Ruzora
Engineering Culture

Java 11 End of Life: Migrate to 17, 21, or 25?

Oracle Premier Support for Java 11 ended in September 2023. Here is what the real deadlines are, what breaks on the way to 21 or 25, and how long the migration takes.

RE

Roberto Espinoza

CEO, Ruzora

October 2, 20266 min read

Java 11 end of life already happened for most teams: Oracle Premier Support ended in September 2023, and what is left is paid Extended Support that runs to January 2032. If you run free OpenJDK builds, the Eclipse Temurin 11 commitment runs to at least October 2027. My advice is to skip Java 17 as a destination and move straight to 21 or 25, because 17 just lost Oracle Premier Support too.

That last part surprises people. Java 17 was the "safe" target for three years. As of September 2026 it sits where Java 11 sat in 2023.

Key Takeaways

  • Oracle Premier Support for Java 11 ended in September 2023; Extended Support runs to January 2032, and only matters if you pay Oracle.
  • Eclipse Temurin 11 builds are promised until at least October 2027, so the free-build clock is about a year out.
  • Java 17 Premier Support ended in September 2026. Target Java 21 or 25 instead.
  • The hard part of the upgrade is strong encapsulation of JDK internals (JEP 403) and old libraries that reflect into them, not your own code.

The Java 11 End of Life Dates That Actually Matter

There is no single Java 11 end of life date. It depends on whose build you run and where.

PlatformJava 11 dateSource
Oracle Premier SupportEnded Sep 2023Oracle roadmap
Oracle Extended SupportUntil Jan 2032Oracle roadmap
Eclipse Temurin 11At least Oct 2027Adoptium
AWS Lambda `java11` (AL2)Deprecated Jun 30, 2027Lambda runtimes

And the targets you would move to:

VersionOracle Premier untilOracle Extended untilTemurin at least until
Java 17Sep 2026 (ended)Sep 2029Oct 2027
Java 21Sep 2028Sep 2031Dec 2029
Java 25Sep 2030Sep 2033Sep 2031

Two footnotes from Oracle's roadmap are worth reading slowly. The Extended Support uplift fee is waived for Java 11 from October 2023 to January 2032, and the full Extended Support fee is waived for Java 17 from October 2026 to September 2029. Both only help if you already pay for Oracle Java SE support. Oracle also says JDK 21 updates starting with the October 2026 Critical Patch Update are planned to move to the OTN license, and users who want permissively licensed builds "should upgrade to Oracle JDK 25 or later." If you run Oracle JDK specifically, that one sentence is the strongest argument for 25.

Most startups I talk to run Temurin, Corretto or a cloud vendor image, so the October 2027 Temurin date and the June 30, 2027 Lambda deprecation are the real deadlines. Lambda also offers a `java11.al2023` runtime that runs to June 30, 2029, which moves the Lambda date but not the Temurin one.

Engineering team gathered for a planning session
Engineering team gathered for a planning session

What Breaks Between Java 11 and 21

Oracle's migration guide lists the changes. The ones that cost real time:

Strong encapsulation (JEP 403, JDK 17). Code that reflects into JDK internals now throws `InaccessibleObjectException`, and the `--illegal-access` flag no longer relaxes it. Your own code rarely does this. Old versions of serialization libraries, mocking frameworks, bytecode tools and ORMs do. The fix is usually a dependency bump, occasionally an `--add-opens` flag as a stopgap.

UTF-8 by default (JEP 400, JDK 18). If your servers ran with a different platform charset, file reads and writes that never named a charset now behave differently. This one hides in batch jobs and CSV exports.

Nashorn is gone (removed in JDK 15). Anything that evaluated JavaScript inside the JVM needs a replacement, usually GraalJS or moving that logic out.

Security Manager deprecated for removal (JEP 411), finalization deprecated (JDK 18). Rarely blocking today, but they show up as warnings you should clear now rather than at the next upgrade.

If you are also on Spring Boot 2.7, the Java move is tied to a framework move, because Spring Boot 3 requires Java 17. I wrote that up separately in Spring Boot 2.7 end of life.

