurement rather than a rolling one, and "not actual users" pre-empts any argument about who touched Java.

Produce a certified summary figure and a one-page definition memo signed by an officer. Do not produce an HR system extract. An extract invites Oracle to re-derive your number with its own inclusion rules, and every re-derivation in my experience moves upward.

The memo states the number, the measurement date, the definition applied, and the exclusion logic, and it stops there. Build the underlying methodology once and keep it, per establishing your own source of truth for the Java employee count.

Employee countBand rate per monthAnnual listNote
9,999$12.50 (3,000 to 9,999 band area)$1,259,874Worst position on the curve
10,000$8.25$990,000One more employee saves $269,874
28,000 (Oracle example)$6.75$2,268,00023,000 employees plus 5,000 contractors
49,999$5.25$3,149,937Last published band; above 50,000 is negotiated

The band boundaries invert the arithmetic, and that is a lever, not a curiosity. At 9,999 employees you pay $1,259,874 per year at list. At 10,000 you pay $990,000. Adding one person removes $269,874 from your annual cost.

If your defended count lands within a few hundred of a boundary from below, the commercially correct answer is to buy at the next band, not to argue your way down to a worse rate.

On contractors, the scoping phrase is "support your internal business operations," not "appears on the accounts payable ledger." A construction firm building your warehouse, an external audit firm, a marketing agency.

A legal panel: none of those support internal business operations in the Java sense, and none of them run your Java.

Scope the contractor roster deliberately, document why each population was included or excluded, and be prepared to defend it once rather than repeatedly.

5.

The three questions to refuse in writing, and the language to use

Three asks in the standard nine deserve a written refusal, not a negotiation. The first is "when was Java first installed on each of the listed systems?" That question has no compliance purpose.

It has a billing purpose: it establishes a start date for back fees, and Oracle habitually anchors to January 2019, when Java SE updates went commercial. Answer it and you have hand-delivered the multiplier on every year of the claim.

The refusal language is simple and non-hostile: "The applicable order and Schedule P govern current use of the Programs. We will confirm present deployment and present entitlement.

Historical first-install dating is outside the scope of the audit notice and we decline to reconstruct it." Do not say "we do not have it" if you do; say it is out of scope.

The second is unrestricted raw system access or credentialed scanning. Schedule P obliges cooperation, reasonable assistance, and access to information reasonably requested, including running Oracle measurement tools and providing the resulting data.

It does not oblige you to hand Oracle credentials, admit an auditor to a console, or permit discovery sweeps across estates outside the audited Programs. Run any tooling yourself, on your own hardware, under your own review, and produce the output.

Keep the working papers inside your privileged Java audit record set so drafts and internal estimates never reach Oracle's desk.

The third is anything reaching beyond the notice period or beyond the Programs under the applicable order. Oracle holds download and support records up to seven years and will ask questions shaped by that reach, even where the quoted claim covers two to four.

Confine every dataset to the notice window and to the named Programs, and say so in a standing objection letter that opens by affirming cooperation and then narrows scope item by item.

That letter preserves your cooperation status while creating a record that you objected contemporaneously, which matters if the file ever moves to counsel.

One trap to note in the same letter: the NFTC is void where any Java subscription agreement exists, so if you hold a live subscription anywhere in the group, "free" JDK 21 or 17 builds are not free for you.

Patch pipeline records are therefore evidence and exposure at once, and after the October 2026 Critical Patch Update pushes JDK 21 onto OTN, automated updaters will keep manufacturing new exposure until someone pins them.

6.

What we see across Java audit engagements

2 to 4 years
Typical quoted look-back against a 7-year retention capability

Oracle can reach back seven years on download and support records, but the claims we see quoted almost always settle into a two to four year window, which means the opening number is a negotiating position, not a ceiling.

$269,874
Value of one employee at the 10,000 band boundary

At list, 9,999 employees costs $1,259,874 per year and 10,000 costs $990,000, so the employee count deserves more defense effort than the entire install inventory combined.

The recurring patterns from 2024 through 2026 engagements are consistent enough to plan around.

Oracle opens from download logs rather than deployment evidence, because it has no agent on your estate and cannot scan remotely.

The log proves an IP range fetched a binary, not that anything runs today, which is why reconstructing your own download history before responding changes the conversation.

The JDK 17 precedent (NFTC ended September 2024, build 17.0.12 the last free update) is now being replayed verbatim for JDK 21 from the October 2026 CPU, and Oracle's sales teams cite the first cliff as proof the second one will bite.

Silent conversion through patch pipelines is the most common single source of new liability we encounter: nobody decided to buy Java, an unattended updater simply pulled 17.0.13 or later and moved the estate onto OTN.

Legacy perpetual Java SE Advanced holdings turn up in roughly every large manufacturing and financial engagement we handle.

They are genuine audit cover for historical use and useful migration runway, but they earn zero credit against Universal Subscription price, and buyers who budget on the assumption of an offset are consistently short.

Finally, internal budgets keep adding a 22% support line to the subscription rate. That line does not exist. The Universal Subscription rate is all-in, and the double-count inflates the internal case for settling early.

The pattern that matters most is the mismatch between where Oracle's evidence sits and where your money sits. Oracle's evidence is circumstantial and install-shaped: download logs, patch records, first-install dates. Your bill is headcount-shaped.

Teams that spend six weeks perfecting an install inventory and thirty minutes on the employee number have optimized the wrong side of the equation entirely.

