Frequent shifts in Oracle’s Java licensing model are catching many organizations off guard creating unexpected compliance and audit risks. Pentaho Enterprise Edition helps teams stay secure and predictable with certified, open JDK options and tested compatibility across Java 17 and beyond.
In recent months, we’ve seen many customers move to Pentaho 10.2 Enterprise Edition to “remove some of the open-source risks” that they have been managing for the last few years. While this is not a new topic, it’s certainly one that open-source users need to monitor consistently. Underlying components regularly shift, and what has worked for years can suddenly create a problem from both a licensing and a security perspective.
For example, Pentaho Community Edition version 9.3 was released on Java 11. Prior CE versions utilized Java 8. While Java remains a stable platform, recent policy changes require additional engineering and compliance attention. Accordingly, we’ve made updates to run on Java 17 in our Enterprise Edition.
With the recent changes to Oracle’s support policy for the related Java SE toolkits the legacy environments our customers may have relied on are now outside of commercial terms. Continued usage could result in either audit costs or related support fees, which is why we are encouraging those concerned about these risks to upgrade to our Pentaho Enterprise Edition.
Java Changes and Escalating Costs
Since 2019, there have been at least five large changes to the Java ecosystem. During that time, the license agreement type under which Oracle licenses different Java releases has changed three times. The required subscription if you’re using the Oracle SE Java JDK has changed twice. The old Oracle Java SE subscription (tied to the count of Java developers) has been replaced by the more broad-based Java SE Universal Subscription. The Universal Subscription price is now pegged to the size of your company, all employees and contractors, and it costs significantly more.
With the risk of rising costs and license confusion, everyone needs to ask: How is my company managing its Java tools and environments given the seismic changes? Are we at risk? What will it cost us?
How Pentaho Helps Mitigate Risks (and costs!)
At Pentaho, our approach has been Bring your own Java JDK. We support multiple flavors and test them. There are many open-source JDK alternatives that our Pentaho team tests in our QA processes. The options range from Open JDK, Eclipse Temurin, Azul Zulu, Red Hat Open JDK.
If you are using the Oracle JDK in production, you need to be aware of the following:
This is all a healthy reminder that a quick internal check can reveal if Oracle JDK usage is still ongoing and worth the risks outlined here. Shifting to a certified open-JDK standard can leverage the options available in the Pentaho Enterprise release. This not only creates operational predictability, but it helps support alignment with key security requirements including NIST SP 800‑53 (controls SI‑2 and CM‑6) and the HIPAA Security Rule [45 CFR § 164.308(a)(1)].
Investments in open-source resources change over time. What was once a cost-saving strategy may easily morph into a costly headache. Remove the hidden risk of open source by moving to a Pentaho Enterprise Edition. Our team of experts will help you protect your investment in data management.
Disclaimer: The following does not constitute compliance advice. It is provided for informational purposes only. Customers are solely responsible for understanding their unique needs according to their organizational requirements. This is not legal advice and is based on November 2025 publicly available information.
Author
View All Articles
Featured
Simplifying Complex Data Workloads for Core Operations and...
Creating Data Operational Excellence: Combining Services + Technology...
Top Authors
Tim Tilson
Sandeep Prakash
Jon Hanson
Richard Tyrrell
Duane Rocke
Categories
North American insurers face a paradox: world-class risk science built on fragmented, legacy data. Pentaho helps carriers unify mainframe, cloud, and partner systems into a single source of truth, delivering real-time lineage, governance, and audit readiness that turns regulatory risk into competitive advantage.
Learn More
Too many AI projects fail not because of algorithms, but because of data. Pentaho helps enterprises build the governed, catalog-driven data foundations that make AI explainable, scalable, and secure—turning innovation into measurable impact.
Customer loyalty is now won or lost in moments that matter. Pentaho helps insurers unify fragmented systems, automate claims and communications, and deliver real-time, personalized experiences that build trust, accelerate growth, and define the next era of insurance.
When ISG calls your platform “Exemplary,” it means something’s working. Pentaho earned top honors for delivering smart simplicity — integrating, governing, and optimizing enterprise data so businesses can run leaner, faster, and more intelligently.
The future belongs to insurers who treat privacy as power. Pentaho equips them with trusted, transparent data foundations that turn every potential breach into proof of control—strengthening trust with regulators, investors, and customers alike.