A Concrete Version

Take a hypothetical B2B SaaS backend: 9 Maven modules, about 140,000 lines of Java 11, 210 direct and transitive dependencies, Spring Boot 2.7, deployed as containers plus 6 Lambda functions on `java11`.

Here is how I would size the move to Java 21:

  • Dependency audit and bumps: 210 dependencies, about 35 need a newer version for JDK 17+ compatibility. At roughly 1.5 hours each to bump, compile and fix call sites: 52 hours.
  • Reflection and `--add-opens` cleanup: say 12 failures surfacing in tests at about 3 hours each: 36 hours.
  • Charset audit: grep for readers, writers and `getBytes()` without an explicit charset, about 60 call sites at 20 minutes each: 20 hours.
  • Spring Boot 2.7 to 3.x (javax to jakarta, Security 6, Hibernate 6): the biggest line item, about 160 hours for a codebase this size.
  • Lambda runtime changes, CI images, base Docker images, load test and staged rollout: 40 hours.

Total: 52 + 36 + 20 + 160 + 40 = 308 hours. Two senior engineers working on it full time (about 70 productive hours a week between them) finish in four to five weeks. One engineer squeezing it between feature work takes a quarter, and usually more.

Without the Spring Boot move, the same estimate is 148 hours, about two weeks for two people.

The Honest Counterpoint

You might not need to rush. If you pay Oracle, Java 11 Extended Support runs to January 2032 with the uplift fee waived. If your app is a stable internal service with no Lambda functions and few dependencies, a 2027 upgrade is defensible.

The other trap is the big-bang approach. Teams decide to go 11 to 25, Spring Boot 2.7 to 4.x, and refactor everything "while we're in there." That turns a five-week upgrade into a six-month rewrite, and big rewrites fail for predictable reasons. Upgrade the runtime first, ship it, then move the framework.

When Outside Engineers Make Sense

Upgrades are a bad fit for your product team. They are urgent but not exciting, and they get preempted by every feature request. A dedicated senior Java engineer for one quarter, working through a defined checklist, usually ships the migration faster than the team that wrote the code, because they are not context-switching.

That is the shape of work modernizing a legacy app with outside help fits. If you go this route, vet for real JVM migration experience, not framework buzzwords. Ruzora sends a vetted shortlist of senior LATAM Java engineers within 72 hours; you can request one here.

Frequently Asked Questions

When is Java 11 end of life?

Oracle Premier Support ended in September 2023, and Oracle Extended Support runs to January 2032. Eclipse Temurin 11 builds are committed until at least October 2027. AWS Lambda deprecates the `java11` runtime on June 30, 2027.

Should I upgrade from Java 11 to 17 or 21?

21, or 25 if you use Oracle JDK. Java 17 Oracle Premier Support ended in September 2026 and its Temurin commitment runs to October 2027, so it buys you about a year. Java 21 gets Temurin builds to at least December 2029.

How long does a Java 11 to Java 21 migration take?

For a mid-size service with no framework change, two to three weeks for two senior engineers is typical. If Spring Boot 2.7 to 3.x is part of it, plan on four to six weeks, mostly spent on the javax to jakarta move and Spring Security 6.

The Bottom Line

Java 11 end of life is a free-build problem by October 2027 and a Lambda problem by June 2027. Go to 21 or 25, keep the framework move separate, and give it to someone whose only job is finishing it. If you need that person, see vetted engineers.

Roberto Espinoza is CEO of Ruzora, which helps US startups hire pre-vetted senior LATAM engineers, with a vetted shortlist in 72 hours. See available engineers.

RE

Roberto Espinoza

CEO, Ruzora

Roberto is the founder and CEO of Ruzora. He works directly with US startup founders and CTOs on staff-augmentation and software-factory engagements, and personally reviews senior engineer placements.

AI-vetted engineers, ready now

Your next senior engineer is already vetted and waiting.

It starts with a single call. 72 hours later, you're reviewing scored candidates who already match your stack and culture.