The practical consequence: put your best analyst on the employee definition (which sweeps in agents, contractors, outsourcers, and consultants supporting internal operations) and on establishing your own source of truth for that count before Oracle proposes one.

Every hour spent there is worth more than a week of install reconciliation.

Try Vera AI · free 30 day trial
Do not send the counter until Vera has read the deal.
  • Percentile standing for your exact deal size and industry, from real closed transactions
  • Scenario simulation before the call: test alternative terms and see the financial impact of each
  • A negotiation playbook, talking points, and a two page executive brief on day one
Start the free Vera AI trial →30 days free · no credit card · cancel anytime
7.

Your first five moves

  1. Map every ask against Schedule P and answer in writing inside the 45-day notice window, itemizing which of the nine categories fall within "reasonable assistance and access to information reasonably requested" under the applicable order, and stating plainly that Oracle has no contractual right to HR extracts, virtualization maps, or seven-year patch pipelines simply because a script asks for them.
  2. Freeze all voluntary production and route everything through one named owner, because in our experience the damaging disclosures in Java audits come from a sysadmin answering a direct email rather than from the formal response, and the privilege and record-handling discipline only holds if there is exactly one desk the data leaves from.
  3. Build the certified employee count and the definition memo before you touch install work, since the metric is employees and the contract requires the count to at minimum equal headcount at the order effective date, so your own source of truth for that number is worth more than a perfect CMDB export ever will be.
  4. Answer first-install and download questions with scoped written statements, never raw logs, because Oracle anchors back fees to a first-install date (often January 2019) and to download records it already holds, and a narrative that separates downloads from production deployments concedes far less than an unfiltered timeline.
  5. Model the band boundary and the 50,000-processor position now, so when the finding lands you already know that 9,999 employees lists at $1,259,874 against $990,000 at 10,000, and that install counts matter contractually only above 50,000 processors, giving you a priced counter instead of a reaction.
8.

Frequently asked questions

Does Oracle's Java audit clause require me to run the LMS script?

Schedule P states you agree to provide reasonable assistance and access to information reasonably requested, including but not limited to running Oracle data measurement tools on your servers and providing the resulting data.

That language supports a request but is bounded by the scope of the applicable order and Master Agreement and by the requirement not to unreasonably interfere with normal business operations.

In practice you can negotiate what the script runs against, when, and in what form results are shared, and you should never grant Oracle direct or credentialed access to run it.

If Oracle charges per employee, why does it ask for install data at all?

Two reasons. The Employee metric permits installation on up to 50,000 processors excluding desktops and laptops, so above that threshold install data becomes contractually relevant.

Below it, install counts serve as a narrative anchor: a large findings number creates pressure that has no arithmetic connection to the subscription price, which is set purely by headcount.

How far back can Oracle claim on Java?

Oracle holds download logs and support records for up to seven years and could theoretically assert claims across that period. In practice quoted retroactive periods in Java engagements run two to four years, often anchored to January 2019 when Java SE updates became paid for commercial use.

Never confirm a first-install date in writing without understanding it sets the start of the back-fee calculation.

Should I give Oracle our HR headcount extract?

No. Produce a certified summary figure with a written definition memo explaining how you applied the price list definition of Employee, including which contractors and outsourcers support internal business operations and which do not.

A raw HR extract invites Oracle to reinterpret your scope and pull in categories you excluded. The summary plus definition memo is defensible, auditable on request, and keeps the interpretation under your control.

Does having downloaded Java prove we owe a subscription?

No. Oracle has no agent on your estate and cannot remotely scan your servers, so download logs are circumstantial: they show that an IP range in your organization pulled a build, not that the build was installed, remained installed, or was used for a commercial purpose requiring a license.

Downloads are not deployments, and the burden of connecting them sits with Oracle unless you volunteer the connection yourself.

What changes for Java 21 in October 2026?

JDK 21 updates through and including September 2026 are available under the NFTC. Beginning with the October 2026 Critical Patch Update, further Oracle JDK 21 updates are planned under the Java SE OTN license, the same license used for Java 8, 11 and 17.

That makes your patch pipeline both evidence and exposure: routine update automation can move you from free to paid without any procurement decision, exactly as it did with JDK 17.0.13 onward after September 2024.

Do our legacy perpetual Java SE Advanced licenses reduce the subscription price?

They provide audit cover for the versions and support periods they entitle, and they give you migration runway, but they earn no credit against the Universal Subscription price. Budget accordingly and do not let a vendor rep imply otherwise.

Also note that the Universal Subscription rate is all-in with no separate 22% support line, so any budget adding a support percentage is double-counting.

© 2026 Redress Compliance · Independent, buyer sideredresscompliance.com
Industry Recognized
500+ Enterprise Clients
$2B+ Under Advisory
11 Vendor Practices
100% Buyer Side Independent
Oracle Java White Paper

Oracle Database Options & Management Packs: the accidental-use audit trap

The separately-licensed options and packs that ship enabled by default, get switched on with a single click, and become the single largest line item in most Oracle audit findings.

Gated with a work email on the download page. No sales follow up you did not ask for.

Get the White Paper →
Independent, buyer side. We never share your details with vendors.
Run the software spend health check against your Oracle Java estate in under five minutes.
Open the Tool → Oracle Hub →
Editorial boardroom interior

The advisor your vendors do not want.

500+ enterprise clients. 11 vendor practices. Industry recognized. One conversation can change what you pay for the next three years.

Stay ahead of Oracle Java pricing and contract moves.

One buyer side briefing a week. Renewal signals, discount bands, and the levers that work. No vendor spin.