EOSL Alerts

Oracle JDK 23 EOL March 18, 2025 – 40-70% Savings Plan

Updated 3rd Party Support Team

What Changes on March 18, 2025?

On March 18, 2025, Oracle JDK 23 reaches end of life (EOL) and end of active support. After that date:

  • No more public updates: Oracle will stop releasing patches, including security fixes, for JDK 23.
  • No vendor support: Oracle’s support SLAs no longer apply to this version. Any production issue will not be addressed by Oracle.
  • No extended support: JDK 23 is not a Long-Term Support (LTS) release, so there is no paid extended support option from Oracle. The latest version in this line is 23.0.2.
  • Compliance exposure: Many regulatory frameworks and insurance policies require running supported software. Operating JDK 23 after EOL may be flagged as a risk.

This is a hard deadline, not a soft transition. The clock is ticking.

Why a Full Migration Isn’t Realistic in 3 Months

Migrating every application from JDK 23 to an LTS release (such as JDK 21 or JDK 17) in just three months is improbable for most enterprises. Common blockers include:

  • Incompatibilities in third-party libraries or custom frameworks.
  • Testing cycles that span multiple weeks or months.
  • Dependency on other teams (e.g., middleware, database, security) to validate changes.

Acknowledging this reality, your focus must shift to risk management rather than a full migration. Use the remaining weeks to contain exposure, document decisions, and secure a safety net.

Your Immediate Action Plan: Week-by-Week Checklist

The following 12-week plan is designed to be aggressive but achievable. Adjust based on your team’s capacity, but do not skip steps.

Weeks 1–2: Inventory Every JDK 23 Instance

  • Use your CMDB, container registries, and deployment scripts to list all systems running JDK 23.
  • Include development, staging, and production environments.
  • Record the exact version (e.g., 23.0.2) and the application or service that depends on it.

Weeks 3–4: Classify Criticality and Risk

  • Label each instance as critical, important, or low impact based on business function.
  • Identify which instances are internet-facing, process sensitive data, or are subject to regulatory compliance.
  • Prioritize the highest-risk instances for immediate action.

Weeks 5–6: Isolate and Harden

  • For critical systems that cannot be migrated before EOL, implement network segmentation (e.g., firewalls, VPNs, internal-only access).
  • Apply any available security patches for JDK 23.0.2 now (this is the last release).
  • Review and tighten application-level security controls (e.g., input validation, access controls).

Weeks 7–8: Document for Auditors and Insurers

  • Create a formal risk acceptance document for each instance that will run JDK 23 after EOL.
  • Include the reason for the delay, compensating controls in place, and a planned migration date.
  • Share this documentation with your compliance, audit, and risk management teams. Many insurers require this for cyber coverage.

Weeks 9–10: Evaluate Third-Party Support Options

  • Third-party maintenance providers can deliver security patches and technical support for JDK 23 after Oracle’s EOL, extending the safe operational window.
  • Compare offerings: look for vendors that provide CVEs backports, 24/7 support, and SLAs comparable to Oracle’s.
  • Request sample patch timelines and proof of engineering capability for JDK 23.

Weeks 11–12: Secure a Support Contract

  • Finalize a third-party support agreement to begin on March 18, 2025, so coverage is continuous.
  • Ensure the contract covers all instances you identified in the inventory, including those you plan to migrate later.
  • Confirm the hand-off process with your vendor and internal teams.

Options After EOL

You have three paths for JDK 23 after March 18, 2025:

  1. Third-party support – The most practical choice for most estates. It keeps your systems patched and supported while you plan a migration to an LTS release on your own schedule.
  2. Upgrade to an LTS release – Ideal if you can complete the migration before EOL, but unrealistic for many. If you can target a few critical apps, do so.
  3. Accept the risk – Only viable for air-gapped, non-critical systems with no compliance requirements. Even then, you must document the decision.

Third-party support is not a permanent fix—it buys you time. Use that time to migrate to JDK 21 or JDK 17, both of which have many years of support ahead.

Next Steps

Start your inventory today. The first two weeks are the most critical. If you want to explore third-party support for Oracle JDK 23, contact our team to discuss how we can help you stay patched and compliant after March 18.

How we can help

Keep it supported after end of life

The vendor's date doesn't have to be yours. Our engineers keep Oracle JDK 23 running after official support ends — independent third-party support that covers most operational issues, typically at 40-70% below the last renewal quote.

Oracle OS software support →

Migration services

When you do decide to move, we plan and execute the migration. Your current environment stays under vendor support while your contract is active — and if the renewal lapses mid-move, our third-party support covers most issues until the last workload is off it.

Migration & hybrid cloud services →

24×7 remote administration

Short on hands to run it day to day? Our NOC engineers monitor, patch and administer your environment around the clock — incident response included, at a fraction of the cost of an in-house night shift.

24/7 operations & remote administration →

Talk to a support specialist

Speak with an engineer, not a sales rep. We respond within 24 hours.

Your quote will be sent to this address.

By submitting this form, you agree to our Privacy Policy.