NAT is not useful, firewalls are.
NAT merely swaps an address for another in the outgoing IP packet, recording the connection, and doing the inverse op on incoming packets matching the record. It's actually called IP masquerading, and it does not protect you of anything.
Without a firewall rule that drops incoming packets, outside can readily reach your internal network with the proper route (your router already knows how to route external/internal, since it's its very role), even with NAT. The exact same incoming packet drop rule can readily be used with IPv6. And you can punch holes in the firewall for your internal services the same way you always did, you just don't need address swapping part anymore, nor "port forwarding", since all machines have all ports to them. In fact, the firewall stack actually gets two rules added each time you define a "port forwarding": the firewall rule to not drop the packet, and the NAT rule to forward it. Guess what forwards natively packets to the correct IPs? Routing. And that's precisely the purpose of NAT: being able to route IPs not meant to be routed in the first place, virtually extending the IP address space by having LAN machines sharing one address. The thing is, every IPv6 address is routable†, hence NAT simply has no purpose in IPv6.
The only real problem is that people have been framed to think that NAT is how things work. The truth is, having no NAT anymore is a bliss. Everything is easier, from DMZ routing to authorization to abuse handling, mostly because many issues, limitations, and extra work vanish.
PS: and don't start me on "NAT is good at using a single IP to connect to your machines". That's what DNS is for.
† except local-scoped addresses, but those are constrained to the link, since they are automatically assigned by the machine itself, and made to provide automatic peer-to-peer link-local connectivity only. By design, having only a link-local address means you have no internet connectivity whatsoever.